A company is deploying a new web application on Amazon EC2 instances within a Virtual Private Cloud (VPC). The application requires outbound internet access to retrieve third-party APIs but should not be directly accessible from the internet. The security team also requires that all outbound traffic from the application instances passes through a centralized inspection point for deep packet inspection. How should this network architecture be designed to meet these requirements securely and efficiently?
- ADeploy EC2 instances in private subnets, route outbound traffic through a NAT instance in a public subnet, and use VPC Flow Logs for inspection.
- BDeploy EC2 instances in private subnets, route outbound traffic through a NAT Gateway in a public subnet, and then through a Network Firewall in another public subnet before reaching an Internet Gateway.
- CDeploy EC2 instances in public subnets, use Network ACLs to block inbound traffic, and route outbound traffic through a VPC endpoint.
- DDeploy EC2 instances in public subnets with Security Groups allowing outbound traffic, and configure an Internet Gateway.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploy EC2 instances in private subnets, route outbound traffic through a NAT Gateway in a public subnet, and then through a Network Firewall in another public subnet before reaching an Internet Gateway.
Deploying EC2 instances in private subnets ensures they are not publicly accessible. Routing outbound traffic through a NAT Gateway provides internet access without direct inbound connections. Placing an AWS Network Firewall after the NAT Gateway, but before the internet gateway, allows for centralized deep packet inspection of all outbound traffic, fulfilling the security team's requirement.
Why the other options are wrong
- A. While NAT instances can provide outbound access, they are less scalable and highly available than NAT Gateway. VPC Flow Logs provide metadata but not deep packet inspection of traffic content.
- C. Deploying instances in public subnets violates the requirement for no direct internet access. VPC endpoints are for private access to AWS services, not for general internet access or deep packet inspection of outbound traffic.
- D. Deploying instances in public subnets exposes them directly to the internet, violating the requirement for no direct internet access. It also lacks a centralized inspection point.
Secure Outbound Internet Access with Inspection
A VPC architecture pattern where private instances securely access the internet via a NAT Gateway, with all outbound traffic subjected to deep packet inspection by a Network Firewall.
- Private subnets for application instances.
- NAT Gateway for outbound internet access.
- AWS Network Firewall for centralized deep packet inspection.
Memory trick: Private Apps Need NAT and Firewall Guard!