Home icon

Design and build IPv6 internet inspection architectures on AWS

Networking & Content Delivery Blog



This article provides a comprehensive guide to designing and implementing IPv6 internet inspection architectures on AWS, focusing on secure egress and ingress traffic management.

  • Covers two main approaches for IPv6 deployment: dual stack and IPv6-only
  • Explains internet connectivity methods using Egress-only Internet Gateway (EIGW) and Internet Gateway (IGW)
  • Describes three primary traffic inspection patterns:
    • Distributed egress and ingress inspection
    • Centralized ingress inspection
    • Centralized egress inspection
  • Provides detailed steps for configuring Gateway Load Balancer (GWLB) and endpoint services for dual-stack operation

Key considerations include supporting NAT66/NPTv6, ensuring appliance compatibility with GENEVE protocol, and maintaining proper routing and security configurations for IPv6 traffic.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

May 20
2025
AWS Organizations now supports Internet Protocol Version 6 (IPv6)
Sep 16
2026
Choosing the right inspection architecture for AWS Network Firewall
Jun 4
2025
AWS Resource Groups now supports IPv6
Jun 23
2025
AWS Private CA now supports Internet Protocol Version 6 (IPv6)

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.