List of questions
Related questions
Question 111 - ANS-C01 discussion
A company has stateful security appliances that are deployed to multiple Availability Zones in a centralized shared services VPC. The AWS environment includes a transit gateway that is attached to application VPCs and the shared services VPC. The application VPCs have workloads that are deployed in private subnets across multiple Availability Zones. The stateful appliances in the shared services VPC inspect all east-west (VPC-to-VPC) traffic.
Users report that inter-VPC traffic to different Availability Zones is dropping. A network engineer verified this claim by issuing Internet Control Message Protocol (ICMP) pings between workloads in different Availability Zones across the application VPCs. The network engineer has ruled out security groups, stateful device configurations, and network ACLs as the cause of the dropped traffic.
What is causing the traffic to drop?
The stateful appliances and the transit gateway attachments are deployed in a separate subnet in the shared services VPC.
Appliance mode is not enabled on the transit gateway attachment to the shared services VPC
The stateful appliances and the transit gateway attachments are deployed in the same subnet in the shared services VPC.
Appliance mode is not enabled on the transit gateway attachment to the application VPCs.
0 comments
Leave a comment first