Memory hook: Every stateful flow needs a coherent forward and return path through the same inspection context.
Must remember
- A Transit Gateway attachment associates with a route table used for traffic arriving from it; propagation supplies learned routes into selected tables. Separate tables can isolate environments while exposing shared services. VPC subnet route tables must also point to the correct attachment path.
- Place attachment subnets in the AZs that need connectivity. Overlapping VPC prefixes are not solved by propagation. Peering does not provide unrestricted transitive routing; distinguish VPC peering, TGW peering and supported route propagation behaviour.
- Centralised stateful inspection needs symmetric routing and appropriate appliance behaviour. TGW appliance mode helps preserve an appliance-AZ flow path on supported VPC attachments. GWLB distributes traffic to virtual appliances using GENEVE; Network Firewall provides managed network inspection. A bypass route can invalidate the security design even if the firewall itself is healthy.
- PrivateLink exposes a supported service through endpoints without broad network connectivity. Interface endpoints use ENIs, DNS and security groups; gateway endpoints route supported S3/DynamoDB traffic differently. Endpoint policies add controls but do not create missing identity/resource grants.
- IPv6 needs its own routes and controls. An egress-only internet gateway allows outbound IPv6 internet connectivity with responses; it is not IPv4 NAT. NAT64/DNS64 address specific IPv6-to-IPv4 access patterns. Check dual-stack service support and avoid assuming an IPv4 firewall rule protects IPv6.
- Use Flow Logs for connection metadata, Traffic Mirroring for supported packet inspection, Reachability Analyzer for configuration paths and CloudWatch for metrics. Monitor drops, throughput, connection counts and DNS errors. MTU, MSS and path-MTU discovery explain failures where small packets work but larger ones stall.
- Automate network changes through reviewed IaC, staged rollout and rollback; track IP space with IPAM, quotas and ownership. Compare NAT, endpoints, TGW processing, cross-AZ transfer and cross-Region transfer over the expected traffic volume. Lowest hourly infrastructure cost may not minimise total transfer cost.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Isolate production and test attached to one TGW | Separate association/propagation designs with only required routes. |
| Expose one service without joining whole networks | PrivateLink when supported. |
| Stateful firewall sees only one direction | Inspect symmetry, route tables and appliance-mode design. |
Traps
- A route existing in TGW does not create the VPC subnet route.
- A firewall can be bypassed by a more-specific route.
- Packet capture and flow metadata provide different evidence.
Active recall
1. What is the difference between association and propagation?
Association selects the TGW lookup table for incoming attachment traffic; propagation populates selected tables with routes.
2. Why is symmetry important for stateful inspection?
The inspector must correlate both directions of a connection.
3. Which control serves outbound-only IPv6 internet access?
An egress-only internet gateway, with appropriate routes and security rules.
4. Small requests work but large transfers fail. What should be examined?
MTU/MSS, fragmentation/path-MTU discovery and permitted control traffic.
5. Why can centralised NAT cost more than expected?
Cross-AZ/TGW processing and data transfer may outweigh savings from fewer gateways.