Transit Gateway and AWS Network Firewall

0

Currently we are using the Virtual firewall with Transit Gateway, can you please share the steps and best practice to transition from Virtual Firewall to AWS Network Firewall. Now Virtual FW is deployed on the Inspection VPC which is attached with the transit gateway and which is not behaving as expected.

Edited by: SunnyKbmf on Jul 9, 2021 2:49 PM

질문됨 3년 전1835회 조회
2개 답변
0
수락된 답변

You can follow this blog to transitioning from Network Virtual appliances to Network Firewall.

https://aws.amazon.com/blogs/networking-and-content-delivery/deployment-models-for-aws-network-firewall/

Following deployment models are explained in this blog -

  1. Distributed AWS Network Firewall deployment model: AWS Network Firewall is deployed into each individual VPC.
  2. Centralized AWS Network Firewall deployment model: AWS Network Firewall is deployed into centralized VPC for East-West (VPC-to-VPC) and/or North-South (internet egress and ingress, on-premises) traffic. We refer to this VPC as inspection VPC throughout this blog post.
  3. Combined AWS Network Firewall deployment model: AWS Network Firewall is deployed into centralized inspection VPC for East-West (VPC-to-VPC) and subset of North-South (On Premises/Egress) traffic. Internet ingress is distributed to VPCs which require dedicated inbound access from the internet and AWS Network Firewall is deployed accordingly.

You can refer this blog for routing configuration however this is GLB use case.
https://aws.amazon.com/blogs/networking-and-content-delivery/centralized-inspection-architecture-with-aws-gateway-load-balancer-and-aws-transit-gateway/

AWS
abhdey
답변함 3년 전
profile picture
전문가
검토됨 한 달 전
0

Thanks, this blog seems useful.

답변함 3년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인