- Home
- Skills
- Technical Documentation
- Network Architecture Diagram and Cloud VPC Hub Model
Network Architecture Diagram and Cloud VPC Hub Model
Models cloud network architectures: Transit Gateway hubs, segregated route domains, and central inspection DMZ firewalls.
$5
Works with the AI tools you already use
Network Architecture Diagram and Cloud VPC Hub Model
Example session with this skill installed
Model formal cloud Network Architecture Diagram, Transit Gateway hubs, and DMZ firewalls for Enterprise Core Banking.
- Subject: enterprise-core-banking-network v3.0 (run-id: quote-netdiag-001) governing 140 VPCs across 3 regions and $95B daily clearing.
- Deciders: Chief Network Architect (David O'Reilly) and Chief Information Security Officer (Elena Rostova).
- Scope: AWS Transit Gateway hub-and-spoke; dedicated route domains (Prod, Non-Prod, Shared Services); Security DMZ with Palo Alto firewalls; 100 Gbps DirectConnect.
- Tension: Flat ad-hoc VPC peering allowed a compromised staging container to route traffic directly into production database subnets in incident NET-4919 ($4.2M penalty). Elena Rostova and David O'Reilly mandate an authoritative Network Architecture Diagram: segregated TGW route tables, deep packet inspection DMZs, and private database subnet isolation.
Write the network architecture diagram under docs/.
- Read your context and instructions
- Compiled the network architecture diagram
- Generated the document
Wrote docs/architecture/tasks/quote-netdiag-001/network-diagram/network-architecture-diagram.md. Complete network architecture diagram specification establishing transit gateways, VPC peering meshes, DMZ perimeter firewalls, and multi-region hybrid DirectConnect links.
skill: network-diagram
Network Architecture Diagram Specification: Enterprise Core Banking [NET-BANK-001]
Summary
This specification establishes the formal Network Architecture Diagram specification, virtual private cloud (VPC) topology, Transit Gateway routing meshes, perimeter DMZ firewalls, and hybrid on-premise DirectConnect links for enterprise-core-banking-network v3.0 under run ID quote-netdiag-001. It governs enterprise network engineering across 3 AWS regions, 140 VPCs, 24 million retail accounts, and $95B in daily clearing volume sustaining 65,000 requests/second. It decisively investigates and resolves the network routing outages and lateral movement vulnerabilities demonstrated in incident NET-4919 (where deploying uncoordinated ad-hoc VPC peering meshes allowed a compromised non-production test container in a staging VPC to route traffic directly across flat un-firewalled routes into the production Core Banking database subnet, triggering an emergency 8-hour network isolation quarantine, dropping $4.2M in merchant transactions, and drawing severe regulatory audit sanctions). The specification models the exact hub-and-spoke network topology using AWS Transit Gateway, enforces strict perimeter DMZ inspection via Palo Alto next-generation virtual firewalls, isolates traffic across Prod, Non-Prod, and Shared Services VPC route domains, and provides
executable Mermaid and PlantUML network diagrams.
Detailed Description
Operating large-scale cloud networks with unmanaged, point-to-point VPC peering connections inevitably degrades into an unmaintainable "spaghetti mesh." When hundreds of VPCs peer directly with one another without centralized inspection or security boundaries, network engineers cannot trace packet flows, route tables hit hard cloud provider limits, and an intrusion into an untrusted developer sandbox can traverse flat routes directly into mission-critical financial ledgers. Network Architecture Modeling establishes
Governed Hub-and-Spoke Infrastructure: it routes all inter-VPC and hybrid traffic through centralized
AWS Transit Gateways (TGW), enforces deep packet inspection in dedicated Security Inspection VPCs (DMZ), isolates network traffic into segregated route tables (Prod, Non-Prod, Core Ledger), and establishes redundant 100 Gbps dedicated DirectConnect links to on-premise clearinghouse datacenters.
