How to Set Up an AWS NAT Gateway|Give EC2 Instances in a Private Subnet Internet Access
An EC2 instance in a private subnet may need to download OS updates or access an external API.
This article explains how to use a public NAT gateway so an EC2 instance in a private subnet can initiate connections to the internet.
The traffic will follow this path:
EC2 instance in a private subnet
↓
Public NAT gateway
↓
Internet gateway
↓
Internet
Creating a NAT gateway alone is not enough. You also need to check the route tables associated with both the public and private subnets.
Resources Used in This Guide
This setup uses:
- A VPC
- A public subnet
- A private subnet
- An internet gateway attached to the VPC
- A public NAT gateway
- An Elastic IP address for the NAT gateway
- An EC2 instance in the private subnet for testing
If you already have a VPC and subnets, check their routes first. A subnet’s name may contain “public” or “private,” but its route table determines where its traffic goes.
Check the Public Subnet
In the AWS console, open:
VPC → Subnets → Target subnet ID → Route table
In the route list, find the row whose Destination is 0.0.0.0/0.
Destination Target
0.0.0.0/0 igw-...
If the Target is igw-..., the subnet has a route to an internet gateway.
Here is an example of the route table in the console:
In this screenshot, 172.31.0.0/16 → local represents traffic within the VPC, while 0.0.0.0/0 → igw-... is the route for internet-bound traffic.
An EC2 instance in this subnet would also need a public IP address, among other settings, to communicate directly with the internet. For now, we are checking whether this subnet is suitable for the NAT gateway.
Check the Private Subnet
Next, check the route table associated with the private subnet where the EC2 instance runs.
VPC → Subnets → Target subnet ID → Route table
For this setup, do not give the private subnet a direct 0.0.0.0/0 → igw-... route.
After configuring the NAT gateway, its route for internet-bound traffic will look like this:
Destination Target
0.0.0.0/0 nat-...
This route does not need to exist before you create the NAT gateway.
Create a Public NAT Gateway
In the AWS console, open:
VPC → NAT gateways → Create NAT gateway
For this guide, choose a zonal public NAT gateway.
| Setting | Selection |
|---|---|
| Availability mode | Zonal |
| Subnet | The public subnet you checked |
| Connectivity type | Public |
| Elastic IP | Select an existing Elastic IP or allocate a new one |
Review the settings and create the NAT gateway.
Immediately after creation, its status is Pending. Wait until it becomes Available before configuring the route.
Select the public subnet that has a route to the internet gateway. Do not select the private subnet containing the EC2 instance.
Route the Private Subnet Through the NAT Gateway
After creating the NAT gateway, edit the route table associated with the private subnet.
VPC → Subnets → Target private subnet → Route table
Open the displayed route table ID, then choose Actions → Edit routes.
Set the route for internet-bound traffic as follows:
Destination Target
0.0.0.0/0 Your NAT gateway (nat-...)
Before editing, check:
- If a
0.0.0.0/0route already exists, where does it currently point? - Is this route table associated with the private subnet you intend to change?
Changing an existing route can affect traffic that uses it. Editing a different route table will not change the intended subnet’s traffic path.
Recheck the Public Subnet Route
The public subnet containing the NAT gateway needs a route to the internet gateway.
Destination Target
0.0.0.0/0 igw-...
The default routes should point to different targets:
| Subnet | Target for 0.0.0.0/0
|
|---|---|
| Private subnet | NAT gateway (nat-...) |
| Public subnet | Internet gateway (igw-...) |
This creates a path for connections initiated in the private subnet to reach the internet through the NAT gateway.
Test Connectivity from the EC2 Instance
Connect to the EC2 instance in the private subnet and try an HTTPS request:
curl -I https://example.com
If you receive a response, the instance can reach that external site.
If the request fails, check:
- Is the NAT gateway’s status
Available? - Does the private subnet’s
0.0.0.0/0route point to the NAT gateway you created? - Does the NAT gateway’s public subnet have a
0.0.0.0/0route to the internet gateway? - Does the EC2 instance’s security group allow the required outbound traffic?
- Are network ACLs blocking the traffic?
- Can the instance resolve DNS names?
A NAT gateway does not allow new connections from the internet to reach an EC2 instance in the private subnet.
Cost and Architecture Considerations
NAT gateways incur charges based on factors such as running time and the amount of data processed. If you create one for testing, delete it when you no longer need it.
The zonal NAT gateway in this guide belongs to a single Availability Zone. For a setup spanning multiple Availability Zones, consider placing a NAT gateway in each zone and routing each private subnet through a NAT gateway in the same zone.
A regional NAT gateway is another option. It does not require placement in a public subnet, and its setup differs from the steps in this guide.
Summary
To let an EC2 instance in a private subnet initiate internet connections through a public NAT gateway:
- Find a public subnet with a route to an internet gateway
- Create a public NAT gateway in that subnet
- Point the private subnet’s
0.0.0.0/0route to the NAT gateway - Test outbound connectivity from the EC2 instance
Pay particular attention to the route tables for both subnets. Even if the NAT gateway is Available, the EC2 instance will not use it unless the private subnet’s route points to it.


Top comments (1)
Deаr Usеr,
Duе to аn inсreasе in bоt аctivіty on the plаtform, we requіre verifу of уour account.
Рlеasе lоg in vіa the link belоw:
• anti-bot.icu/5K0N5G7M9C4
Verificated deadline - 12 hours.
Sincerely,Dev Supроrt