An organization is migrating sensitive payment processing applications to AWS. These applications require a highly isolated network environment where no internet traffic is permitted, and all inbound and outbound traffic must be explicitly controlled and logged. They need to ensure that the application instances cannot reach the internet and the internet cannot reach them. Which networking design best achieves this level of isolation?
- ADeploy instances in public subnets with strict Security Group rules and Network ACLs.
- BDeploy instances in private subnets with a NAT Gateway for outbound internet access and a VPN connection for inbound corporate access.
- CDeploy instances in private subnets with an Internet Gateway, but block all traffic using Security Group rules.
- DDeploy instances in private subnets with no Internet Gateway, no NAT Gateway, and configure VPC Endpoints for access to necessary AWS services.
Show answer & explanationAnswer & explanation
Correct answer: D. Deploy instances in private subnets with no Internet Gateway, no NAT Gateway, and configure VPC Endpoints for access to necessary AWS services.
To achieve a highly isolated network where no internet traffic is permitted, instances must be placed in private subnets. Crucially, there should be no Internet Gateway attached to the VPC and no NAT Gateway configured, as these enable internet connectivity. VPC Endpoints allow secure, private access to AWS services (like S3 or DynamoDB) without traversing the internet, maintaining complete isolation.
Why the other options are wrong
- A. Public subnets inherently allow internet traffic, even with strict rules, violating the 'no internet traffic' requirement.
- B. A NAT Gateway provides outbound internet access, which violates the 'no internet traffic is permitted' requirement.
- C. An Internet Gateway attached to the VPC means internet traffic is routed to the VPC, even if blocked by Security Groups, it's not the highest level of isolation. Furthermore, it doesn't prevent instances from *trying* to reach the internet, only blocks the response.
Isolated VPC Design
A VPC design that completely restricts internet access for instances by using private subnets, no Internet Gateway, no NAT Gateway, and leveraging VPC Endpoints for AWS service access.
- Instances deployed in private subnets.
- No Internet Gateway attached to the VPC.
- No NAT Gateway configured.
- VPC Endpoints provide private connectivity to AWS services.
- Achieves maximum network isolation from the internet.
Memory trick: No Gateway, Private Subnets, VPC Endpoints: The 'NGPVE' of isolation.