
AWS Certified Advanced Networking – Specialty (ANS-C01) Certification Guide
By :

With the advent of Gateway Load Balancer (GWLB), the recommended TGW inspection VPC design has changed a bit to include that, but here is the inspection VPC design without GWLB first. Note that the TGW is being used to control the connectivity and the routing from east-west flows between VPCs to force inspection by a security appliance – in this case, AWS Firewall. The following figure depicts an inspection VPC design using AWS Firewall:
Figure 5.19: TGW with an inspection VPC design using AWS Firewall
Understanding the route table flows is key to understanding how security appliance insertion/redirection works in the cloud. The traffic flow is shown in Figure 5.19. Each step in the flow of traffic between VPCs is marked: