AWS Transit Gateway: Attachments and Route Tables - 夜莺博客

AWS Transit Gateway: Attachments and Route Tables

AWS Transit Gateway turns a mesh of VPC peerings into a hub-and-spoke routing domain, but the hub only works if the attachment subnets and route tables are designed deliberately. The two failures that show up repeatedly are traffic that never leaves a subnet because its route table lacks a TGW route, and traffic that reaches the wrong VPC because everything propagates into a single default route table. This guide covers the attachment design, propagation versus static routes, and the segmentation patterns that keep environments isolated.

Attachment design

  • Give the TGW attachment its own subnet in each Availability Zone — a small /28 is usually enough. Do not reuse workload subnets.
  • Keep the network ACLs on the attachment subnets open; apply restrictive ACLs to workload subnets instead. Restricting the attachment subnet is the most common cause of one-way flows.
  • Associate the same VPC route table with all subnets that must use the TGW, unless a middle-box VPC requires separate tables.
aws ec2 create-transit-gateway \
  --description "core-tgw" \
  --options AmazonSideAsn=64512,AutoAcceptSharedAttachments=disable,\
DefaultRouteTableAssociation=disable,DefaultRouteTablePropagation=disable,\
VpnEcmpSupport=enable,DnsSupport=enable

aws ec2 create-transit-gateway-vpc-attachment \
  --transit-gateway-id tgw-0abc123 \
  --vpc-id vpc-0aaa111 \
  --subnet-ids subnet-0bbb111 subnet-0bbb222

Disable default association and propagation at creation time. Enabling them later creates a default route table that silently absorbs every attachment and hides segmentation mistakes.

Routes: propagation versus static

# Propagate VPN / Direct Connect attachments (BGP learned)
aws ec2 enable-transit-gateway-route-table-propagation \
  --transit-gateway-route-table-id tgw-rtb-prod \
  --attachment-id tgw-attach-0vpn1

# Static route for a blackhole or a summary
aws ec2 create-transit-gateway-route \
  --destination-cidr-block 10.99.0.0/16 \
  --transit-gateway-route-table-id tgw-rtb-prod \
  --blackhole

# VPC route table: send remote prefixes to the TGW
aws ec2 create-route --route-table-id rtb-0prod \
  --destination-cidr-block 10.10.0.0/8 \
  --transit-gateway-id tgw-0abc123

Two independent route decisions must agree: the TGW route table decides which attachment a packet leaves through, and the VPC subnet route table decides that the packet goes to the TGW at all. A blackhole on the TGW side with a valid subnet route produces a silent drop that shows only as a timeout.

Segmentation with multiple TGW route tables

Prod RT   : associated prod, shared-services VPCs; propagates prod + shared
Dev  RT   : associated dev VPCs; propagates dev + shared
Shared RT : associated shared-services; propagates shared only
Inspection RT: associated spoke VPCs; static default 0.0.0.0/0 -> firewall VPC attachment
aws ec2 associate-transit-gateway-route-table \
  --transit-gateway-route-table-id tgw-rtb-prod \
  --transit-gateway-attachment-id tgw-attach-0prod1

aws ec2 create-transit-gateway-route \
  --destination-cidr-block 0.0.0.0/0 \
  --transit-gateway-route-table-id tgw-rtb-spokes \
  --transit-gateway-attachment-id tgw-attach-0fw

Centralised inspection works by giving each spoke route table a default route to the firewall attachment while the firewall's own route table returns traffic to the correct spoke attachment. Route symmetry matters: if the firewall VPC's table lacks a path back to a spoke, return traffic is dropped even though the inbound direction is logged as working.

Verifying and operating

aws ec2 search-transit-gateway-routes \
  --transit-gateway-route-table-id tgw-rtb-prod --filters Name=state,Values=active
aws ec2 get-transit-gateway-route-table-associations --transit-gateway-route-table-id tgw-rtb-prod
aws ec2 describe-transit-gateway-attachments --filters Name=state,Values=available
# flow logs on the attachment ENIs are the fastest way to prove drops
aws ec2 create-flow-logs --resource-type TransitGatewayAttachment \
  --resource-ids tgw-attach-0prod1 --traffic-type ALL \
  --log-destination-type cloud-watch-logs --log-group-name /aws/tgw/prod

Also watch the TGW and attachment quota per AZ: a spoke that suddenly loses cross-AZ traffic often has an AZ-level attachment limit reached, not a routing error.

Related reading: BGP ECMP configuration across Cisco, Juniper and Arista, Terraform network automation for Cisco, Junos and Arista, and Azure ExpressRoute circuits and BGP peering.

原文链接:https://docs.aws.amazon.com/vpc/latest/tgw/tgw-best-design-practices.html