perimeter protection
sec grp, nACL, routing, endpoints , gateways
Why network segmentation
private acces to all VPCs from on premises
not: belong to different teams owners
path
first steps is route table, next step is the route table in transit gateway(destination is VPN),
AWS systems Manager( session Manager)
SSM