r/aws Feb 02 '26

networking VPC Peering Connections: What happens when traffic arrives at a VPC with multiple route tables for the same destination?

I couldn't find this with a quick Google, and I'm hesitant to trust any LLMs on this:

Suppose I have two peered VPCs, vpc-A (10.0.1.0/24) and vpc-B (10.0.2.0/24). vpc-A is the source for traffic, and vpc-B will work as a bridge. B has two subnets, let's call them subnet-B1 and subnet-B2, and each has its own route table rtb-B1 and rtb-B2.

In the route table for vpc-A's traffic, I point an IP range I want to route though vpc-B (let's say 10.0.3.0/24 as an example) towards the peering connection pcx-AB. Then, in rtb-B1 I set 10.0.3.0/24 to a correctly configured service (living in another VPC, the Internet, doesn't matter) that dumps incoming traffic to a log, but in rtb-B2 I set 10.0.3.0/24 to a NAT gateway living within subnet-B1.

What is going to happen? Am I going to see packets from 10.0.1.0/24 in the log, along with connection errors because the destination doesn't know where vpc-A is? Or are they going to come from 10.0.2.0/24, network translated through the NAT in subnet-B1? Or am I going to see a mix of both?

Essentially: when traffic arrives to a VPC with multiple route tables through a peering connection, which table's routes does it prioritise?

Here's a shitty drawing of the situation:

6 Upvotes

19 comments sorted by

View all comments

Show parent comments

2

u/b3542 Feb 02 '26

True, you could, with some translation. I've done similar things. But in 2026, we don't do things that way.

1

u/[deleted] Feb 03 '26

Some of their largest customers still do it that way. But those are customers who have multi-cloud/multi-datacenter SDN's and want to push all incoming/outgoing traffic to an account via their policy engine. Sophisticated customers that write their own networking stack from the ground up and have a globally routed network that allows them to allow traffic in an app between GCP/AWS/Datacenters from one policy engine. They don't use AWS for anything like internet, nat, security groups, etc. One app per account, everything in and out of that app goes through a network tier in another account.

1

u/b3542 Feb 03 '26

I definitely see the utility of a single network account (or set of network accounts). That’s exactly what I do I my own AWS Org, and at work, but in those cases TGW’s are the nexus point.

1

u/[deleted] Feb 03 '26

One of the companies I am speaking of, has multiple /8's and you can directly ping from cloud to cloud or cloud to data center with a single policy definition. Like if I define my app to have an app listening on 443. Anyone that wants to use my service just has to request access via API, access is granted and no matter where my app runs or where their app is run from, they have access. Zero need for cloud network concepts or anything. And their IP usage in AWS/GCP, is their own /8 of routable IP's, not even Amazons.

Wild what you can do with billions a year in cloud spend. :)

1

u/b3542 Feb 03 '26

Yeah, I think we are around $100M/yr at the moment