Home icon

Centralized VPC inspection with Amazon VPC Route Server and AWS Transit Gateway

Networking & Content Delivery Blog



This article demonstrates centralized VPC inspection using Amazon VPC Route Server and AWS Transit Gateway to route multi-VPC traffic through shared firewall appliances with automatic failover.

  • East-west inspection routes spoke-to-spoke traffic through centralized inspection with active-standby failover using BGP AS-path prepending
  • North-south inspection extends the pattern to internet-bound traffic, with firewall instances routing inspected packets to internet gateways
  • AZ-affinity inspection uses dual route servers to keep traffic local within Availability Zones under normal conditions, crossing AZ boundaries only during failover
  • BGP dynamic routing automatically detects firewall failures and updates Transit Gateway route tables to redirect traffic to standby instances
  • Provides alternative to Gateway Load Balancer when appliances lack GENEVE support or require active-standby failover with fine-grained BGP control

The approach enables resilient centralized inspection architectures for multi-VPC environments with automatic failover and optional AZ-affinity optimization.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 25
2026
Centralized traffic inspection for Oracle Database@AWS
Apr 26
2023
Best practices and considerations to migrate from VPC Peering to AWS Transit Gateway
Apr 1
2025
Monitor AWS Transit Gateway Flow Logs centrally using Amazon Managed Grafana
Apr 1
2025
Announcing the general availability of Amazon VPC Route Server

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.