Networking
Part 3 of 6 · Private NetworkingNAT Gateways & Egress — Private Subnets, NAT vs NAT Instance, Egress Control
A private subnet has no direct internet-gateway route. NAT lets IPv4 workloads start outbound flows. It is not a firewall and not inbound publishing. Prefer endpoints when the destination is a supported AWS API, and one NAT gateway per AZ when you pay for resilience.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Managed NAT vs doing it yourself
Prefer
NAT gateway for standard IPv4 egress
AWS-managed, no instance patching, high bandwidth. Put one in each AZ and route same-AZ private subnets to it. Still not a domain filter.
- Hourly plus per-GB processing.
- AZ-local. A shared NAT makes other AZs depend on it.
- Responses follow established flows only.
Alternative
NAT instance, or NAT you did not need
An instance fits custom filtering you will actually operate. Endpoints fit AWS APIs. An egress-only internet gateway fits IPv6, not IPv4.
- You own patching, sizing, failover, and source/dest check.
- Interface endpoints have their own hourly and data charges.
- Do not assume an instance is cheaper after HA and ops.
Overview
A private subnet has no direct route to an internet gateway. Instances may still need to start outbound connections for updates, package repos, external APIs, or AWS services. A common IPv4 design routes that traffic through a NAT gateway in a public subnet. The NAT uses the public subnet's IGW route and an Elastic IP.
Private describes routing, not a promise that the workload cannot talk outward. NAT allows connections started inside. It does not publish the instance for unsolicited inbound. Return packets belong to established flows.
Ask what the workload needs before you add NAT. If it only calls supported AWS APIs, VPC endpoints may avoid the internet path and the NAT processing charge.
Options
| Option | Good fit | Strengths | Trade-offs |
|---|---|---|---|
| NAT gateway | General managed IPv4 egress | Managed, scales, high bandwidth | Hourly and per-GB; not domain policy; AZ placement |
| NAT instance | Custom routing or a lab | Full control of software and logs | You own patching, failover, source/dest check, capacity |
| VPC endpoints | Supported AWS APIs | Avoids the public path; endpoint policy | Coverage varies; interface endpoints cost money; DNS |
| Egress-only IGW | Outbound IPv6 | Managed stateful IPv6 egress, no NAT | IPv6 only; not IPv4 and not a general filter |
Placement. One NAT gateway in a public subnet that routes to an IGW. Private subnets send IPv4 0.0.0.0/0 to that NAT. A NAT gateway lives in one AZ. For resilience, deploy one per AZ and route each private subnet to the same-AZ NAT. A single shared NAT is cheaper in gateway-hours and makes other AZs depend on it, with cross-AZ transfer.
Endpoints. Gateway endpoints for S3 and DynamoDB are route-table entries. Interface endpoints are private ENIs plus optional private DNS. They are not a universal internet replacement. Inventory services, regions, DNS names, and protocols.
Cost. Estimate NAT hourly charges, processed GB, cross-AZ transfer, and endpoint hourly and data charges. Compare against measured traffic, not instance count. Rates vary by region. Logging, destination transfer, and firewalls add more.
Egress control. Security groups can limit outbound protocol, port, and destination CIDR or prefix list. They are not an FQDN allowlist. NACLs are stateless and need return-path rules. For domain-aware policy, use Network Firewall, a controlled proxy, or an egress appliance, plus endpoint policies and DNS controls. NAT alone is not that policy.
Egress paths
Flow
- 1
1 Private workload
- next2 NAT public subnet
- 2
2 NAT public subnet
- next3 Internet gateway
- 3
3 Internet gateway
- next4 Public internet
- 4
4 Public internet
- next5 Established response
- 5
5 Established response
Lesson map
NAT Gateways & Egress — Private Subnets, NAT vs NAT Instance, Egress Control
A private subnet has no direct internet-gateway route. NAT lets IPv4 workloads start outbound flows. It is not a firewall and not inbound publishing. Prefer endpoints when the destination is a supported AWS API, and one NAT gateway per AZ when you pay for resilience.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB a["1 Private workload"] n["2 NAT public subnet"] i["3 Internet gateway"] x["4 Public internet"] a -->|1 Private workload| n n -->|2 NAT public subnet| i i -->|3 Internet gateway| x
Supported AWS APIs can skip that path.
Flow
- 1
1 Private workload
- next2 VPC endpoint
- 2
2 VPC endpoint
- next3 AWS service
- 3
3 AWS service
- 4
4 IPv6 workload
- next5 Egress-only IGW
- 5
5 Egress-only IGW
- next6 IPv6 internet
- 6
6 IPv6 internet
Single-AZ NAT failure
With one NAT in AZ A, private subnet B's default route crosses AZs. If that NAT or AZ fails, both subnets lose this IPv4 egress path. Per-AZ NAT gateways and same-AZ routes keep a surviving AZ's egress local. That does not make every dependency highly available. Check retries, DNS, endpoint health, and any central firewall.
