⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 998+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
Staff SRE / Principal Architect [L3] Networking Staff SRE Scenario [L3]

Q: Your company has two VPCs in different AWS regions. You set up VPC Peering between them. From VPC A (10.0.0.0/16), you can reach a server in VPC B (10.1.0.0/16). However, the server in VPC A cannot access the internet *through* VPC B's NAT Gateway. Why?

AWS VPC Peering does not support Transitive Edge Routing.

#Networking #Networking #L3 #VPC #DNS #Security
🎙️ Candidate Opening & Architectural Context
""Isolating network failures requires proving whether packets are dropped by route tables, security groups, or stateless NACLs. The interviewer is testing: VPC Peering limitations, transitive routing.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Initial Diagnostics & Root Cause Analysis

AWS VPC Peering does not support Transitive Edge Routing.

  • Provide VPC A with its own NAT Gateway and Internet Route.
  • Use AWS Transit Gateway, which supports advanced routing topologies including routing edge internet traffic through a centralized egress VPC.
  • Setup proxy software (e.g. Squid) on an instance in VPC B, and have VPC A explicitly use that proxy.
2️⃣

Remediation & Permanent Safeguards

This means traffic from VPC A cannot traverse VPC B to hit an edge device configured in VPC B (like an Internet Gateway, NAT Gateway, Direct Connect, or VPN). VPC Peering only allows communication strictly terminating at the instances within the peered VPCs. To solve this, you would need to either:

💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Provide VPC A with its own NAT Gateway and Internet Route.."
⚡ 60-Second Elevator Pitch Talking Points
  • Provide VPC A with its own NAT Gateway and Internet Route.
  • Use AWS Transit Gateway, which supports advanced routing topologies including routing edge intern...
  • Setup proxy software (e.g. Squid) on an instance in VPC B, and have VPC A explicitly use that proxy.
Advertisement
Want more Networking scenarios?
Explore our complete collection of scenario-based Networking interview runbooks.
Browse All Networking Questions →

📚 Related Production Scenarios in Networking