A global enterprise uses AWS Transit Gateway to connect its numerous VPCs across multiple regions. The security team mandates that all outbound internet traffic from any VPC must be inspected by a third-party firewall appliance, which is deployed as an EC2 instance in a dedicated security VPC (10.0.0.0/16) in the `us-east-1` region. This appliance should be the single egress point for all internet-bound traffic from all connected VPCs, regardless of their region. How should a network engineer configure the Transit Gateway to enforce this security requirement?
- APublish a default route (0.0.0.0/0) from the security VPC's route table to the Transit Gateway route table, and associate all other VPCs with this route table.
- BEnable Transit Gateway Appliance Mode on the attachment to the security VPC and configure a default route (0.0.0.0/0) in all other VPC's TGW route tables pointing to the security VPC attachment.
- CCreate a Transit Gateway Peering connection between each regional Transit Gateway and the `us-east-1` Transit Gateway, and then configure static routes in each regional TGW route table pointing to the `us-east-1` TGW for 0.0.0.0/0.
- DConfigure a default route (0.0.0.0/0) in each Transit Gateway attachment route table pointing to the security VPC attachment.
Show answer & explanationAnswer & explanation
Correct answer: B. Enable Transit Gateway Appliance Mode on the attachment to the security VPC and configure a default route (0.0.0.0/0) in all other VPC's TGW route tables pointing to the security VPC attachment.
To ensure all traffic, including return traffic, is routed through a network appliance like a firewall, Transit Gateway Appliance Mode must be enabled on the attachment to the security VPC. This forces both ingress and egress traffic for a flow to use the same appliance. Then, a default route (0.0.0.0/0) in the Transit Gateway route tables associated with other VPCs, pointing to the security VPC attachment, will direct all internet-bound traffic through the firewall. For cross-region traffic, Transit Gateway Peering would also be necessary to route traffic to the central security VPC.
Why the other options are wrong
- A. VPC route tables publish routes to the TGW, but the TGW route tables dictate routing between attachments. Publishing a default route from the security VPC itself doesn't configure the TGW to send all internet-bound traffic to that VPC for inspection, nor does it ensure symmetric routing.
- C. While TGW peering is needed for cross-region communication, simply creating peering and static routes won't enforce symmetric routing through the appliance for stateful inspection; Appliance Mode is crucial.
- D. This only configures the outbound path. Without Appliance Mode, return traffic might not go back through the appliance, breaking stateful inspection.
Transit Gateway Appliance Mode
A feature that ensures that traffic between two VPCs (or a VPC and the internet) traverses a network appliance, such as a firewall, in a consistent, symmetric manner.
- Maintains symmetric routing for stateful appliances.
- Enabled on a Transit Gateway attachment.
- Critical for centralized ingress/egress inspection VPCs.
Memory trick: Appliance Mode makes traffic flow through the funnel, always.