A DevOps team is developing a new application that will process highly sensitive customer data. The application will run on Amazon EC2 instances within a private subnet. The security team mandates that all outgoing internet traffic from these instances must be inspected and filtered by a third-party firewall appliance running in an inspection VPC before reaching the public internet to ensure compliance with data exfiltration policies. How can this network architecture be implemented MOST effectively?
- ADeploy the firewall appliance within the application VPC's private subnet and configure a default route to it.
- BSet up a Transit Gateway to connect the application VPC to the inspection VPC, routing internet-bound traffic through the firewall appliance.
- CUse a VPC Endpoint for S3 and other AWS services to prevent direct internet access, and manually configure proxy settings on EC2 instances for other internet traffic.
- DConfigure a NAT Gateway in the private subnet and route all traffic through it to the internet.
Show answer & explanationAnswer & explanation
Correct answer: B. Set up a Transit Gateway to connect the application VPC to the inspection VPC, routing internet-bound traffic through the firewall appliance.
Using a Transit Gateway to connect the application VPC to an inspection VPC (where the firewall appliance resides) allows for centralized routing and inspection of all internet-bound traffic, fulfilling the requirement for mandatory third-party firewall inspection before reaching the public internet.
Why the other options are wrong
- A. Deploying the firewall within the application VPC doesn't allow for a centralized inspection model across multiple VPCs or enforce inspection for all outbound traffic if multiple subnets or routes exist.
- C. VPC Endpoints secure access to AWS services, but don't address general internet outbound traffic inspection by a third-party firewall.
- D. A NAT Gateway allows outbound internet access but does not provide a mechanism to route traffic through a third-party firewall in a separate inspection VPC.
Centralized Egress Inspection with TGW
A Transit Gateway (TGW) facilitates centralized egress traffic inspection by routing all internet-bound traffic from spoke VPCs through an inspection VPC containing a firewall appliance, before reaching the Internet Gateway.
- TGW simplifies inter-VPC routing at scale.
- Enables hub-and-spoke network topology.
- Allows for mandatory traffic inspection before internet access.
Memory trick: All 'traffic' must 'pass' through the 'transit' 'inspection' 'gate'.