Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To give EC2 instances in a private subnet outbound IPv4 internet access, create a public NAT Gateway in a public subnet, associate an Elastic IP address with it, and route the private subnet’s 0.0.0.0/0 traffic to the NAT Gateway. The public subnet must itself have a default route to the VPC’s internet gateway, and the NAT Gateway must reach the Available state. This permits instances to initiate internet connections and receive replies; it does not let internet hosts initiate unsolicited connections to those instances.

What you need before creating the NAT Gateway

Use a VPC with an internet gateway attached, at least one public subnet, and at least one private subnet. The NAT Gateway goes in the public subnet, while the EC2 instance remains in the private subnet. Allocate an Elastic IP address for each public NAT Gateway, and make sure the relevant subnets are associated with the route tables you intend to update.

For a multi-AZ production design, AWS’s example uses two public subnets, two private subnets, two NAT Gateways, and corresponding private route tables. Check service quotas and Elastic IP availability before provisioning those resources. See AWS’s CLI walkthrough for a VPC with private subnets and NAT Gateways.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set up the routes and NAT Gateway

The setup depends on two routes: a public-subnet default route to the internet gateway, and a private-subnet default route to the NAT Gateway. Creating a NAT Gateway alone does not send instance traffic through it.

#1 Best Overall
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
  • Dual band router upgrades to 1200 Mbps high speed internet (300mbps for 2.4GHz plus 900Mbps for 5GHz), reducing buffering and ideal for 4K stream
  • Full Gigabit Ports - Gigabit Router with 4 Gigabit LAN ports, ideal for any internet plan and allow you to directly connect your wired devices
  • Boosted Coverage - Four external antennas equipped with Beamforming technology extend and concentrate the Wi-Fi signals
  • MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
  • Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home

Configure with the AWS CLI

  1. Create an internet gateway and attach it to the VPC:
    aws ec2 create-internet-gateway
    aws ec2 attach-internet-gateway --internet-gateway-id igw-... --vpc-id vpc-...
  2. Create public and private route tables, then associate each subnet with its intended route table. Use the IDs returned by the AWS CLI.
  3. In the public route table, add a default IPv4 route to the attached internet gateway:
    aws ec2 create-route --route-table-id rtb-public --destination-cidr-block 0.0.0.0/0 --gateway-id igw-...
  4. Allocate an Elastic IP address for the NAT Gateway:
    aws ec2 allocate-address --domain vpc
  5. Create a public NAT Gateway in the public subnet, using the allocation ID returned for the Elastic IP:
    aws ec2 create-nat-gateway --subnet-id subnet-public --allocation-id eipalloc-...
  6. Wait until the gateway is available:
    aws ec2 wait nat-gateway-available --nat-gateway-ids nat-...
  7. In the private route table associated with the EC2 subnet, direct the IPv4 default route to the NAT Gateway:
    aws ec2 create-route --route-table-id rtb-private --destination-cidr-block 0.0.0.0/0 --nat-gateway-id nat-...

Replace sample IDs with the values returned by your commands. AWS documents this two-AZ pattern with a NAT Gateway in each AZ and each private subnet routed through its AZ-local gateway in the AWS CLI tutorial.

Configure in the AWS Management Console

  1. Open the VPC console and choose NAT gateways, then create a NAT Gateway in the selected public subnet.
  2. Set Connectivity type to Public, select or allocate an Elastic IP address, and create the gateway.
  3. Wait for the NAT Gateway status to become Available.
  4. Open the route table associated with the private subnet, add a route with destination 0.0.0.0/0, and select the NAT Gateway as its target.

Confirm that the public subnet’s effective route table has 0.0.0.0/0 pointing to the attached internet gateway. The private route points to the NAT Gateway; these are separate routes serving separate subnets.

