AWS Certified Advanced Networking – Specialty (ANS-C01)Network DesignMedium

A software development company uses AWS Organizations to manage multiple accounts, with each team owning several VPCs. They need to implement a centralized egress strategy for all internet-bound traffic from Development VPCs to ensure all traffic passes through a set of security appliances (firewalls, IDS/IPS) in a dedicated Egress VPC before reaching the public internet. This must apply to both IPv4 and IPv6 traffic. How can this be achieved efficiently?

  1. ADeploy an AWS Transit Gateway, attach all Development VPCs and the Egress VPC, and configure Transit Gateway route tables to direct all internet-bound IPv4 and IPv6 traffic from Development VPCs to the Egress VPC.
  2. BConfigure a NAT Gateway and a separate Egress-only Internet Gateway in each Development VPC, routing traffic through them.
  3. CUse AWS Global Accelerator to front the security appliances in the Egress VPC and direct all Development VPC traffic to the Global Accelerator.
  4. DEstablish VPC peering connections between each Development VPC and the Egress VPC, then route traffic through a NAT Gateway in the Egress VPC.
Show answer & explanation

Correct answer: A. Deploy an AWS Transit Gateway, attach all Development VPCs and the Egress VPC, and configure Transit Gateway route tables to direct all internet-bound IPv4 and IPv6 traffic from Development VPCs to the Egress VPC.

Transit Gateway provides a central hub for VPC connectivity. By attaching all Development and Egress VPCs to the TGW, and then configuring TGW route tables to forward all internet-bound traffic (0.0.0.0/0 for IPv4 and ::/0 for IPv6) from Development VPCs to the Egress VPC, centralized egress through security appliances can be achieved efficiently for both IPv4 and IPv6.

Why the other options are wrong

  • B. This is a decentralized approach, requiring duplicate security appliances and management in each VPC, which is not efficient or centralized.
  • C. Global Accelerator is for improving application performance over the internet, not for routing internal VPC traffic through a centralized egress point with security appliances.
  • D. VPC peering creates a mesh, which is not scalable for many VPCs, and it doesn't inherently support centralized egress for both IPv4 and IPv6 without complex routing.

Centralized Egress with TGW (IPv4/IPv6)

An architecture where all internet-bound traffic from multiple spoke VPCs is routed through a central Egress VPC via AWS Transit Gateway. This allows for unified inspection and security enforcement using shared security appliances for both IPv4 and IPv6 traffic.

  • Uses AWS Transit Gateway as a central hub.
  • All internet-bound traffic from spoke VPCs routes to a dedicated Egress VPC.
  • Security appliances (firewalls, IDS/IPS) are deployed in the Egress VPC.
  • Simplifies network architecture and security policy enforcement.
  • Supports both IPv4 and IPv6 traffic routing.

Memory trick: Transit Gateway is the 'Traffic Cop' for all IPv4/IPv6 egress.

More Network Design questions