AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignEasy
A large e-commerce company uses AWS for its entire infrastructure. They have multiple production VPCs across different AWS accounts within the same AWS Region. The security team mandates that all outbound internet traffic from these production VPCs must be inspected and filtered by a centralized set of security appliances (firewalls, IDS/IPS) hosted in a dedicated 'Security VPC'. Which AWS networking service should be used to achieve this centralized egress routing for all production VPCs?
- AAWS VPN CloudHub
- BAWS Direct Connect
- CVPC Peering
- DAWS Transit Gateway
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Transit Gateway
AWS Transit Gateway is designed to centralize routing for multiple VPCs, including across different accounts, within a region. It allows for a 'hub-and-spoke' model where all VPCs attach to the Transit Gateway, and egress traffic can be routed through a centralized Security VPC containing the inspection appliances.
Why the other options are wrong
- A. AWS VPN CloudHub is used to connect multiple on-premises networks to a single AWS VPC using VPN connections, not for inter-VPC routing within AWS.
- B. Direct Connect provides a dedicated network connection from on-premises to AWS, not for inter-VPC routing within AWS.
- C. VPC peering creates a direct connection between two VPCs, but it does not scale well for many VPCs and cannot easily centralize egress traffic through a single point.
Centralized Egress with TGW
Using AWS Transit Gateway to route all outbound internet traffic from multiple VPCs through a single, dedicated Security VPC for inspection and filtering.
- TGW acts as a central hub.
- Simplifies network management for many VPCs.
- Enables consistent security policy enforcement.
- Security VPC hosts firewalls/IDS/IPS.
Memory trick: One way out, through the gate, security checked, no debate!