The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Deploying the AWS Gateway Load Balancer

Prev Next

This document will focus on the most commonly used design patterns and optimal configuration settings as best practices to consider when deploying the GWLB:

  1. Tune TCP keep-alive or timeout values to support long-lived TCP flows

  2. Enable Appliance Mode on AWS Transit Gateway to maintain flow symmetry for inter-VPC traffic inspection

  3. Understand when to use Cross-Zone Load Balancing

  4. Understand appliance and AZ failure scenarios

  5. Choose one-arm firewall deployment mode for egress traffic inspection

  6. Choose one-arm firewall deployment mode for SSL/TLS traffic inspection

  7. Jumbo Frame supports MTU 8500, but the protected AWS instances have a default MTU of 9001. You must update MTU on AWS instances to enable the traffic inspection. Else, GWLB will drop the traffic.

    If you have enabled SSL decryption on the Sensor, then MTU should not exceed 1500. If the MTU exceeds 1500, the Sensor does not decrypt jumbo traffic.

For more information, see Best practices for deploying Gateway Load Balancer and Traffic Mirroring limitations.