Transit Gateway data encryption
Hi, can anybody tell me if and how data is protected while it passes through a Transit Gateway? Consider following setup:
A <-----> TGW <-----> B IPSec ??? IPSec
Traffic is encrypted between A and TGW and between TGW and B, but what about "within" TGW? Pointers to any documentation about what happens there highly appreciated...
There's some detail missing here - how are the IPSEC tunnels being created? Are A and B instances or sites?
If I assume that you're using the AWS VPN service and that A and B are sites: The traffic within Transit Gateway is not encrypted. Think of Transit Gateway as a cloud-scale router. If you had a router that terminated two IPSEC tunnels and routed between them the traffic on the router is not encrypted as it passes through that device. That's because the router must decrypt the packet from (say) A, determine the appropriate destination (B in this case) and then encrypt it again before sending it onto B.
In general, there are many places in every network where (at least) the IP (and perhaps TCP) headers of a packet need to be visible in order to route the packet(s) correctly. For the payload to remain encrypted at that point requires application-layer security such as TLS. It's the only way to achieve end-to-end encryption between two hosts.
Thanks for your reply and sorry for not being entirely clear. Yes, A and B are meant to be sites using the AWS VPN service.
Think of Transit Gateway as a cloud-scale router
This is what I expected, I just wanted to make sure.
AWS Transit Gateway monitoring with CloudwatchAccepted Answerasked 2 years ago
Transit Gateway data encryptionAccepted Answerasked 3 months ago
AWS Transit Gateway attachment pricingAccepted Answerasked 2 years ago
Data Transfer OUT Charges Through TGW in Another AccountAccepted Answerasked 3 years ago
Transit Gateway to AWS Instance Encryptionasked 3 months ago
Modify Transit Gateway Properties After CreationAccepted Answerasked 3 years ago
Transit Gateway to Direct Connect Gateway to Transit GatewayAccepted Answerasked 2 years ago
AWS Transit Gateway peering encryptionAccepted Answerasked 2 years ago
AWS Transit Gateway through BGP propagation and routing behaviorAccepted Answerasked 2 years ago
Migration from Transit VPC to AWS Transit GatewayAccepted Answerasked 2 years ago