AWS Hub-and-Spoke with On-Premises Metro Train Connectivity

aws · architecture diagram.

About This Architecture

AWS Transit Gateway hub-and-spoke architecture connects a production spoke VPC (DRIV2-Prod) to on-premises metro train networks through a centralized inspection VPC in the Nexus-Prod hub account. Traffic flows from EC2/ECS app servers through NAT Gateways, Transit Gateway with three route tables (Spoke-RT, Inspection-RT, VPN-RT), AWS Network Firewall endpoints in appliance mode across three availability zones, and Site-to-Site VPN with dual-tunnel HA to reach metro train endpoints and onboard WiFi systems. This design demonstrates defense-in-depth for OT environments: security groups restrict outbound to forward proxy IPs, NACLs limit egress to on-prem CIDRs, Network Firewall enforces stateful IPS and domain filtering on HTTPS/443, and on-premises firewalls provide Layer 5 inspection before traffic reaches the metro train OT segment. Fork this diagram on Diagrams.so to customize route tables, add spoke VPCs, modify firewall rules, or export as .drawio for network documentation. Ideal reference for hybrid cloud architects balancing centralized security inspection with high-availability requirements for critical infrastructure connectivity.

People also ask

How do I design an AWS Transit Gateway hub-and-spoke architecture with centralized security inspection for on-premises OT networks?

Use AWS Transit Gateway with three route tables (Spoke-RT, Inspection-RT, VPN-RT) to route spoke VPC traffic through a centralized inspection VPC running Network Firewall in appliance mode across three AZs, then to on-premises via Site-to-Site VPN with dual-tunnel HA. This diagram shows defense-in-depth with security groups, NACLs, Network Firewall stateful rules, and on-prem Layer 5 firewalls pro

AWS Hub-and-Spoke with On-Premises Metro Train Connectivity

AWSadvancedTransit GatewayNetwork FirewallSite-to-Site VPNHybrid CloudOT Security
Domain: NetworkingAudience: AWS network architects designing hybrid cloud connectivity with operational technology (OT) segmentation
7 views0 favoritesPublic

Created by

February 23, 2026

Updated

April 4, 2026 at 5:53 AM

Type

architecture

Need a custom architecture diagram?

Describe your architecture in plain English and get a production-ready Draw.io diagram in seconds. Works for AWS, Azure, GCP, Kubernetes, and more.

Generate with AI