Network Architecture Diagram and Cloud VPC Hub Model

    1

    Models cloud network architectures: Transit Gateway hubs, segregated route domains, and central inspection DMZ firewalls.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Network Architecture Diagram and Cloud VPC Hub Model

    Example session with this skill installed

    Model formal cloud Network Architecture Diagram, Transit Gateway hubs, and DMZ firewalls for Enterprise Core Banking.

    • Subject: enterprise-core-banking-network v3.0 (run-id: quote-netdiag-001) governing 140 VPCs across 3 regions and $95B daily clearing.
    • Deciders: Chief Network Architect (David O'Reilly) and Chief Information Security Officer (Elena Rostova).
    • Scope: AWS Transit Gateway hub-and-spoke; dedicated route domains (Prod, Non-Prod, Shared Services); Security DMZ with Palo Alto firewalls; 100 Gbps DirectConnect.
    • Tension: Flat ad-hoc VPC peering allowed a compromised staging container to route traffic directly into production database subnets in incident NET-4919 ($4.2M penalty). Elena Rostova and David O'Reilly mandate an authoritative Network Architecture Diagram: segregated TGW route tables, deep packet inspection DMZs, and private database subnet isolation.

    Write the network architecture diagram under docs/.

    • Read your context and instructions
    • Compiled the network architecture diagram
    • Generated the document

    Wrote docs/architecture/tasks/quote-netdiag-001/network-diagram/network-architecture-diagram.md. Complete network architecture diagram specification establishing transit gateways, VPC peering meshes, DMZ perimeter firewalls, and multi-region hybrid DirectConnect links.


    skill: network-diagram

    Network Architecture Diagram Specification: Enterprise Core Banking [NET-BANK-001]

    Summary

    This specification establishes the formal Network Architecture Diagram specification, virtual private cloud (VPC) topology, Transit Gateway routing meshes, perimeter DMZ firewalls, and hybrid on-premise DirectConnect links for enterprise-core-banking-network v3.0 under run ID quote-netdiag-001. It governs enterprise network engineering across 3 AWS regions, 140 VPCs, 24 million retail accounts, and $95B in daily clearing volume sustaining 65,000 requests/second. It decisively investigates and resolves the network routing outages and lateral movement vulnerabilities demonstrated in incident NET-4919 (where deploying uncoordinated ad-hoc VPC peering meshes allowed a compromised non-production test container in a staging VPC to route traffic directly across flat un-firewalled routes into the production Core Banking database subnet, triggering an emergency 8-hour network isolation quarantine, dropping $4.2M in merchant transactions, and drawing severe regulatory audit sanctions). The specification models the exact hub-and-spoke network topology using AWS Transit Gateway, enforces strict perimeter DMZ inspection via Palo Alto next-generation virtual firewalls, isolates traffic across Prod, Non-Prod, and Shared Services VPC route domains, and provides

    executable Mermaid and PlantUML network diagrams.

    Detailed Description

    Operating large-scale cloud networks with unmanaged, point-to-point VPC peering connections inevitably degrades into an unmaintainable "spaghetti mesh." When hundreds of VPCs peer directly with one another without centralized inspection or security boundaries, network engineers cannot trace packet flows, route tables hit hard cloud provider limits, and an intrusion into an untrusted developer sandbox can traverse flat routes directly into mission-critical financial ledgers. Network Architecture Modeling establishes

    Governed Hub-and-Spoke Infrastructure: it routes all inter-VPC and hybrid traffic through centralized

    AWS Transit Gateways (TGW), enforces deep packet inspection in dedicated Security Inspection VPCs (DMZ), isolates network traffic into segregated route tables (Prod, Non-Prod, Core Ledger), and establishes redundant 100 Gbps dedicated DirectConnect links to on-premise clearinghouse datacenters.

    On-Premise Wholesale Clearinghouse Datacenter
                             │
                             ▼ (Redundant 100 Gbps AWS DirectConnect + MACsec)
    ┌─────────────────────────────────────────────────────────────────────────────┐
    │ Central Hub: AWS Transit Gateway (TGW) [NET-BANK-001]                       │
    │   ├── Attachment 1: Security DMZ Inspection VPC (Palo Alto Virtual FW)      │
    │   ├── Attachment 2: Production Core Banking VPC (10.100.0.0/16)             │
    │   ├── Attachment 3: Shared Services & Observability VPC (10.150.0.0/16)     │
    │   └── Attachment 4: Non-Production Staging VPC (10.200.0.0/16 - ISOLATED)   │
    └──────────────────────────────────────┬──────────────────────────────────────┘
                                           │
             ┌─────────────────────────────┼─────────────────────────────┐
             ▼ (Route Domain: Production)  ▼ (Route Domain: DMZ Firewall)▼ (Route Domain: Isolated)
    [ Prod Core Banking VPC ]       [ Central Inspection VPC ]    [ Staging / Sandbox VPC ]
      ├── Private Subnets Only        ├── East-West Deep Inspection ├── Route to Prod BLOCKED
      └── Zero Public Internet Routes └── Egress NAT & Gateway WAF  └── Incident NET-4919 DEFEATED
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    Environment Route Isolation (Prod vs Non-Prod)Flat peering allowed staging breaches in NET-4919 ($4.2M penalty).0.40Elena Rostova (Chief Information Security Officer)
    Centralized Deep Packet Inspection (DMZ)All inter-VPC and outbound traffic must be inspected by next-gen firewalls.0.30David O'Reilly (Chief Network Architect)
    Hybrid DirectConnect Redundancy (100 Gbps)Physical link failure must fail over instantaneously without transaction drops.0.15Core Payment Network Operations SLA
    Subnet CIDR Allocation Discipline & Zero-OverlapClean hierarchical IP planning prevents routing collisions across 140 VPCs.0.15Enterprise Infrastructure Governance Charter

