

# Amazon Network Firewall example architectures with routing
<a name="architectures"></a>

This section provides a high-level view of simple architectures that you can configure with Amazon Network Firewall and shows example route table configurations for each. For additional information and examples, see [Deployment models for Amazon Network Firewall](https://amazonaws-china.com/blogs/networking-and-content-delivery/deployment-models-for-aws-network-firewall/). 

**Note**  
For information about managing route tables for your VPC, see [Route tables](https://docs.amazonaws.cn/vpc/latest/userguide/VPC_Route_Tables.html) in the *Amazon Virtual Private Cloud User Guide*.

**Unsupported architectures**  
The following lists architectures and traffic types that Network Firewall doesn't support:
+ VPC peering.
+ Inspection of Amazon Global Accelerator traffic.
+ Inspection of AmazonProvidedDNS traffic for Amazon EC2.

**Topics**
+ [Simple single zone architecture with an internet gateway using Amazon Network Firewall](arch-single-zone-igw.md)
+ [Multi zone architecture with an internet gateway using Amazon Network Firewall](arch-two-zone-igw.md)
+ [Architecture with an internet gateway and a NAT gateway using Amazon Network Firewall](arch-igw-ngw.md)