A global enterprise is expanding its AWS footprint across multiple regions and accounts. They have a strict requirement for network segmentation, ensuring that specific environments (e.g., Development, Staging, Production) cannot communicate directly with each other, even if they reside in different VPCs within the same region or across regions, unless explicitly allowed through a centralized firewall. All inter-VPC traffic must flow through a central hub. Which AWS networking service and configuration strategy will best achieve this granular network segmentation?
- ADirect Connect Gateway with associated private VIFs.
- BVPC peering connections with Network ACLs and Security Groups.
- CAWS Transit Gateway with separate route tables for each attachment.
- DAWS Cloud WAN with a single global network segment.
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Transit Gateway with separate route tables for each attachment.
AWS Transit Gateway is ideal for complex multi-VPC connectivity. By associating different VPC attachments with separate Transit Gateway route tables, you can implement fine-grained network segmentation. Each route table can be configured to allow or deny traffic to specific destinations, effectively isolating environments and forcing traffic through a centralized firewall VPC attached to the TGW, ensuring strict control over inter-VPC communication.
Why the other options are wrong
- A. Direct Connect Gateway is for connecting on-premises networks to multiple VPCs/TGWs, not for inter-VPC segmentation within AWS.
- B. VPC peering creates a full mesh for many VPCs, which is unmanageable for strict segmentation and doesn't allow for centralized traffic inspection without complex routing.
- D. AWS Cloud WAN provides a global network, but a 'single global network segment' would defeat the purpose of 'strict network segmentation' between different environments.
TGW Network Segmentation
Using AWS Transit Gateway's route tables to control and isolate traffic flow between connected VPCs, enabling granular network segmentation for different environments or purposes.
- TGW acts as a central hub for all inter-VPC traffic.
- Each VPC attachment can be associated with a unique TGW route table.
- Allows explicit control over which VPCs can communicate.
- Enables forcing traffic through a centralized security VPC.
- Scalable for hundreds or thousands of VPCs.
Memory trick: TGW's route tables, a segmented domain, keeping environments apart, again and again!