Home icon

Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway

Networking & Content Delivery Blog



This article demonstrates centralized VPC inspection using Amazon VPC Route Server and AWS Transit Gateway to route multi-VPC traffic through shared firewall appliances with automatic failover.

  • East-west inspection routes spoke-to-spoke traffic through centralized inspection with active-standby failover using BGP AS-path prepending
  • North-south inspection extends the pattern to internet-bound traffic, with firewall instances routing inspected packets to internet gateways
  • AZ-affinity inspection uses dual route servers to keep traffic local within Availability Zones under normal conditions, crossing AZ boundaries only during failover
  • BGP dynamic routing automatically detects firewall failures and updates Transit Gateway route tables to redirect traffic to standby instances
  • Provides alternative to Gateway Load Balancer when appliances lack GENEVE support or require active-standby failover with fine-grained BGP control

The approach enables resilient centralized inspection architectures for multi-VPC environments with automatic failover and optional AZ-affinity optimization.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 25
2026
Centralized traffic inspection for Oracle Database@AWS
Aug 11
2026
Deployment models for AWS Network Firewall: Transit Gateway attachment and multiple VPC endpoints
Jul 30
2026
AWS announces general availability of Policy-Based Routing on AWS Transit Gateway
Jul 16
2026
Dynamic Inbound Routing for BYOIP Workloads Using Amazon VPC Route Server

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.