What's changed: Deepened ANS-C01 Chapter 6 (SG/NACL eval order/SG references/ephemeral, inspection VPC routing/appliance mode/firewall remits, Shield Adv/WAF Web ACL/Firewall Mgr prereqs/ACM Region + tables, scenarios, FAQ, traps; ja figures)
6.2Centralized Inspection and Firewalls
Inspect at one point—understand AWS Network Firewall, an inspection VPC, routing via Transit Gateway, appliance insertion with GWLB, and the Route 53 Resolver DNS Firewall.
To inspect traffic from many VPCs in one place, put AWS Network Firewall in an inspection VPC and route all traffic through it via the Transit Gateway.
6.2.1Centralized inspection architecture
- AWS Network Firewall: a managed stateful firewall + IPS. Apply domain allow-lists and IPS rules.
- Inspection VPC + TGW: aggregate all VPCs’ traffic through the TGW into an inspection VPC.
- GWLB: use to transparently insert third-party appliances (NGFW/IDS).
- Route 53 Resolver DNS Firewall: block resolution to malicious domains at the DNS query level.
Common on ANS-C01: VPC-level managed stateful FW/IPS with domain allow-lists = AWS Network Firewall, centralized inspection of all VPCs = inspection VPC + TGW, insert third-party FW = GWLB, and block resolution of malicious domains = Route 53 Resolver DNS Firewall. The key contrast: managed = Network Firewall, third-party = GWLB.
Continue reading — free sign-up
You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.

