Urgent.News

What's breaking now, across thousands of outlets.

Tech

🍊How to Set Up an AWS NAT Gateway Give EC2 Instances in a Private Subnet Internet Access

How to Set Up an AWS NAT Gateway|Give EC2 Instances in a Private Subnet Internet Access An EC2 instance in a private subnet may need to download OS updates or access an external API. This article explains how to use a public NAT gateway so an EC2 instance in a private subnet can initiate connections to the internet. The traffic will follow this path: EC2 instance in a private subnet ↓ Public NAT…

To enable EC2 instances in a private subnet to access the internet, follow these steps:

1. Ensure the public subnet has a route to an internet gateway. In the AWS console, navigate to VPC > Subnets, select the target subnet ID, and check the route table. Look for a route with a Destination of 0.0.0.0/0 pointing to the internet gateway (igw-...).

2. Create a public NAT gateway in the public subnet. Open the VPC > NAT gateways section in the console, choose a zonal NAT gateway, select the public subnet, and allocate an Elastic IP address if necessary. Create the NAT gateway, and wait for it to reach the "Available" status.

3. Modify the route table associated with the private subnet. In the VPC > Subnets section, select the target private subnet and open its route table. Add a new route with a Destination of 0.0.0.0/0 and a Target pointing to your newly created NAT gateway (nat-...).

4. Adjust the public subnet's route table if needed. Ensure the public subnet's route table has a Destination of 0.0.0.0/0 pointing to the internet gateway (igw-...). This separation ensures the private subnet's traffic is routed through the NAT gateway.

5. Test the connectivity from the EC2 instance in the private subnet. Using a command like curl -I https://example.com, check if the instance can reach external sites. If the request fails, verify the NAT gateway's status, the 0.0.0.0/0 route in the private subnet's route table, the NAT gateway's public subnet route, and the EC2 instance's security group and network ACL settings.

6. Consider cost and architecture implications. NAT gateways incur charges based on usage. If only testing, delete the NAT gateway once complete. For setups requiring redundancy, consider multiple Availability Zones and regional NAT gateways for a more robust solution.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

React forgot to add something.

It is a simple and humble Global state management . I know, Now you are thinking "Why not React context or any others?". The answer is simple.

More from Monday 28 September →