AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationHard

A global enterprise uses AWS Transit Gateway to connect its numerous VPCs across multiple regions. The security team mandates that all outbound internet traffic from any VPC must be inspected by a third-party firewall appliance, which is deployed as an EC2 instance in a dedicated security VPC (10.0.0.0/16) in the `us-east-1` region. This appliance should be the single egress point for all internet-bound traffic from all connected VPCs, regardless of their region. How should a network engineer configure the Transit Gateway to enforce this security requirement?

  1. APublish a default route (0.0.0.0/0) from the security VPC's route table to the Transit Gateway route table, and associate all other VPCs with this route table.
  2. BEnable Transit Gateway Appliance Mode on the attachment to the security VPC and configure a default route (0.0.0.0/0) in all other VPC's TGW route tables pointing to the security VPC attachment.
  3. CCreate a Transit Gateway Peering connection between each regional Transit Gateway and the `us-east-1` Transit Gateway, and then configure static routes in each regional TGW route table pointing to the `us-east-1` TGW for 0.0.0.0/0.
  4. DConfigure a default route (0.0.0.0/0) in each Transit Gateway attachment route table pointing to the security VPC attachment.
Show answer & explanation

Correct answer: B. Enable Transit Gateway Appliance Mode on the attachment to the security VPC and configure a default route (0.0.0.0/0) in all other VPC's TGW route tables pointing to the security VPC attachment.

To ensure all traffic, including return traffic, is routed through a network appliance like a firewall, Transit Gateway Appliance Mode must be enabled on the attachment to the security VPC. This forces both ingress and egress traffic for a flow to use the same appliance. Then, a default route (0.0.0.0/0) in the Transit Gateway route tables associated with other VPCs, pointing to the security VPC attachment, will direct all internet-bound traffic through the firewall. For cross-region traffic, Transit Gateway Peering would also be necessary to route traffic to the central security VPC.

Why the other options are wrong

  • A. VPC route tables publish routes to the TGW, but the TGW route tables dictate routing between attachments. Publishing a default route from the security VPC itself doesn't configure the TGW to send all internet-bound traffic to that VPC for inspection, nor does it ensure symmetric routing.
  • C. While TGW peering is needed for cross-region communication, simply creating peering and static routes won't enforce symmetric routing through the appliance for stateful inspection; Appliance Mode is crucial.
  • D. This only configures the outbound path. Without Appliance Mode, return traffic might not go back through the appliance, breaking stateful inspection.

Transit Gateway Appliance Mode

A feature that ensures that traffic between two VPCs (or a VPC and the internet) traverses a network appliance, such as a firewall, in a consistent, symmetric manner.

  • Maintains symmetric routing for stateful appliances.
  • Enabled on a Transit Gateway attachment.
  • Critical for centralized ingress/egress inspection VPCs.

Memory trick: Appliance Mode makes traffic flow through the funnel, always.

More Network Implementation questions