A software development company has multiple development VPCs in different AWS accounts, all within the same region. They need to establish secure and efficient communication between these development VPCs for various microservices and shared tooling. The security team also requires that specific development environments (e.g., 'feature-dev' vs. 'bugfix-dev') maintain network isolation, only allowing explicitly permitted traffic. Which AWS networking solution provides the most scalable and manageable way to connect these VPCs while enforcing segmentation?
- AVPC Peering connections between each development VPC.
- BSite-to-Site VPN tunnels between all development VPCs.
- CAWS Transit Gateway with separate route tables for each VPC attachment.
- DAWS PrivateLink for inter-VPC service consumption.
Show answer & explanationAnswer & explanation
Correct answer: C. AWS Transit Gateway with separate route tables for each VPC attachment.
AWS Transit Gateway is designed for connecting thousands of VPCs and on-premises networks. By using separate Transit Gateway route tables for each VPC attachment, you can implement fine-grained network segmentation. This allows you to control which VPCs can communicate with each other, centralize routing, and manage connectivity efficiently across multiple accounts, which is highly scalable and manageable.
Why the other options are wrong
- A. VPC peering connections create a full mesh, which becomes unmanageable and unscalable for many VPCs, making it difficult to enforce granular segmentation policies.
- B. Site-to-Site VPNs are generally for connecting on-premises networks to AWS VPCs, and using them for inter-VPC connectivity would be overly complex and not as scalable as Transit Gateway.
- D. PrivateLink is for private service consumption across VPCs, not for general inter-VPC connectivity and network segmentation of entire VPCs.
TGW for Multi-VPC Segmentation
Utilizing AWS Transit Gateway with distinct route tables per VPC attachment to achieve scalable and manageable network segmentation across multiple VPCs and AWS accounts.
- TGW acts as a central routing hub.
- Supports connections across thousands of VPCs.
- Separate TGW route tables enable granular segmentation.
- Simplifies network architecture for multi-account environments.
- Allows for centralized control and inspection points.
Memory trick: TGW's route tables, a segment for each, connecting VPCs, within easy reach!