NAT Instance
Network Address Translation- Allow
Instancesin thePrivate Subnetto access interner - Must be launched in the
Public Subnet - Must be disabled
SourceandDestinationcheck - Need and
Elastic IP (ENI)attached to theNat Instance - From the
Private Route TablethisIPbe the target NAT Instancesecurity rules:- Allow
HTTPfromVPC CIDR - Allow
HTTPSfromVPC CIDR - Allow
All ICMP - IPv4fromVPC CIDRfor ping Private Route Tablesecurity rules- Any connection outgoing to the internet
(0.0.0.0/0), be target toNAT Instance ConsofNAT Instance- Not
HA - Not easy setup
Elastic IPto make stable routeInternet Trafficdepends on EC2 performance (Network Throughput)