On-Premise Wholesale Clearinghouse Datacenter
│
▼ (Redundant 100 Gbps AWS DirectConnect + MACsec)
┌─────────────────────────────────────────────────────────────────────────────┐
│ Central Hub: AWS Transit Gateway (TGW) [NET-BANK-001] │
│ ├── Attachment 1: Security DMZ Inspection VPC (Palo Alto Virtual FW) │
│ ├── Attachment 2: Production Core Banking VPC (10.100.0.0/16) │
│ ├── Attachment 3: Shared Services & Observability VPC (10.150.0.0/16) │
│ └── Attachment 4: Non-Production Staging VPC (10.200.0.0/16 - ISOLATED) │
└──────────────────────────────────────┬──────────────────────────────────────┘
│
┌─────────────────────────────┼─────────────────────────────┐
▼ (Route Domain: Production) ▼ (Route Domain: DMZ Firewall)▼ (Route Domain: Isolated)
[ Prod Core Banking VPC ] [ Central Inspection VPC ] [ Staging / Sandbox VPC ]
├── Private Subnets Only ├── East-West Deep Inspection ├── Route to Prod BLOCKED
└── Zero Public Internet Routes └── Egress NAT & Gateway WAF └── Incident NET-4919 DEFEATED
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Environment Route Isolation (Prod vs Non-Prod) | Flat peering allowed staging breaches in NET-4919 ($4.2M penalty). | 0.40 | Elena Rostova (Chief Information Security Officer) |
| Centralized Deep Packet Inspection (DMZ) | All inter-VPC and outbound traffic must be inspected by next-gen firewalls. | 0.30 | David O'Reilly (Chief Network Architect) |
| Hybrid DirectConnect Redundancy (100 Gbps) | Physical link failure must fail over instantaneously without transaction drops. | 0.15 | Core Payment Network Operations SLA |
| Subnet CIDR Allocation Discipline & Zero-Overlap | Clean hierarchical IP planning prevents routing collisions across 140 VPCs. | 0.15 | Enterprise Infrastructure Governance Charter |
Comparison
| Network Architecture Model | Lateral Movement Defense | Centralized Traffic Inspection | Route Table Scalability | Evaluation |
|---|---|---|---|---|
| Option A: Ad-Hoc Full-Mesh Peering (Legacy) | Zero (Failed in NET-4919) | None (Traffic bypasses firewalls) | Terrible (Hits 125 peering cap) | Rejected: Caused NET-4919 disaster; unviable. |
| Option B: Distributed Single-VPC Firewall Proxies | Moderate | Inconsistent (Per-VPC rules drift) | High | Rejected: High management cost across 140 separate VPCs. |
| Option C: Central Transit Gateway Hub (Chosen) | Absolute (Segregated TGW Route Tables) | 100% Inspected in Central DMZ | Optimal (Scales to 5,000 VPCs) | Selected: Zero lateral breach risk, automated, proven. |
Result
Option C is selected. A centralized AWS Transit Gateway hub with dedicated Route Domains is standardized; all inter-VPC traffic is inspected by Palo Alto VM-Series firewalls in the Security DMZ; non-production VPCs cannot route to production.
Required Mechanisms
1. Network Architecture Diagram Specification [MC-ND-01]
graph TD
subgraph OnPrem_DC ["On-Premise Enterprise Datacenter"]
Core_Switch["Hardware Core Switch (Arista 7050)"]
HSM_Appliance["Hardware HSM Appliance (Thales Luna)"]
end
subgraph AWS_Cloud ["AWS Cloud Region: eu-central-1"]
DX_Gateway["AWS DirectConnect Gateway (100 Gbps + MACsec)"]
TGW["Central AWS Transit Gateway (TGW)"]
subgraph Security_DMZ_VPC ["VPC: Security Inspection DMZ (10.50.0.0/16)"]
PaloAlto_FW["Palo Alto VM-Series Virtual Firewalls"]
GWLB["AWS Gateway Load Balancer (GWLB)"]
NAT_GW["AWS Managed NAT Gateway"]
IGW["Internet Gateway (IGW)"]
end
subgraph Prod_Core_VPC ["VPC: Production Core Banking (10.100.0.0/16)"]
EKS_Prod["EKS Core Banking Worker Pods (10.100.10.0/24)"]
Aurora_Prod["Aurora PostgreSQL Primary (10.100.20.0/24)"]
end
subgraph Shared_Services_VPC ["VPC: Shared Services & Telemetry (10.150.0.0/16)"]
Kafka_Cluster["Apache Kafka 3.6 Cluster (10.150.10.0/24)"]
OTel_Collectors["OpenTelemetry Collectors (10.150.20.0/24)"]
end
subgraph Staging_VPC ["VPC: Non-Production Staging (10.200.0.0/16)"]
Staging_Pods["Staging Test Workloads (10.200.10.0/24)"]
end
end
Core_Switch ===|Redundant DirectConnect 100G| DX_Gateway
DX_Gateway === TGW
TGW <-->|Route Domain: Security| GWLB
GWLB <--> PaloAlto_FW
PaloAlto_FW --> NAT_GW
NAT_GW --> IGW
TGW <-->|Route Domain: Production| EKS_Prod
EKS_Prod <--> Aurora_Prod
TGW <-->|Route Domain: Shared| Kafka_Cluster
Kafka_Cluster <--> OTel_Collectors
TGW <-->|Route Domain: Isolated Non-Prod| Staging_Pods
EKS_Prod -.->|Inspected via TGW| Kafka_Cluster
Staging_Pods -.x|HARD ROUTE DROP (NET-4919 Defeat)| EKS_Prod
2. The NET-4919 Lateral Movement Defense [MC-LM-01]
- Root Cause Elimination:
- In incident NET-4919, direct VPC peering links existed between staging and production VPCs for debugging convenience.
