A multinational corporation has multiple business units, each with its own AWS accounts. They want to implement a centralized network architecture that allows secure and controlled communication between all accounts and on-premises data centers, while also enabling internet access for specific applications. The solution must simplify network management, enforce security policies consistently, and support future expansion. Which networking construct should a solutions architect recommend?
- ACreate a large, shared VPC for all business units, manage subnets centrally, and use Network ACLs and Security Groups for inter-business unit traffic control.
- BUse VPC Peering connections between all relevant VPCs and establish separate Direct Connect connections for each account to the on-premises data centers.
- CImplement AWS PrivateLink for secure connectivity between services across accounts and use AWS Client VPN for remote access to specific applications requiring internet access.
- DDeploy AWS Transit Gateway in a dedicated networking account, connect all business unit VPCs and Direct Connect Gateways to it, and route internet traffic through a centralized NAT Gateway in the networking account.
Show answer & explanationAnswer & explanation
Correct answer: D. Deploy AWS Transit Gateway in a dedicated networking account, connect all business unit VPCs and Direct Connect Gateways to it, and route internet traffic through a centralized NAT Gateway in the networking account.
AWS Transit Gateway centralizes network connectivity for multiple VPCs and on-premises networks, simplifying routing and management. Placing it in a dedicated networking account ensures segregation. Centralized NAT Gateway provides controlled and auditable internet access. This approach scales well and enforces consistent security.
Why the other options are wrong
- A. A large, shared VPC can lead to complex security management and potential resource contention between business units, defeating the purpose of separate accounts. It also doesn't inherently simplify on-premises connectivity.
- B. VPC Peering does not scale well for a large number of VPCs (n*n connections) and doesn't simplify routing. Separate Direct Connect connections for each account would be costly and complex to manage.
- C. AWS PrivateLink provides private connectivity to specific services, not a general network routing solution for inter-VPC and on-premises communication. AWS Client VPN is for remote user access, not for centralized application internet access.
AWS Transit Gateway
A network transit hub that connects VPCs and on-premises networks, simplifying network architecture and centralizing routing.
- Acts as a regional virtual router.
- Simplifies network management for multi-VPC/multi-account environments.
- Supports VPN, Direct Connect, and VPC attachments.
Memory trick: Transit Gateway centralizes, simplifying all connections.