AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignMedium

A security-conscious organization requires all outbound internet traffic from its development and test VPCs to be inspected by a third-party firewall appliance. These VPCs are in different accounts but within the same AWS Region. The solution must be scalable, minimize routing complexity, and ensure that no traffic can bypass the firewall. What is the most effective architecture to implement this?

  1. AUse VPC Peering between each development/test VPC and a central inspection VPC with the firewall.
  2. BDeploy a NAT Gateway in each development and test VPC and route traffic through it.
  3. CDeploy AWS Transit Gateway and create a centralized Egress VPC with the firewall appliance.
  4. DConfigure individual Internet Gateways for each development/test VPC with specific route table entries.
Show answer & explanation

Correct answer: C. Deploy AWS Transit Gateway and create a centralized Egress VPC with the firewall appliance.

Deploying AWS Transit Gateway with a centralized Egress VPC allows all outbound internet traffic from spoke VPCs (development/test) to be routed through a single inspection VPC containing the firewall appliance. This centralizes inspection, simplifies routing, and ensures compliance without bypassing the firewall.

Why the other options are wrong

  • A. VPC Peering creates a mesh network which becomes complex and unscalable with many VPCs, and doesn't inherently force all egress through a central firewall.
  • B. NAT Gateway provides outbound internet connectivity but does not allow for centralized third-party firewall inspection of all traffic.
  • D. Individual Internet Gateways do not centralize traffic for inspection; traffic would go directly to the internet, bypassing the firewall.

Centralized Egress VPC with Transit Gateway

An architecture where multiple spoke VPCs route all outbound internet traffic through a single, dedicated Egress VPC containing security appliances, managed by AWS Transit Gateway.

  • Centralized security inspection (firewall)
  • Simplifies routing for multiple VPCs
  • Ensures all egress traffic is inspected
  • Scalable hub-and-spoke model

Memory trick: TGW funnels all traffic through the firewall's watchful eye.

More Network Design questions