Experiencing an issue with routing with Inspection VPC


When I ping the Instance I get the below error Time to live exceeded

asked a month ago51 views
1 Answer

More information on the architecture can help troubleshooting the issue.

To help troubleshoot this issue, try using Reachability Analyzer. Set the source eni from the source of the ICMP. To understand the return, repeat the same but using the Destination IP for your ICMP traffic as your source to check the return traffic. If you are using Gateway load balancer, the path if routing works right, will show you that GWLB endpoints but will bypass the firewall appliances.

Make sure you TGW is not crossing AZs when forwarding traffic to your FWs appliances by enabling Appliance mode for flow symmetry: https://aws.amazon.com/blogs/networking-and-content-delivery/centralized-inspection-architecture-with-aws-gateway-load-balancer-and-aws-transit-gateway/

Are you using a 3rd party vendor or AWS Network Firewall? Is this a new set up? If so, we have common configurations for some of 3rd party vendors in this workshop: https://catalog.workshops.aws/gwlb-networking/en-US

profile pictureAWS
answered a month ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions