Question 1
Q1A cloud architect is designing a centralized security architecture in AWS using a Transit Gateway (TGW). The requirement is to inspect all East-West traffic between Spoke VPCs and all North-South traffic to the internet. The design includes a dedicated Security VPC with an Auto Scaling Group of FortiGate-VMs behind a Geneve-compliant Gateway Load Balancer (GWLB).
Which routing configuration ensures the return traffic from the FortiGate fleet is correctly sent back to the original Spoke VPC destination?
Show answer & explanation
Correct answer: B
When using a Transit Gateway with a centralized inspection VPC (Security VPC), asymmetric routing often occurs because the TGW might send return traffic to a different availability zone than the source. Enabling 'Appliance Mode' on the TGW attachment for the Security VPC ensures that return traffic is routed to the same availability zone where the inspection took place, maintaining flow symmetry required for stateful firewalls like FortiGate.