AWS Centralized Egress / East-West¶
In a centralized Egress / East-West deployment, a Service VPC will be used as a centralized security hub to connect all spoke VPCs and route traffic using an AWS Transit Gateway (TGW). Valtix will orchestrate the deployment of the Service VPC and attach the Service VPC to an existing or new TGW (orchestrated by Valtix). The Service VPC will use an AWS Gateway Load Balancer (GWLB). The GWLB will load balance the traffic across one or more Valtix Gateway instances deployed to accommodate protection. The Valtix Gateway will operate in Forwarding or Forward Proxy to inspect and protect southbound and east-west traffic.
Deployment Architecture¶
Traffic Flow (Egress)¶
Traffic Flow (East-West)¶
Routing Configuration¶
Note
The diagram shows both Ingress and Egress / East-West Gateways. The Ingress and Egress / East-West Gateways can be deployed into the same VPC. If protection is for Egress /East-West only, the Ingress Gateway is not needed.