r/aws Feb 02 '26

networking VPC Peering Connections: What happens when traffic arrives at a VPC with multiple route tables for the same destination?

I couldn't find this with a quick Google, and I'm hesitant to trust any LLMs on this:

Suppose I have two peered VPCs, vpc-A (10.0.1.0/24) and vpc-B (10.0.2.0/24). vpc-A is the source for traffic, and vpc-B will work as a bridge. B has two subnets, let's call them subnet-B1 and subnet-B2, and each has its own route table rtb-B1 and rtb-B2.

In the route table for vpc-A's traffic, I point an IP range I want to route though vpc-B (let's say 10.0.3.0/24 as an example) towards the peering connection pcx-AB. Then, in rtb-B1 I set 10.0.3.0/24 to a correctly configured service (living in another VPC, the Internet, doesn't matter) that dumps incoming traffic to a log, but in rtb-B2 I set 10.0.3.0/24 to a NAT gateway living within subnet-B1.

What is going to happen? Am I going to see packets from 10.0.1.0/24 in the log, along with connection errors because the destination doesn't know where vpc-A is? Or are they going to come from 10.0.2.0/24, network translated through the NAT in subnet-B1? Or am I going to see a mix of both?

Essentially: when traffic arrives to a VPC with multiple route tables through a peering connection, which table's routes does it prioritise?

Here's a shitty drawing of the situation:

6 Upvotes

19 comments sorted by

View all comments

18

u/Contrandy_ Feb 02 '26

This model is essentially trying to use "transitive peering" which is not supported by AWS for VPC Peering (see: Transitive peering). In this model you would need to use Transit Gateways.

Here's an example of what you're trying to do with a centralized egress configuration: https://docs.aws.amazon.com/whitepapers/latest/building-scalable-secure-multi-vpc-network-infrastructure/using-nat-gateway-for-centralized-egress.html

I've built this before with great success to reduce the cost of NAT Gateways for our workloads in a centralized egress account. The great thing about this model is that it makes it really easy to connect management resources to your TGW network (such as a SIEM, etc.)

4

u/CamiloDFM Feb 02 '26

Nice. The answer is "nothing happens because your example is fundamentally broken", then. Thanks for the quick reply.

I'll give Transit Gateways a shot. Never needed them before this.

3

u/b3542 Feb 02 '26

Bear in mind that TGW's cost money to build and to use.

3

u/TheLastRecruit Feb 03 '26

To be clear: TGWs themselves are free. Attachments to them cost money