- Transit Gateway Route Domain Invariant:
- Transit Gateway maintains separate route tables:
TGW_Route_Table_Prod: Can route toSecurity_DMZandShared_Services.TGW_Route_Table_NonProd: Can route toSecurity_DMZand local staging subnets.
- Transit Gateway maintains separate route tables:
Zero Route Propagation: TGW_Route_Table_NonProd contains
zero routes to Prod_Core_VPC. Any packet from staging destined for a production IP is dropped at the Transit Gateway interface with zero network traversal.
3. Security DMZ East-West Deep Packet Inspection [MC-DPI-01]
- All cross-VPC traffic routes through the Gateway Load Balancer (GWLB):
- Diverts packets to Palo Alto VM-Series firewalls without modifying IP headers (GENEVE encapsulation).
- Enforces layer-7 application inspection, TLS decryption, and automated intrusion prevention (IPS) rules before forwarding packets to destination VPCs.
Invariants and Contracts
Strict Environment Network Isolation [INV-NET-01]
Non-production VPCs must not have network routes to production VPCs.
Configuring direct VPC peering, transit routing, or shared subnets between Prod and Non-Prod is strictly prohibited.
Mandatory East-West Security Inspection [INV-NET-02]
Inter-VPC network traffic crossing distinct organizational security zones must traverse the central inspection DMZ.
Bypassing firewall inspection via direct point-to-point VPC peering is prohibited by security policy.
Private Subnet Isolation for Data Stores [INV-NET-03]
Production database clusters and in-memory caches must reside in isolated private database subnets with zero internet routes.
Assigning public IP addresses or attaching Internet Gateways to database subnets is strictly barred.
Explicit Unknowns
- Bandwidth saturation overhead on AWS Gateway Load Balancers when Kafka streams 160,000 events/second through the central inspection VPC (G-1).
- Time required for BGP dynamic routing protocols to converge over AWS DirectConnect during primary fiber cut failovers (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 3 AWS regions across 140 VPCs | provided | Enterprise network infrastructure brief | Current |
| 24 million accounts across $95B volume | provided | Financial scope intake | Current |
| Incident NET-4919 $4.2M loss and lateral breach | provided | Security incident forensic post-mortem | Historical |
| Transit Gateway hub-and-spoke and 100G DirectConnect | provided | Corporate Network Architecture Policy | Current |
| Central Transit Gateway Hub (Option C) selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Mandatory environment isolation invariant INV-NET-01 | decided | Architectural invariant INV-NET-01 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against network architecture standards:
- Environment Isolation: PASS. Segregated TGW route tables prevent staging-to-prod routing (NET-4919 closed).
- Inspection Rigor: PASS. Centralized Security DMZ with GWLB and Palo Alto firewalls inspects all traffic.
- Topology Precision: PASS. Explicit CIDRs (10.50, 10.100, 10.150, 10.200) and protocols modeled.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-NET-01: David O'Reilly to determine whether AWS Cloud WAN should be evaluated to replace Transit Gateway for managing cross-region inter-continental routing across Frankfurt, Virginia, and Singapore in Q2 (Owner: David O'Reilly).
Next steps
- Network Engineering squad deploys the central AWS Transit Gateway and segregated route tables.
- Security team configures the Gateway Load Balancer and Palo Alto VM-Series firewalls in the DMZ.
- Conduct staging penetration test attempting to ping production database IPs from staging pods to verify route drop.
network-architecture-diagram-and-cloud-v.pdf
PDF · document
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill projects an authoritative logical, physical, declared or observed network topology into a bounded view. It preserves endpoint/device/interface/link/segment/route identities, topology state, provenance, omissions and notation loss.
Use it when
Use when consumers need a reproducible network view of already accepted elements and relations at exact model/configuration/observation revisions.
For example: “Ransomware moved from a ward PC to the imaging system. Both were described as being on 'the hospital network'. Nobody has a diagram showing what could reach what.”
What you get
- Network Architecture Diagram
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/network-diagram/.
What it will not do
Do not use for network/cloud/security architecture, deployment diagrams, scanning, packet/flow analysis, troubleshooting, firewall/DNS/LB/VPN design, IaC/device configuration or implementation.
How it works
- Check the subject is the network layer.
- State whether the view is intended, declared or observed.
- Draw segments with their address ranges and their purpose.
- Put every mediator on the diagram.
- Show direction and what is permitted, not just connectivity.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install