A cybersecurity firm is deploying a network intrusion detection/prevention system (IDPS) in their AWS environment. They need to inspect all ingress and egress traffic for multiple VPCs in a centralized manner for deep packet inspection and threat analysis. The solution must be highly available, scalable, and minimize operational overhead. Which architectural pattern and AWS service facilitate this requirement?
- ADeploy an EC2-based IDPS appliance in each VPC and manage it individually.
- BUse a centralized inspection VPC with AWS Transit Gateway and AWS Network Firewall.
- CConfigure VPC Flow Logs to send data to Amazon Kinesis and then process with AWS Lambda.
- DImplement AWS WAF on all public-facing load balancers and CloudFront distributions.
Show answer & explanationAnswer & explanation
Correct answer: B. Use a centralized inspection VPC with AWS Transit Gateway and AWS Network Firewall.
A centralized inspection VPC with AWS Transit Gateway allows routing all ingress and egress traffic from spoke VPCs through a dedicated inspection VPC. AWS Network Firewall, being a managed, scalable, and highly available service, can then perform deep packet inspection and threat analysis within this inspection VPC, minimizing operational overhead compared to self-managing EC2-based appliances.
Why the other options are wrong
- A. Deploying and managing individual EC2-based IDPS appliances in each VPC is operationally intensive and does not provide centralized inspection or minimize overhead.
- C. VPC Flow Logs provide metadata about traffic but do not perform deep packet inspection or active intrusion prevention; processing with Kinesis/Lambda is for analysis, not inline inspection.
- D. AWS WAF protects web applications (Layer 7) from common exploits, but it does not provide deep packet inspection for all network traffic (Layers 3-4) or intrusion detection/prevention for the entire VPC environment.
Centralized Inspection VPC with Transit Gateway & Network Firewall
An architectural pattern where all network traffic (ingress/egress) from multiple VPCs is routed through a central inspection VPC for deep packet inspection and threat analysis using AWS Network Firewall, managed by AWS Transit Gateway.
- Transit Gateway routes traffic to/from inspection VPC.
- AWS Network Firewall performs stateful deep packet inspection, IDS/IPS.
- Centralized security for multiple spoke VPCs.
- Highly available, scalable, managed service.
- Minimizes operational overhead compared to self-managed appliances.
Memory trick: Transit Gateway 'routes all cars' to the Network Firewall 'inspection station' for security.