Separate association, propagation, and subnet routing
First draw the attachment through which the packet enters Transit Gateway. The table associated with that attachment determines destination lookup. Propagation has a different role: it installs an attachment’s routes in one or more tables. An attachment associates with one table while it can propagate into several. Do not confuse a route visible in the shared-services table with the table actually used by production traffic. Also confirm the application subnet route to Transit Gateway and the return path. In the fictional exercise, a positions flow enters through PROD, associated with the isolated table. Its destination exists only in the services table; captures and tables should explain failure before permissions are opened. Two Available attachments do not establish that the complete path has been configured.
Read preference without losing the inspection requirement
Lookup selects the most specific route for the destination. For the same prefix, a static route takes precedence over a propagated route. In the original model, 172.22.0.0/16 leads to inspection, but 172.22.44.0/24 leads directly to the destination. A packet for 172.22.44.19 uses the latter and can bypass intended inspection. A successful functional test does not validate the security control. Compare the selected route, inspection-point records, and agreed negative tests. A blackhole route drops traffic matching the selected route; it does not guarantee blocking every more-specific exception. Record prefix, route origin, next hop, and table for every decision. Avoid treating attachment-type preference as overriding the initial most-specific match.
Ensure zone coverage and flow consistency
Resources in a zone need a VPC attachment with a subnet in that zone to reach Transit Gateway. Adding a third application zone without reviewing the attachment can cause failures only on new instances. The subnet route alone does not create that coverage. For stateful inspection in an appliance VPC, appliance mode retains the chosen zone for that attachment during the flow; the design still needs coherent routing both ways and state on the correct appliance. Do not assume enabling an option fills missing routes or fixes every asymmetry. Rehearsal should record source, destination, ports, zone, and forward and return paths. Include cross-zone traffic and the planned failure condition. One healthy connection in one zone does not establish coverage of the full deployment.
Choose the attachment and demonstrate boundaries
Direct peering between Transit Gateways requires acceptance and static routes to send traffic through the peer; do not assume automatic dynamic propagation. Overlapping VPC CIDRs are not solved by adding an attachment either. Identify the collision and review addressing or a compatible integration without claiming nonexistent general connectivity. Current documentation allows integrating AWS Network Firewall through a managed network function attachment, reducing manual inspection-VPC management. This option has its own requirements; do not present it as generic support for any third-party firewall. In either design, confirm effective routes that send traffic to inspection. For the PM, the output should be an allowed-and-denied flow matrix, table owners, per-zone evidence, and a reversible change plan. A centralized design still needs validation for each consumer.
from ipaddress import ip_address, ip_network
routes = [('172.22.0.0/16', 'inspection'), ('172.22.44.0/24', 'direct')]
destination = ip_address('172.22.44.19')
matches = [(ip_network(prefix).prefixlen, target) for prefix, target in routes if destination in ip_network(prefix)]
selected_target = max(matches)[1] # direct
# Teaching model: longest-prefix selection only, not all AWS route priorities.At a fictional bank, the positions application reaches a central service, but no records appear at the inspection point. The team identifies a /24 route taking precedence over the inspection /16 and reviews the exception with security and networking before retesting.
Common pitfalls
Inspecting the wrong table; confusing propagation with association; omitting return paths or zones; treating connectivity as proof of inspection.
Related topics: Hybrid DNS and authority across accounts
Validate the packet’s selected path in both directions against connectivity and segmentation requirements.
Reference: How Transit Gateway works · SAP-C02