AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationHard

A company has multiple VPCs in a single AWS Region. They need to establish full mesh connectivity between all VPCs and also provide centralized internet egress for all private subnets through a set of security appliances. What is the most scalable and manageable solution for this scenario?

  1. AUse a shared services VPC with an Internet Gateway and VPN connections from other VPCs to the shared services VPC.
  2. BConfigure a distributed set of Network Load Balancers across all VPCs to handle inter-VPC traffic and internet egress.
  3. CCreate VPC peering connections between all VPCs and deploy NAT Gateways with security appliances in each VPC.
  4. DDeploy a Transit Gateway, attach all VPCs to it, and route all internet-bound traffic from private subnets to a dedicated 'inspection' VPC attached to the TGW.
Show answer & explanation

Correct answer: D. Deploy a Transit Gateway, attach all VPCs to it, and route all internet-bound traffic from private subnets to a dedicated 'inspection' VPC attached to the TGW.

AWS Transit Gateway simplifies network topology by acting as a central hub for all VPCs. By attaching all VPCs to the Transit Gateway and routing all internet-bound traffic from private subnets through a dedicated 'inspection' VPC (which hosts the security appliances) attached to the TGW, you achieve full mesh connectivity and centralized, scalable internet egress.

Why the other options are wrong

  • A. Using VPN connections between VPCs is less scalable and more complex than Transit Gateway for inter-VPC communication, and doesn't inherently centralize egress through appliances.
  • B. Network Load Balancers are for distributing traffic to targets, not for routing inter-VPC traffic or centralizing internet egress through security appliances in this manner.
  • C. VPC peering connections are not scalable for a full mesh (N*(N-1)/2 connections) and deploying NAT Gateways/appliances in each VPC defeats centralization.

Transit Gateway for Centralized Egress

Using AWS Transit Gateway to simplify routing between many VPCs and centralize outbound internet traffic through a dedicated inspection VPC for security appliances.

  • Simplifies network topology (hub-and-spoke).
  • Enables full mesh connectivity between attached VPCs.
  • Allows for centralized security inspection of internet egress.

Memory trick: Transit Gateway is the 'Traffic Cop' for all VPC roads.

More Network Implementation questions