How to Fix Inter-Region Traffic Through Inspection VPC in Transit Gateway?
A US-based company is expanding its business to Europe. A network engineer needs to extend the company's network infrastructure by setting up a new hub and spoke architecture in the eu-west-1 Region. The network engineer uses a transit gateway peering connection to connect the new resources in eu-west-1 to an existing environment in the us-east-1 Region. The hub and spoke architecture in each AWS Region includes an inspection VPC that uses AWS Network Firewall to centralize traffic inspection for each Region. To reduce costs, the network engineer decides to inspect inter-Region traffic by using the inspection VPC in the Region that originates the traffic. The network engineer configures the transit gateway route tables accordingly for each Region. When the network engineer tests the new architecture, communication within each Region works as expected. However, the network engineer finds that inter-Region communication is not working. The network engineer must resolve the inter-Region communication issue. Which solution will meet this requirement?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests your understanding of Transit Gateway Appliance Mode and asymmetric routing pitfalls when using AWS Network Firewall; the trap is that simply recognizing asymmetric routing (option C) is not enough—you must know the exact configuration setting that forces symmetric inspection.
When inter-Region traffic fails in a Transit Gateway hub-and-spoke architecture with AWS Network Firewall inspection VPCs, enabling Appliance Mode on the Transit Gateway attachments is the correct fix. The AWS community unanimously confirms this solution, which ensures symmetric traffic flow through the originating inspection VPC.
Selecting option C, 'Prevent asymmetric routing in the inspection VPCs,' because it correctly identifies the root cause but fails to provide the actionable Transit Gateway configuration needed. Option C describes the desired outcome, not the mechanism, while Appliance Mode is the specific feature that resolves it.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option D is correct because AWS Transit Gateway's default routing can send each flow across different attachments, causing asymmetric paths. Enabling Appliance Mode on both inspection VPC attachments forces the Transit Gateway to pin each bidirectional flow to a single attachment, ensuring request and response traffic traverse the same Network Firewall inspection VPC. This is exactly what is needed when inter-Region traffic must be inspected in the originating Region, as stated in the question.
Why the Other Options Are Wrong
Option A is invalid because Transit Gateway does not support OSPF dynamic routing; it uses static routes and BGP only in Direct Connect/VPN contexts. Option B is incorrect because AWS RAM is for sharing Transit Gateways across accounts, not for enabling inter-Region connectivity or fixing routing. Option C identifies the symptom but offers no specific configuration; it fails to mention Appliance Mode, which is the actual solution required.
Community Comment Notes
Community comments strongly support D. One commenter notes that OSPF is unsupported on TGW, making A wrong. Another explains that Appliance Mode must be enabled on both inspection VPC attachments in both Regions, and explicitly advises enabling it to 'resolve the asymmetric routing issue and enable inter-Region communication.' A third comment clarifies that default optimized routing can lead to asymmetric paths, which is precisely why Appliance Mode is necessary.
Official Reference
Exam Strategy
For ANS-C01, always match the described behavior with the exact AWS feature—when you see asymmetric routing in an inspection VPC scenario, immediately look for 'Appliance Mode' in the options. Remember that AWS Transit Gateway does not use OSPF, and AWS RAM only shares resources across accounts, so eliminate those distractors first.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →