Glossary

    Transit Gateway

    Network Security

    AWS Transit Gateway acts as a cloud router, connecting thousands of VPCs and on-premises networks through a single gateway. It simplifies network topology by replacing complex VPC peering meshes.

    Security Features

    • Route Tables: segment traffic between VPCs (e.g., isolate production from development)
    • Route Table Associations: control which VPCs can communicate with each other
    • Blackhole Routes: drop traffic to specific CIDRs
    • Multicast Support: for specialized network patterns
    • Flow Logs: Transit Gateway flow logs for network visibility

    Network Segmentation Pattern

    • Shared Services VPC: DNS, logging, security tools accessible by all
    • Inspection VPC: route all traffic through Network Firewall or IDS/IPS appliances
    • Isolated VPCs: prevent direct communication between workload VPCs

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.