Rank #2
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Choose the right NAT type and subnet design

Public NAT Gateway for internet egress

A public NAT Gateway allows instances in a private subnet to connect to the public internet through an internet gateway. It uses an Elastic IP address. For this article’s outbound internet use case, choose public connectivity. AWS says the API defaults to public if no connectivity type is specified, but selecting and verifying the intended type avoids ambiguity in scripts and console setup. See the CreateNatGateway API reference.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Private NAT Gateway for private network connectivity

A private NAT Gateway is intended for private communication through a transit gateway or virtual private gateway, such as connectivity between VPCs or to an on-premises network. It is not the option for direct public internet access. AWS describes the distinction in its NAT device overview.

Rank #3
Sale
TP-Link AC1200 WiFi Router Dual Band Wireless Internet Router (Archer A54)
  • Dual-band Wi-Fi with 5 GHz speeds up to 867 Mbps and 2.4 GHz speeds up to 300 Mbps, delivering 1200 Mbps of total bandwidth¹. Dual-band routers do not support 6 GHz. Performance varies by conditions, distance to devices, and obstacles such as walls.
  • Covers up to 1,000 sq. ft. with four external antennas for stable wireless connections and optimal coverage.
  • Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
  • Access Point Mode - Supports AP Mode to transform your wired connection into wireless network, an ideal wireless router for home
  • Advanced Security with WPA3 - The latest Wi-Fi security protocol, WPA3, brings new capabilities to improve cybersecurity in personal networks

One gateway or one per Availability Zone

A single NAT Gateway can serve multiple private subnets, but it creates a dependency on that gateway and can route traffic across AZs. AWS recommends considering a NAT Gateway in each AZ to reduce the risk of a single-AZ failure affecting egress. Routing each private subnet through a gateway in the same AZ can also avoid cross-AZ data transfer charges. AWS’s private-subnet NAT example shows an AZ-aligned design.

Regional availability mode

The CreateNatGateway API reference documents both zonal and regional availability modes; zonal is the default. Regional mode is described as a single gateway that can work across multiple AZs, with automatic AZ expansion unless explicit AZ addresses disable that behavior. Availability and console or API behavior can vary by Region, so verify current support for your target Region in the API reference before designing around it.

Rank #4
Sale
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
  • DUAL-BAND WIFI 6 ROUTER: Wi-Fi 6(802.11ax) technology achieves faster speeds, greater capacity and reduced network congestion compared to the previous gen. All WiFi routers require a separate modem. Dual-Band WiFi routers do not support the 6 GHz band.
  • AX1800: Enjoy smoother and more stable streaming, gaming, downloading with 1.8 Gbps total bandwidth (up to 1200 Mbps on 5 GHz and up to 574 Mbps on 2.4 GHz). Performance varies by conditions, distance to devices, and obstacles such as walls.
  • CONNECT MORE DEVICES: Wi-Fi 6 technology communicates more data to more devices simultaneously using revolutionary OFDMA technology
  • EXTENSIVE COVERAGE: Achieve the strong, reliable WiFi coverage with Archer AX1800 as it focuses signal strength to your devices far away using Beamforming technology, 4 high-gain antennas and an advanced front-end module (FEM) chipset
  • OUR CYBERSECURITY COMMITMENT: TP-Link is a signatory of the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Secure-by-Design pledge. This device is designed, built, and maintained, with advanced security as a core requirement.

Understand NAT behavior and capacity

The NAT Gateway translates the source IPv4 address for an instance’s outbound request and allows response traffic back to that connection. It does not publish the private instance for inbound connections: unsolicited connections initiated from the internet are not allowed by this NAT arrangement. Security groups and network ACLs remain relevant and are not overridden by the gateway. AWS explains NAT behavior in its NAT device guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

AWS documents a limit of up to 55,000 simultaneous connections per NAT Gateway IPv4 address to each unique destination. A destination is defined by destination IP address, port, and protocol. AWS also documents up to eight associated IPv4 addresses overall and a default limit of two Elastic IP addresses for a public NAT Gateway; quota adjustments may be possible for the public-gateway Elastic IP limit. These are AWS service limits, not independent benchmark results. If connection pressure is suspected, inspect CloudWatch metrics ErrorPortAllocation and PacketsDropCount. Details are in AWS’s NAT Gateway operating guide.

