A company has multiple VPCs in a single AWS Region. They need to establish full mesh connectivity between all VPCs and also provide centralized internet egress for all private subnets through a set of security appliances. What is the most scalable and manageable solution for this scenario?
- AUse a shared services VPC with an Internet Gateway and VPN connections from other VPCs to the shared services VPC.
- BConfigure a distributed set of Network Load Balancers across all VPCs to handle inter-VPC traffic and internet egress.
- CCreate VPC peering connections between all VPCs and deploy NAT Gateways with security appliances in each VPC.
- DDeploy a Transit Gateway, attach all VPCs to it, and route all internet-bound traffic from private subnets to a dedicated 'inspection' VPC attached to the TGW.
Show answer & explanationAnswer & explanation
Correct answer: D. Deploy a Transit Gateway, attach all VPCs to it, and route all internet-bound traffic from private subnets to a dedicated 'inspection' VPC attached to the TGW.
AWS Transit Gateway simplifies network topology by acting as a central hub for all VPCs. By attaching all VPCs to the Transit Gateway and routing all internet-bound traffic from private subnets through a dedicated 'inspection' VPC (which hosts the security appliances) attached to the TGW, you achieve full mesh connectivity and centralized, scalable internet egress.
Why the other options are wrong
- A. Using VPN connections between VPCs is less scalable and more complex than Transit Gateway for inter-VPC communication, and doesn't inherently centralize egress through appliances.
- B. Network Load Balancers are for distributing traffic to targets, not for routing inter-VPC traffic or centralizing internet egress through security appliances in this manner.
- C. VPC peering connections are not scalable for a full mesh (N*(N-1)/2 connections) and deploying NAT Gateways/appliances in each VPC defeats centralization.
Transit Gateway for Centralized Egress
Using AWS Transit Gateway to simplify routing between many VPCs and centralize outbound internet traffic through a dedicated inspection VPC for security appliances.
- Simplifies network topology (hub-and-spoke).
- Enables full mesh connectivity between attached VPCs.
- Allows for centralized security inspection of internet egress.
Memory trick: Transit Gateway is the 'Traffic Cop' for all VPC roads.