§ · HELP

How to use the TransitLab AWS networking simulator

TransitLab is a browser-based simulator for the AWS network data plane. You build a topology, ask "can traffic get from A to B?", and the engine walks the path hop by hop — reaching the destination or stopping at the exact hop that breaks, with a reason and a fix.

The three panes

Reading a trace

A trace lists every hop on the forward path — subnet → route table → gateway → … — and ends in one of three ways:

Traces run both directions: if A reaches B but B has no route back, that asymmetry is flagged — the classic gotcha where a ping leaves but the reply never returns.

A failure also carries an analyzer-style code — TransitLab's own normalization of the failure, written the way AWS's Reachability Analyzer explains a blocked path: NO_ROUTE_TO_DESTINATION, ENI_SG_RULES_MISMATCH (a security-group drop), SUBNET_ACL_RESTRICTION (a NACL drop). Some coincide with real Reachability Analyzer codes; don't expect a 1:1 match. When the source (or, on an ingress drop, the destination) is a declared host, the result also includes a synthesized VPC Flow Log line (ACCEPT or REJECT) — so the vocabulary the console and the exam use is right there in the trace. Non-fatal issues surface as advisories rather than stopping the trace: appliance-mode AZ asymmetry, a stateless-NACL return path that only partly opens the ephemeral range, an endpoint with no declared host (so its security groups couldn't be evaluated).

What it models

Enough of the AWS data plane to reason about real hybrid topologies:

What it doesn't model

TransitLab is a focused data-plane simulator — routing plus SG/NACL filtering — not a full AWS emulator. By design it does not cover:

One working assumption: keep your CIDRs disjoint. The engine resolves routes by longest-prefix match and doesn't exhaustively flag every overlapping-CIDR misconfiguration across a whole topology.

Start here

Open the examples menu — 48 labs grouped by topic, from VPC and NAT through Transit Gateway, Direct Connect, BGP, PrivateLink, inspection, security groups & NACLs, and the IP path to Route 53 Resolver endpoints. Load "Two VPCs via TGW" — the smallest complete topology. Run the default trace, then break it on purpose (delete a route-table propagation, blackhole a prefix) and watch where the path stops. From there, work up to the Direct Connect, BGP, and security-group examples.

Open the simulator why I built it →