A financial institution requires strict network segmentation and isolation for different environments (e.g., development, staging, production) within a single AWS account. Each environment has its own set of VPCs, and direct communication between them is strictly prohibited unless explicitly allowed through a central inspection point. How can this be architected using AWS Transit Gateway to enforce strict isolation and controlled inter-VPC communication?
- AUse AWS PrivateLink to connect specific services between VPCs in different environments.
- BCreate a central inspection VPC and attach all environment VPCs to the Transit Gateway, routing all inter-VPC traffic through the inspection VPC.
- CAttach all VPCs to a single Transit Gateway and use Transit Gateway route tables to control traffic between them.
- DDeploy separate Transit Gateways for each environment (Dev, Staging, Prod) and do not peer them.
Show answer & explanationAnswer & explanation
Correct answer: B. Create a central inspection VPC and attach all environment VPCs to the Transit Gateway, routing all inter-VPC traffic through the inspection VPC.
To enforce strict isolation and controlled inter-VPC communication through a central inspection point, the best approach is to attach all environment VPCs to a single Transit Gateway, and then route all traffic destined for other environments through a dedicated inspection VPC. This allows security appliances (e.g., firewalls, IDS/IPS) in the inspection VPC to scrutinize and filter all cross-environment traffic, ensuring strict adherence to security policies before it reaches its destination.
Why the other options are wrong
- A. PrivateLink is for consuming specific services privately, not for general inter-VPC communication and central inspection of all traffic.
- C. While Transit Gateway route tables can control traffic, they don't inherently force traffic through a central inspection point for deep packet inspection unless specifically configured with an inspection VPC.
- D. Deploying separate Transit Gateways for each environment achieves isolation but prevents any inter-VPC communication, even controlled, which contradicts the 'explicitly allowed through a central inspection point' requirement.
Transit Gateway Centralized Inspection
A pattern where all inter-VPC traffic is routed through a dedicated inspection VPC attached to a Transit Gateway, enabling centralized security policy enforcement.
- Uses a dedicated 'inspection' VPC with security appliances.
- All spoke VPCs attach to a Transit Gateway.
- Transit Gateway route tables are configured to direct cross-VPC traffic via the inspection VPC.
Memory trick: For 'strict' inter-VPC control, 'inspect' all traffic 'centrally'.