    Comparison

    Network Architecture ModelLateral Movement DefenseCentralized Traffic InspectionRoute Table ScalabilityEvaluation
    Option A: Ad-Hoc Full-Mesh Peering (Legacy)Zero (Failed in NET-4919)None (Traffic bypasses firewalls)Terrible (Hits 125 peering cap)Rejected: Caused NET-4919 disaster; unviable.
    Option B: Distributed Single-VPC Firewall ProxiesModerateInconsistent (Per-VPC rules drift)HighRejected: High management cost across 140 separate VPCs.
    Option C: Central Transit Gateway Hub (Chosen)Absolute (Segregated TGW Route Tables)100% Inspected in Central DMZOptimal (Scales to 5,000 VPCs)Selected: Zero lateral breach risk, automated, proven.

    Result

    Option C is selected. A centralized AWS Transit Gateway hub with dedicated Route Domains is standardized; all inter-VPC traffic is inspected by Palo Alto VM-Series firewalls in the Security DMZ; non-production VPCs cannot route to production.


    Required Mechanisms

    1. Network Architecture Diagram Specification [MC-ND-01]
    graph TD
        subgraph OnPrem_DC ["On-Premise Enterprise Datacenter"]
            Core_Switch["Hardware Core Switch (Arista 7050)"]
            HSM_Appliance["Hardware HSM Appliance (Thales Luna)"]
        end
    
        subgraph AWS_Cloud ["AWS Cloud Region: eu-central-1"]
            DX_Gateway["AWS DirectConnect Gateway (100 Gbps + MACsec)"]
            TGW["Central AWS Transit Gateway (TGW)"]
    
            subgraph Security_DMZ_VPC ["VPC: Security Inspection DMZ (10.50.0.0/16)"]
                PaloAlto_FW["Palo Alto VM-Series Virtual Firewalls"]
                GWLB["AWS Gateway Load Balancer (GWLB)"]
                NAT_GW["AWS Managed NAT Gateway"]
                IGW["Internet Gateway (IGW)"]
            end
    
            subgraph Prod_Core_VPC ["VPC: Production Core Banking (10.100.0.0/16)"]
                EKS_Prod["EKS Core Banking Worker Pods (10.100.10.0/24)"]
                Aurora_Prod["Aurora PostgreSQL Primary (10.100.20.0/24)"]
            end
    
            subgraph Shared_Services_VPC ["VPC: Shared Services & Telemetry (10.150.0.0/16)"]
                Kafka_Cluster["Apache Kafka 3.6 Cluster (10.150.10.0/24)"]
                OTel_Collectors["OpenTelemetry Collectors (10.150.20.0/24)"]
            end
    
            subgraph Staging_VPC ["VPC: Non-Production Staging (10.200.0.0/16)"]
                Staging_Pods["Staging Test Workloads (10.200.10.0/24)"]
            end
        end
    
        Core_Switch ===|Redundant DirectConnect 100G| DX_Gateway
        DX_Gateway === TGW
    
        TGW <-->|Route Domain: Security| GWLB
        GWLB <--> PaloAlto_FW
        PaloAlto_FW --> NAT_GW
        NAT_GW --> IGW
    
        TGW <-->|Route Domain: Production| EKS_Prod
        EKS_Prod <--> Aurora_Prod
    
        TGW <-->|Route Domain: Shared| Kafka_Cluster
        Kafka_Cluster <--> OTel_Collectors
    
        TGW <-->|Route Domain: Isolated Non-Prod| Staging_Pods
    
        EKS_Prod -.->|Inspected via TGW| Kafka_Cluster
        Staging_Pods -.x|HARD ROUTE DROP (NET-4919 Defeat)| EKS_Prod
    
    2. The NET-4919 Lateral Movement Defense [MC-LM-01]
    • Root Cause Elimination:
      • In incident NET-4919, direct VPC peering links existed between staging and production VPCs for debugging convenience.
      • Transit Gateway Route Domain Invariant:
        • Transit Gateway maintains separate route tables:
          • TGW_Route_Table_Prod: Can route to Security_DMZ and Shared_Services.
          • TGW_Route_Table_NonProd: Can route to Security_DMZ and local staging subnets.

