EC2 unable to connect to


Hi , we have below environment setup and we are unable to connect to .

EC2 server(No public ip) and NAT gateway in same subnet, The subnet has route next hop Natgateway

my question is why cant NAT gateway reach without internet gateway? if we have both EC2 and NATgateway in the single subnet will the EC2 be able to connect to internet ? without internet gateway?

Will the NAT gateway be able to connect to internet independently? we need only outbound

please help

질문됨 4달 전165회 조회
1개 답변
수락된 답변


If a VPC does not have access to an Internet gateway, that VPC will not have an entrance/exit for communicating with the public network, so communication will not be possible even if a NAT Gateway is created.
NAT Gateway connects to the public network through the Internet gateway, so even if you create a NAT Gateway in a subnet that does not have a route to the Internet gateway, you will not be able to communicate to the public network.
Communication takes place as shown in the diagram in the document below.

profile picture
답변함 4달 전
profile pictureAWS
검토됨 4달 전
  • So in our case , when they are in same subnet , how should we create the route to internet gateway?

  • Does that mean EC2 and NAT Gateway are in the same subnet? I think that communication will probably not be possible even if the route to the Internet gateway and the route for the public access NAT Gateway are set in the same route table. Therefore, if you want to go through NAT Gateway, you will need to start EC2 in a private subnet and set a route to NAT Gateway in the route table.

  • Can u explain me why NAT should go through Internet gateway, why can’t this route the traffic alone

  • An internet gateway is linked to a VPC, but a NAT gateway is created within a subnet. The Internet gateway is your VPC's only gateway to the public network. If there is no Internet gateway, the VPC will lose the gateway to communicate with the public network, so even if there is a NAT Gateway, it will not be possible to communicate with the public network.

    Public – (Default) Instances in private subnets can connect to the internet through a public NAT gateway, but cannot receive unsolicited inbound connections from the internet. You create a public NAT gateway in a public subnet and must associate an elastic IP address with the NAT gateway at creation. You route traffic from the NAT gateway to the internet gateway for the VPC. Alternatively, you can use a public NAT gateway to connect to other VPCs or your on-premises network. In this case, you route traffic from the NAT gateway through a transit gateway or a virtual private gateway.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