AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationHard
A solutions architect is designing a network for a new application that will host multiple microservices in a single VPC. Each microservice needs to operate in its own isolated subnet and communicate with other microservices as well as an external API over the internet. The architect wants to ensure that all outbound traffic from the microservice subnets is routed through a centralized firewall appliance deployed in a dedicated subnet. How can this be achieved while maintaining high availability and minimizing network complexity?
- ACreate an internet gateway for each microservice subnet and configure routes to send traffic to the firewall.
- BConfigure a NAT Gateway in each microservice subnet and route traffic through it to the firewall.
- CDeploy a Gateway Load Balancer endpoint in each microservice subnet and route default traffic to the GWLB.
- DUse a Transit Gateway to route traffic from each microservice subnet to the firewall subnet.
Show answer & explanationAnswer & explanation
Correct answer: C. Deploy a Gateway Load Balancer endpoint in each microservice subnet and route default traffic to the GWLB.
Gateway Load Balancer (GWLB) is specifically designed to insert third-party virtual appliances, such as firewalls, into a network path. By deploying a GWLB endpoint in each microservice subnet and routing default traffic to it, all outbound traffic will transparently pass through the centralized firewall appliance for inspection before reaching its destination.
Why the other options are wrong
- A. Creating an internet gateway for each subnet would not centralize traffic through a firewall appliance and would increase network complexity.
- B. NAT Gateway provides NAT functionality but does not inherently provide a mechanism to insert a centralized firewall appliance for all outbound traffic inspection.
- D. While Transit Gateway can route traffic between subnets, it doesn't natively provide the transparent appliance insertion capability of a Gateway Load Balancer without additional complex routing configurations, and it's generally used for inter-VPC or hybrid connectivity.
Gateway Load Balancer (GWLB)
A service that makes it easy to deploy, scale, and manage virtual appliances such as firewalls, intrusion detection systems, and deep packet inspection systems.
- Transparently inserts appliances into the network path.
- Operates at Layer 3 (IP protocol) and Layer 4 (TCP/UDP).
- Supports high availability and auto-scaling of appliances.
Memory trick: Gateway Load Balancer is the 'Guardian' for your 'Gateways' to the internet.