Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway
Networking & Content Delivery Blog
This article demonstrates centralized VPC inspection using Amazon VPC Route Server and AWS Transit Gateway to route multi-VPC traffic through shared firewall appliances with automatic failover.
- East-west inspection routes spoke-to-spoke traffic through centralized inspection with active-standby failover using BGP AS-path prepending
- North-south inspection extends the pattern to internet-bound traffic, with firewall instances routing inspected packets to internet gateways
- AZ-affinity inspection uses dual route servers to keep traffic local within Availability Zones under normal conditions, crossing AZ boundaries only during failover
- BGP dynamic routing automatically detects firewall failures and updates Transit Gateway route tables to redirect traffic to standby instances
- Provides alternative to Gateway Load Balancer when appliances lack GENEVE support or require active-standby failover with fine-grained BGP control
The approach enables resilient centralized inspection architectures for multi-VPC environments with automatic failover and optional AZ-affinity optimization.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2026
2023
2025
2025
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.