Best Value
TP-Link Dual-Band AX3000 Wi-Fi 6 Wireless Gigabit Internet Router for Home
  • Next-Gen Gigabit Wi-Fi 6 Speeds: 2402 Mbps on 5 GHz and 574 Mbps on 2.4 GHz bands ensure smoother streaming and faster downloads; support VPN server and VPN client¹
  • A More Responsive Experience: Enjoy smooth gaming, video streaming, and live feeds simultaneously. OFDMA makes your Wi-Fi stronger by allowing multiple clients to share one band at the same time, cutting latency and jitter.²
  • Expanded Wi-Fi Coverage: 4 high-gain external antennas and Beamforming technology combine to extend strong, reliable, Wi-Fi throughout your home.
  • Improved Battery Life: Target Wake Time helps your devices to communicate efficiently while consuming less power.
  • Improved Cooling Design: No heat ups, no throttles. A larger heat sink and redefined case design cools the WiFi 6 system and enables your network to stay at top speeds in more versatile environments.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Estimate costs and reduce unnecessary NAT traffic

AWS bills for each hour a NAT Gateway is available and for each gigabyte it processes. The AWS CLI tutorial includes an illustrative estimate of about $0.045 per hour plus data-processing charges, but gives no year for that estimate; it is not a live or universal rate. Actual charges depend on Region, date, traffic volume, and other resources. Check AWS NAT Gateway pricing for the applicable Region and current estimate.

  • Keep traffic in the same AZ where practical. Route private subnets through a same-AZ NAT Gateway where the design permits to avoid cross-AZ data transfer charges.
  • Use VPC endpoints for supported AWS services. An endpoint can give service traffic a path that avoids NAT processing. AWS’s example configures an S3 gateway endpoint and notes that this gateway endpoint option has no cost in that example; do not assume the same pricing applies to other endpoint types or Regions.

See AWS’s NAT pricing guidance and VPC example for the cost strategies and topology.

IPv6 follows a separate route

In AWS’s dual-stack example, IPv6 default traffic (::/0) uses an egress-only internet gateway. That route is separate from the IPv4 0.0.0.0/0 route through the NAT Gateway; configuring one does not configure the other.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Troubleshoot a private instance that cannot reach the internet

  • Check that the NAT Gateway is public, is in a public subnet, and has an Elastic IP address.
  • For a public NAT Gateway, confirm the Elastic IP network border group matches the Availability Zone’s network border group; a mismatch can prevent creation.
  • Verify the public subnet’s effective route table sends 0.0.0.0/0 to the VPC’s attached internet gateway.
  • Verify the EC2 subnet is associated with the intended private route table and that its 0.0.0.0/0 target is the NAT Gateway ID.
  • Confirm the NAT Gateway state is Available.
  • If routes are correct but connections still fail, review security-group egress and network ACL egress and return-traffic rules.
  • If the problem appears to be connection capacity, inspect ErrorPortAllocation and PacketsDropCount in CloudWatch.
  • If the traffic is mainly to AWS services, check whether a suitable VPC endpoint can serve that traffic instead.

AWS documents the connectivity-type, subnet, Elastic IP, and gateway configuration details in Work with NAT gateways.

Quick Recap

Bestseller No. 1
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
TP-Link AC1200 Gigabit Dual Band WiFi Router (Archer A6)
MU-MIMO technology - (5GHz band) allows high speeds for multiple devices simultaneously
$44.99
SaleBestseller No. 2
SaleBestseller No. 3
TP-Link AC1200 WiFi Router Dual Band Wireless Internet Router (Archer A54)
TP-Link AC1200 WiFi Router Dual Band Wireless Internet Router (Archer A54)
Supports IGMP Proxy/Snooping, Bridge and Tag VLAN to optimize IPTV streaming
$29.99
SaleBestseller No. 4
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
TP-Link AX1800 WiFi 6 Router (Archer AX21 V5)
VPN SERVER: Archer AX21 Supports both Open VPN Server and PPTP VPN Server
$69.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.