AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationHard

A company requires a highly secure and compliant network architecture for its sensitive data in AWS. All EC2 instances in private subnets must have outbound internet access for patching and updates, but all traffic must be inspected by a third-party firewall appliance. The solution needs to be highly available and scale automatically. Which approach should a network architect choose?

  1. AUse a Transit Gateway to connect all private subnets to a shared services VPC containing an Internet Gateway.
  2. BImplement a Gateway Load Balancer (GWLB) in a dedicated inspection VPC, and route private subnet traffic through GWLB endpoints.
  3. CDeploy a NAT Gateway in each private subnet and configure routes to send traffic through it to the Internet Gateway.
  4. DConfigure a custom proxy server on an EC2 instance in a public subnet and route all private subnet traffic through it.
Show answer & explanation

Correct answer: B. Implement a Gateway Load Balancer (GWLB) in a dedicated inspection VPC, and route private subnet traffic through GWLB endpoints.

Gateway Load Balancer (GWLB) is designed for transparent insertion of virtual appliances like firewalls. By deploying GWLB in an inspection VPC with the firewall appliances and routing all internet-bound traffic from private subnets through GWLB endpoints, the solution achieves centralized inspection, high availability, and scalability.

Why the other options are wrong

  • A. While Transit Gateway can centralize routing, it doesn't natively provide the transparent appliance insertion capability required for inspecting all traffic without additional complex routing and potentially a GWLB.
  • C. NAT Gateway provides outbound internet access but does not allow for transparent insertion of a third-party firewall appliance for inspection.
  • D. A custom proxy server on EC2 instances is less scalable, lacks the built-in high availability of managed services, and adds significant operational overhead compared to GWLB.

Gateway Load Balancer (GWLB) Appliance Insertion

A service that enables transparent deployment, scaling, and management of virtual network appliances (like firewalls) by redirecting traffic through them.

  • Transparently inserts security appliances into the network path.
  • Scales appliances automatically based on traffic.
  • Supports high availability for critical network functions.

Memory trick: GWLB is the 'Gatekeeper' for all outbound internet traffic.

More Network Implementation questions