Two production VPCs (VPC A and VPC B) span all AZs in us-east-1. A new regulation requires all traffic between these production VPCs to be inspected. The company deployed a shared VPC with a stateful firewall and a transit gateway attachment across all VPCs so traffic between VPC A and VPC B routes through the firewall. During testing, the transit gateway drops traffic when it flows between two Availability Zones. What change should the network engineer make to fix this with the LEAST management overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable transit gateway appliance mode on the VPC attachment in the shared VPC..
Why this is the answer
The correct answer is to enable transit gateway appliance mode on the VPC attachment in the shared VPC. This mode ensures that traffic returning to the source VPC through the appliance (firewall) is routed back to the same appliance instance that processed the initial traffic, even if the instances are in different Availability Zones. This prevents asymmetric routing and traffic drops, which is a common issue with stateful appliances and TGWs. Replacing the VPC attachment with a VPN attachment adds significant management overhead and complexity without directly addressing the asymmetric routing problem. Enabling appliance mode on VPC A and VPC B attachments is incorrect because the firewall appliance is located in the shared VPC, not in the production VPCs. VPC peering is not suitable here as it doesn't integrate with the Transit Gateway for centralized routing and inspection, and would require separate peering connections for each VPC.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed