How to set transit gateway as Target for the default route “local” route for for inter-subnet (east-west) inspection through firewall deployed in separate networking account

0

Dear All,

We have different workload accounts and centralize networking account where we have deployed AWS network firewall for inter-subnet (east-west) traffic inspection. We would like to have the centralize firewall for east-west traffic for all accounts and each subnet within VPC should go to transit gateway and then to firewall (inspection of east-west) deployed in networking account.

Kindly guide how to route the default local route (like 10.0.0.0/16) to transit gateway. Is it supported?

I have tried to set the transit gateway eni (network interface) as a target for default route

3개 답변
0

Hi Tushar,

Thank you for responding. I have reviewed the articles, and they focus on east-west traffic inspection between VPCs. However, in our scenario, we intend to route different subnets of a single VPC through the firewall. The firewall is deployed in the network account and connected via a transit gateway.

답변함 5달 전
  • Thanks for the clarification. I updated my answer.

0

Hi,

So to route the traffic between different subnets of a single VPC, a AWS network firewall in each VPC needs to deploy?

We can not have a centralized AWS network firewall for traffic inspection of subnets in same VPC.

답변함 5달 전
  • That is correct.

0

You can not route traffic between different subnets of a single VPC via TGW and inspection VPC.

For your use-case you can use the VPC MSR (more specific routing) feature to steer the traffic via ANFW, see the below blog (see the pattern: "AWS Network Firewall is deployed to protect traffic between two different subnets in the same VPC.")

https://aws.amazon.com/blogs/networking-and-content-delivery/deployment-models-for-aws-network-firewall-with-vpc-routing-enhancements/

profile pictureAWS
전문가
답변함 5달 전
profile picture
전문가
검토됨 5달 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