PaloAltoNetworks / aws-transit-vpc

automated AWS transit vpc
41 stars 34 forks source link

Purpose for NAT Instance / Subnets in Subscriber VPC #22

Closed freimer closed 6 years ago

freimer commented 6 years ago

What is the purpose of the NAT Instances in the subscriber VPC? As far as I can tell, there is no purpose. I can see if you wanted to use it as a bastion host to get to hosts inn the subscriber VPC if things were not working, but this is a security risk also. Can we have an option as to whether to spin up a NAT instance, subnets, and IGW?

freimer commented 6 years ago

I figured this out. the NAT instance is necessary for the PAs to grab their boot code and the Lambda functions to make API calls.