A software development company has multiple development VPCs in different AWS accounts, all connected to a central Transit Gateway. They need to implement a network segmentation strategy to ensure that traffic from one development VPC cannot directly reach another development VPC, but all development VPCs must be able to reach a shared services VPC. Which Transit Gateway routing configuration will achieve this?
- ASeparate Transit Gateway route tables for each development VPC, each associated with its respective VPC, and a shared services route table.
- BNetwork ACLs on each subnet to block traffic between development VPCs.
- CA single Transit Gateway route table where all VPC attachments are associated and propagated.
- DVPC peering connections configured between the shared services VPC and each development VPC.
Show answer & explanationAnswer & explanation
Correct answer: A. Separate Transit Gateway route tables for each development VPC, each associated with its respective VPC, and a shared services route table.
By using separate Transit Gateway route tables for each development VPC, and associating each development VPC with its own route table, you prevent direct routing between development VPCs. Each development VPC's route table would only have routes to the shared services VPC and potentially to on-premises networks, but not to other development VPCs. The shared services VPC would have a route table allowing access from all development VPCs.
Why the other options are wrong
- B. Network ACLs provide stateless filtering at the subnet level but do not solve the routing problem of preventing inter-VPC traffic at the Transit Gateway level, requiring complex and error-prone management.
- C. A single route table with propagation would allow all VPCs to reach each other, violating the segmentation requirement.
- D. VPC peering creates a mesh network and is not scalable for many VPCs, nor does it integrate well with TGW for centralized routing policy.
TGW Network Segmentation
Using AWS Transit Gateway route tables to control traffic flow between attached VPCs, enabling granular network segmentation.
- Multiple TGW route tables provide fine-grained control.
- Associations link VPCs to specific route tables.
- Propagations automatically learn routes from attachments.
Memory trick: Transit Gateway route tables are like traffic cops, directing which VPCs can talk to whom.