A software development company uses AWS Organizations to manage multiple accounts, with each team owning several VPCs. They need to implement a centralized egress strategy for all internet-bound traffic from Development VPCs to ensure all traffic passes through a set of security appliances (firewalls, IDS/IPS) in a dedicated Egress VPC before reaching the public internet. This must apply to both IPv4 and IPv6 traffic. How can this be achieved efficiently?
- ADeploy an AWS Transit Gateway, attach all Development VPCs and the Egress VPC, and configure Transit Gateway route tables to direct all internet-bound IPv4 and IPv6 traffic from Development VPCs to the Egress VPC.
- BConfigure a NAT Gateway and a separate Egress-only Internet Gateway in each Development VPC, routing traffic through them.
- CUse AWS Global Accelerator to front the security appliances in the Egress VPC and direct all Development VPC traffic to the Global Accelerator.
- DEstablish VPC peering connections between each Development VPC and the Egress VPC, then route traffic through a NAT Gateway in the Egress VPC.
Show answer & explanationAnswer & explanation
Correct answer: A. Deploy an AWS Transit Gateway, attach all Development VPCs and the Egress VPC, and configure Transit Gateway route tables to direct all internet-bound IPv4 and IPv6 traffic from Development VPCs to the Egress VPC.
Transit Gateway provides a central hub for VPC connectivity. By attaching all Development and Egress VPCs to the TGW, and then configuring TGW route tables to forward all internet-bound traffic (0.0.0.0/0 for IPv4 and ::/0 for IPv6) from Development VPCs to the Egress VPC, centralized egress through security appliances can be achieved efficiently for both IPv4 and IPv6.
Why the other options are wrong
- B. This is a decentralized approach, requiring duplicate security appliances and management in each VPC, which is not efficient or centralized.
- C. Global Accelerator is for improving application performance over the internet, not for routing internal VPC traffic through a centralized egress point with security appliances.
- D. VPC peering creates a mesh, which is not scalable for many VPCs, and it doesn't inherently support centralized egress for both IPv4 and IPv6 without complex routing.
Centralized Egress with TGW (IPv4/IPv6)
An architecture where all internet-bound traffic from multiple spoke VPCs is routed through a central Egress VPC via AWS Transit Gateway. This allows for unified inspection and security enforcement using shared security appliances for both IPv4 and IPv6 traffic.
- Uses AWS Transit Gateway as a central hub.
- All internet-bound traffic from spoke VPCs routes to a dedicated Egress VPC.
- Security appliances (firewalls, IDS/IPS) are deployed in the Egress VPC.
- Simplifies network architecture and security policy enforcement.
- Supports both IPv4 and IPv6 traffic routing.
Memory trick: Transit Gateway is the 'Traffic Cop' for all IPv4/IPv6 egress.