A global company uses AWS Transit Gateway to connect its numerous VPCs across multiple regions. They have a requirement to centrally inspect all east-west traffic (VPC-to-VPC) for security and compliance purposes using a set of third-party network virtual appliances. The appliances reside in a dedicated inspection VPC. How can the network engineer configure Transit Gateway to meet this requirement efficiently?
- ADeploy a Network Load Balancer (NLB) in the inspection VPC and route all traffic through it.
- BAttach the inspection VPC to the Transit Gateway and configure static routes on each spoke VPC to direct traffic to the inspection VPC.
- CAttach the inspection VPC to the Transit Gateway and use a Transit Gateway route table with appliance mode enabled to steer traffic.
- DSet up VPC peering between all spoke VPCs and the inspection VPC.
Show answer & explanationAnswer & explanation
Correct answer: C. Attach the inspection VPC to the Transit Gateway and use a Transit Gateway route table with appliance mode enabled to steer traffic.
Transit Gateway's appliance mode, when enabled on an attachment, ensures that traffic is symmetrically routed to a specific network appliance. This is crucial for stateful inspection devices. By attaching the inspection VPC to the Transit Gateway and configuring the route tables with appliance mode, all east-west traffic can be steered through the virtual appliances for centralized inspection.
Why the other options are wrong
- A. NLB operates at Layer 4 and is not designed for transparently steering all east-west traffic through a centralized inspection VPC with third-party appliances in this manner.
- B. Configuring static routes on each spoke VPC to direct traffic to the inspection VPC is complex, prone to errors, and does not inherently ensure symmetric routing required for stateful inspection, which appliance mode provides.
- D. VPC peering is not scalable for numerous VPCs and does not provide centralized inspection through a single set of appliances efficiently.
Transit Gateway Appliance Mode
A feature of AWS Transit Gateway that ensures traffic symmetrically returns to the same appliance for stateful inspection, enabling centralized network security.
- Ensures symmetric routing for stateful appliances
- Enabled on a Transit Gateway VPC attachment
- Critical for centralized firewall/IDS/IPS deployments
- Simplifies network security architecture
Memory trick: Appliance Mode keeps the traffic flowing through the same security gate for inspection.