NAT Instance
Network Address Translation
- Allow
Instances
in thePrivate Subnet
to access interner - Must be launched in the
Public Subnet
- Must be disabled
Source
andDestination
check - Need and
Elastic IP (ENI)
attached to theNat Instance
- From the
Private Route Table
thisIP
be the target NAT Instance
security rules:- Allow
HTTP
fromVPC CIDR
- Allow
HTTPS
fromVPC CIDR
- Allow
All ICMP - IPv4
fromVPC CIDR
for ping Private Route Table
security rules- Any connection outgoing to the internet
(0.0.0.0/0)
, be target toNAT Instance
Cons
ofNAT Instance
- Not
HA
- Not easy setup
Elastic IP
to make stable routeInternet Traffic
depends on EC2 performance (Network Throughput
)