Description
A VPC peering route with 0.0.0.0/0 or ::/0 can send traffic without a more specific route toward the peering connection. Specify the peer VPC’s actual CIDR or the required portion of it as the destination.
Peering does not provide internet exposure or transit through another VPC. It also cannot share the peer’s internet gateway or NAT. Actual communication requires active peering, routes on both sides and access controls such as security groups.
Potential impact
- Traffic for unnecessary destinations may follow an unsuitable path, causing connection failures or routing confusion.
- Unclear destinations and paths can complicate network access reviews and troubleshooting.
Remediation
- Restrict peering destinations to required peer VPC CIDRs, subnets or individual addresses.
- Review route tables, subnet associations and return paths on both sides, and allow only required security group traffic.
- After the change, verify intended communication in both directions and confirm that routes to other destinations remain unaffected.
Examples
These are partial examples requiring the referenced VPCs and peering connection. The route tables have different names, so adding the second resource alone does not change the existing route.
Before
resource "aws_route_table" "public_route_table" {
vpc_id = aws_vpc.vpc1.id
route {
cidr_block = "0.0.0.0/0"
vpc_peering_connection_id = aws_vpc_peering_connection.my_peering.id
}
}
The default IPv4 route points to the peering connection. This does not turn the peer VPC into an internet gateway.
After
resource "aws_route_table" "private_route_table" {
vpc_id = aws_vpc.vpc1.id
route {
cidr_block = aws_vpc.vpc2.cidr_block
vpc_peering_connection_id = aws_vpc_peering_connection.my_peering.id
}
}
The destination is limited to the CIDR of peer VPC vpc2. Narrow it further if only a smaller range is needed, and verify the table’s subnet associations and the peer’s return route.