Flow
- 1
1 Private subnet A
- next2 NAT gateway AZ A
- 2
2 NAT gateway AZ A
- next3 IGW route
- 3
3 IGW route
- 4
4 Private subnet B
- next5 Cross-AZ to NAT A
- 5
5 Cross-AZ to NAT A
- next6 AZ A down drops both
- 6
6 AZ A down drops both
Sandbox: rough NAT cost (Python)
Supply current regional rates. Count cross-AZ GB only when traffic actually crosses AZs and is billable. This is a sketch, not a bill.
Press Run. Snippets must be self-contained — no network, files, or native modules.
Sandbox: gateways versus displaced GB (TypeScript)
CDK can ask for natGateways equal to AZ count and a gateway endpoint on private subnets. The runnable model below is the decision, not a synth. Confirm route tables and endpoint coverage in a real template. The sketch below is the same idea without the CDK imports:
// aws-cdk-lib sketch — not runnable here
// natGateways: 2 // one per AZ
// subnetType: PRIVATE_WITH_EGRESS
// addGatewayEndpoint S3 on private subnetsPress Run. Snippets must be self-contained — no network, files, or native modules.
Subtract only the NAT traffic endpoints actually displace. Do not double-count, and do not assume every AWS call uses an endpoint.
GCP and Azure
GCP Cloud NAT is managed, configured with Cloud Router, and gives outbound access without external IPs on the workload. It does not accept unsolicited inbound. Review IP allocation, ports, logging, and regional scope.
Azure NAT Gateway provides managed outbound connectivity for a subnet using static public IPs or prefixes. It is not inbound publishing. Check subnet association, SNAT ports, and regional price.
In all three clouds, a managed NAT is not automatically a firewall or an FQDN allowlist.
Pitfalls
List the AWS APIs a private fleet calls. Mark which can move to gateway or interface endpoints. Then estimate one shared NAT plus cross-AZ GB versus one NAT per AZ with the endpoint traffic removed.
Interview Q&A
Why does a private subnet need NAT?
Answer
It does not, by definition. NAT is a common way for private IPv4 workloads to start connections to public IPv4 without public addresses on those workloads. Endpoints or a proxy may fit better.
Why one NAT gateway per AZ?
Answer
It removes routine cross-AZ NAT traffic and limits an AZ-local failure. The trade-off is more hourly cost. A single NAT is cheaper in gateway-hours and creates a dependency.
Does NAT prevent inbound access?
Answer
It prevents unsolicited inbound connections through the NAT mapping. It is not a substitute for security groups, firewall policy, or application security. A public load balancer or other ingress path is a separate design.
NAT gateway or NAT instance?
Answer
Prefer a NAT gateway for a standard managed service when cost and features fit. Use an instance when you need custom network software and will operate patching, scaling, monitoring, and failover. Do not assume the instance is cheaper after HA.
How do you reduce NAT cost?
Answer
Measure traffic. Add endpoints for supported AWS services. Route each AZ locally. Do not send internal destinations out the public path. Compare endpoint, NAT, and transfer charges. Do not drop resilience only to save hourly cost.
How do you restrict egress to approved domains?
Answer
Security groups constrain ports and IP ranges. They are not robust domain filters. Use a proxy or firewall with application-layer controls, and account for DNS, TLS, IP changes, and bypass paths. Endpoint policies are service-specific.
Where does the NAT gateway sit?
Answer
In a public subnet whose route table sends the default route to an internet gateway. Private subnets send their default route to the NAT, not to the IGW.
What is an egress-only internet gateway?
Answer
Managed stateful egress for IPv6. It does not provide IPv4 NAT and it is not a general outbound filter.
What fails first in a single-AZ NAT design?
Answer
The NAT's AZ. Every subnet whose default route targets that gateway loses this IPv4 path, including subnets in healthy AZs.
How do endpoints change the bill?
Answer
They remove only the traffic they actually capture from NAT processing. Interface endpoints add their own hourly and data charges. Gateway endpoints for S3 and DynamoDB are usually the first win.
Is return traffic a new inbound connection?
Answer
No. NAT and the stateful path allow responses to flows the private side started. A scan of the private instance from the internet does not arrive through the NAT mapping.
What would you verify after CDK sets natGateways to the AZ count?
Answer
Synthesized route tables, same-AZ targets, and which private subnets still need a default route because an endpoint does not cover that destination.