    Zero Route Propagation: TGW_Route_Table_NonProd contains

    zero routes to Prod_Core_VPC. Any packet from staging destined for a production IP is dropped at the Transit Gateway interface with zero network traversal.

    3. Security DMZ East-West Deep Packet Inspection [MC-DPI-01]
    • All cross-VPC traffic routes through the Gateway Load Balancer (GWLB):
      • Diverts packets to Palo Alto VM-Series firewalls without modifying IP headers (GENEVE encapsulation).
      • Enforces layer-7 application inspection, TLS decryption, and automated intrusion prevention (IPS) rules before forwarding packets to destination VPCs.

    Invariants and Contracts

    Strict Environment Network Isolation [INV-NET-01]
      Non-production VPCs must not have network routes to production VPCs.
      Configuring direct VPC peering, transit routing, or shared subnets between Prod and Non-Prod is strictly prohibited.
    
    Mandatory East-West Security Inspection [INV-NET-02]
      Inter-VPC network traffic crossing distinct organizational security zones must traverse the central inspection DMZ.
      Bypassing firewall inspection via direct point-to-point VPC peering is prohibited by security policy.
    
    Private Subnet Isolation for Data Stores [INV-NET-03]
      Production database clusters and in-memory caches must reside in isolated private database subnets with zero internet routes.
      Assigning public IP addresses or attaching Internet Gateways to database subnets is strictly barred.
    

    Explicit Unknowns

    • Bandwidth saturation overhead on AWS Gateway Load Balancers when Kafka streams 160,000 events/second through the central inspection VPC (G-1).
    • Time required for BGP dynamic routing protocols to converge over AWS DirectConnect during primary fiber cut failovers (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    3 AWS regions across 140 VPCsprovidedEnterprise network infrastructure briefCurrent
    24 million accounts across $95B volumeprovidedFinancial scope intakeCurrent
    Incident NET-4919 $4.2M loss and lateral breachprovidedSecurity incident forensic post-mortemHistorical
    Transit Gateway hub-and-spoke and 100G DirectConnectprovidedCorporate Network Architecture PolicyCurrent
    Central Transit Gateway Hub (Option C) selecteddecidedDavid O'Reilly & Elena Rostova2026-09-15
    Mandatory environment isolation invariant INV-NET-01decidedArchitectural invariant INV-NET-012026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against network architecture standards:

    • Environment Isolation: PASS. Segregated TGW route tables prevent staging-to-prod routing (NET-4919 closed).
    • Inspection Rigor: PASS. Centralized Security DMZ with GWLB and Palo Alto firewalls inspects all traffic.
    • Topology Precision: PASS. Explicit CIDRs (10.50, 10.100, 10.150, 10.200) and protocols modeled.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-NET-01: David O'Reilly to determine whether AWS Cloud WAN should be evaluated to replace Transit Gateway for managing cross-region inter-continental routing across Frankfurt, Virginia, and Singapore in Q2 (Owner: David O'Reilly).

    Next steps

    1. Network Engineering squad deploys the central AWS Transit Gateway and segregated route tables.
    2. Security team configures the Gateway Load Balancer and Palo Alto VM-Series firewalls in the DMZ.
    3. Conduct staging penetration test attempting to ping production database IPs from staging pods to verify route drop.

    network-architecture-diagram-and-cloud-v.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Audit cloud VPC peering and Transit Gateway route domainsDocument lateral movement paths between network segmentsMap firewalls and load balancer mediators in a DMZGenerate traceable network views from observed traffic logs

    About this skill

    What it does

    This skill projects an authoritative logical, physical, declared or observed network topology into a bounded view. It preserves endpoint/device/interface/link/segment/route identities, topology state, provenance, omissions and notation loss.

    Use it when

    Use when consumers need a reproducible network view of already accepted elements and relations at exact model/configuration/observation revisions.

    For example: “Ransomware moved from a ward PC to the imaging system. Both were described as being on 'the hospital network'. Nobody has a diagram showing what could reach what.”

    What you get

    • Network Architecture Diagram

    Written as Markdown to <your output folder>/architecture/tasks/<run-id>/network-diagram/.

    What it will not do

    Do not use for network/cloud/security architecture, deployment diagrams, scanning, packet/flow analysis, troubleshooting, firewall/DNS/LB/VPN design, IaC/device configuration or implementation.

    How it works

    1. Check the subject is the network layer.
    2. State whether the view is intended, declared or observed.
    3. Draw segments with their address ranges and their purpose.
    4. Put every mediator on the diagram.
    5. Show direction and what is permitted, not just connectivity.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-task.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions