Packet Flow in the AWS Gateway Load Balancer—Outbound

Showing results for 
Show  only  | Search instead for 
Did you mean: 
Please sign in to see details of an important advisory in our Customer Advisories area.
L1 Bithead
100% helpful (1/1)

packet-flow-aws-load-outbound.jpgWith the introduction of the Gateway Load Balancer (GWLB) in mid-November 2020, AWS provided its customers with any port, load-balancing router. Prior to that, Azure and GCP were the only public clouds that had such a construct. Customers use these to provide a security layer that is scalable, resilient, and adaptable.


In the AWS implementation, endpoints are an integral part of the solution but are not a new concept in AWS. They connect elastic network interfaces (ENIs) to targets (e.g. GWLB) via "worm holes" in the fabric and and have been used with network load balancers (NLBs) for some time. These worm holes in the fabric bypass the usual routing constructs and can perforce result in some difficulty when troubleshooting. Here, we will trace the flow of a request originating from a client in one VPC (network going out to the internet. The infrastructure was deployed using the following TerraForm template:


Please download and view the entire PDF for instructions: Packet Flow in the AWS Gateway Load Balancer - Outbound.

Rate this article:
L0 Member



I have configured above scenario for outbound traffic with gwlb, tgw and vm firewalls. However, all my firewalls are unhealthy under target group. I am following below link for configuration and verified twice that there is no misconfiguration. Been on hold (call) for more than 90 mins and would appreciate some suggestions here.



Register or Sign-in
Article Dashboard
Version history
Last Updated:
‎07-08-2021 05:04 PM
Updated by: