This document will focus on the most commonly used design patterns and optimal configuration settings as best practices to consider when deploying the GWLB:
Tune TCP keep-alive or timeout values to support long-lived TCP flows
Enable Appliance Mode on AWS Transit Gateway to maintain flow symmetry for inter-VPC traffic inspection
Understand when to use Cross-Zone Load Balancing
Understand appliance and AZ failure scenarios
Choose one-arm firewall deployment mode for egress traffic inspection
Choose one-arm firewall deployment mode for SSL/TLS traffic inspection
Jumbo Frame supports MTU 8500, but the protected AWS instances have a default MTU of 9001. You must update MTU on AWS instances to enable the traffic inspection. Else, GWLB will drop the traffic.
If you have enabled SSL decryption on the Sensor, then MTU should not exceed 1500. If the MTU exceeds 1500, the Sensor does not decrypt jumbo traffic.
For more information, see Best practices for deploying Gateway Load Balancer and Traffic Mirroring limitations.