Skip to main content
Cloud & AI Hub
Browse
Glossary AI Directory Playgrounds Models Prompts Explainers Strategy Matrix Benchmark Decoder

Transit Gateway

A cloud hub-and-spoke router connecting multiple virtual networks, on-premises environments, and accounts.

Last reviewed: July 25, 2026

A Transit Gateway is a cloud networking hub that connects multiple VPCs, on-premises networks, and other cloud accounts through a single, centrally managed point, replacing the complex mesh of individual point-to-point connections that would otherwise be needed to interconnect the same set of networks.

The Problem It Solves

Connecting VPCs directly to each other via VPC peering works fine for a small number of VPCs, but peering connections are point-to-point and non-transitive — connecting N VPCs directly to each other requires roughly N-squared individual peering connections, and each one has to be individually managed, with its own route table entries on both sides. This becomes impractical well before an organization reaches even a few dozen VPCs, especially when on-premises data centers and multiple AWS accounts also need to be part of the picture.

How It Works

A Transit Gateway acts as a central routing hub: each VPC, VPN connection, or Direct Connect link attaches to the Transit Gateway once, and the gateway itself handles routing traffic between any pair of attachments based on route tables configured centrally on the gateway. This turns what would be an N-squared web of individual connections into a simple hub-and-spoke model, where adding a new VPC to the network just means creating one new attachment to the existing gateway, rather than a new peering connection to every other VPC that needs to reach it.

Additional Capabilities

Beyond simplifying connectivity, Transit Gateway supports route tables that can segment which attachments can reach which other attachments — useful for isolating, say, a shared services VPC that all other VPCs need to reach, from application VPCs that shouldn’t be able to reach each other directly. It also integrates with on-premises networks via VPN or Direct Connect, making it the standard architecture for organizations with a genuinely hybrid, multi-VPC, and multi-account network topology.

Transit Gateway Route Tables for Network Segmentation

Beyond simplifying connectivity, Transit Gateway supports multiple independent route tables that can segment which attachments are allowed to communicate with which others — a shared services VPC might be reachable from every other attached VPC, while two application VPCs are deliberately prevented from reaching each other directly, all managed centrally through the gateway’s routing configuration rather than through per-VPC security group or NACL rules. This centralized segmentation capability is often what ultimately justifies Transit Gateway’s added cost and complexity over simple VPC peering for organizations with genuinely complex, multi-team network topologies.

Advertisement (In-Content)

Historical figures and technical concepts for informational purposes only. Not technical, professional, legal, or financial advice. Sources: Official Documentation.