iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
An instance in a private subnet has no public IP address, yet it can still download packages, call external APIs, and patch itself. The component that makes this work is an Amazon VPC NAT gateway. It lets the private instance start a connection outward, and it sends the replies back, while outside hosts have no route that lets them start a connection inward through that path.
A popular learner post on this exact topic frames the question as “how a machine without a public IP can still access the internet.” The short answer is that the instance never gets a public address of its own. Its outbound traffic is translated onto a gateway that does have one, and the route table decides which traffic takes that detour. The sections below walk through that path, the public and private gateway types, and the placement, cost, and security choices that follow from it.
What a NAT gateway does and does not do
AWS describes a NAT gateway as a way for instances in a private subnet to connect to services outside the VPC, while external services cannot initiate a connection with those instances. The exact sentence in the Amazon VPC User Guide, “NAT gateways,” reads: “You can use a NAT gateway so that instances in a private subnet can connect to services outside your VPC but external services can’t initiate a connection with those instances.”
That one-directional behavior is the point. A NAT gateway does not make a private instance public. The instance keeps its private IPv4 address, and no inbound route from the internet points at it. Connections must be initiated from inside the VPC that contains the gateway, and replies to those connections are allowed back.
#1 Best Overall
- Supports 3 SIP profiles through 1 FXS port and 4/8 FXO ports
- High-performance NAT router
- Lifeline support (FXS port will be hard-relayed to FXO port) in case of a power outage
- 3-way voice conferencing per port
- Automated & secure provisioning options using TR069
How traffic leaves a private instance
The path for internet-bound traffic from a private instance to a public NAT gateway has four hops. AWS’s use-case documentation describes this same layout with a private subnet and a public subnet in one VPC.
- The private instance sends traffic to a destination outside the VPC. Its subnet route table is consulted.
- The private subnet’s route for
0.0.0.0/0targets the NAT gateway, which sits in a public subnet. - The public subnet’s route for
0.0.0.0/0targets the VPC internet gateway. The NAT gateway forwards the traffic through that route. - The NAT gateway rewrites the source address. The private IPv4 address becomes the gateway’s private address, and the internet gateway maps that to the associated Elastic IP before the packet leaves. Replies follow the same mapping in reverse, so they reach the original instance.
Two route tables do the real work. If the private subnet’s default route is missing or points elsewhere, the instance has no way out. If the public subnet has no route to the internet gateway, the gateway has nowhere to send the traffic.
Public NAT gateway and private NAT gateway
AWS offers two NAT gateway types, and they serve different destinations. The choice is made when the gateway is created.
Rank #2
- Supports 2 SIP profiles and 8 FXS ports
- High performance NAT router
- Strong AES encryption with security certificate per unit
- Automated & secure provisioning options using TR069
- 3-way voice conferencing per port
| Type | Intended connectivity | Setup or limit |
|---|---|---|
| Public NAT gateway | Private-subnet instances to the internet. It can also be routed toward other VPCs or on-premises networks. | Create it in a public subnet, associate an Elastic IP, and route it to the VPC internet gateway for internet access. |
| Private NAT gateway | Private-subnet instances to other VPCs or on-premises networks. | Use a transit gateway or virtual private gateway path. It cannot have an Elastic IP, and an internet gateway drops traffic routed from a private NAT gateway. |
Source: Amazon VPC User Guide, NAT gateways.
If the goal is outbound internet access, the public type is the one to use. A private NAT gateway is for reaching other networks over a transit or virtual private gateway, not for reaching the internet.
IPv6 workloads
The IPv4 example above does not carry over unchanged to IPv6. For IPv6 workloads that only need outbound internet access, AWS describes an egress-only internet gateway as a separate option. For IPv6 workloads that must reach IPv4 resources, AWS describes NAT64 with DNS64. These are distinct network paths with their own routing, so treat them as separate designs rather than variations on the NAT gateway flow.
Setting up a public NAT gateway
AWS’s management procedure covers the same steps in the console and the API. In the VPC console, the gateways are listed under NAT gateways.
Rank #3
- Supports 2 SIP profiles and 2 FXS ports
- Strong AES encryption with security certificate per unit
- Supports T.38 Fax for reliable Fax-over-IP
- High performance NAT router
- 3-way voice conferencing per port
- Open the VPC console, choose NAT gateways, then choose Create NAT gateway.
- Enter a name, select the public subnet in the Availability Zone you are targeting, and select the public connectivity type.
- Select an existing Elastic IP, or allocate a new one. A public gateway needs one.
- Choose Create NAT gateway and wait until its state shows as available.
- In the route table for the private subnet, add a route for
0.0.0.0/0with the NAT gateway as the target. - Confirm that the route table for the public subnet has
0.0.0.0/0pointing to the internet gateway.
AWS’s working-with-NAT-gateways guide has the full procedure and the options for each setting: Work with NAT gateways.
Checking that egress works
AWS’s use-case documentation suggests two checks from a private instance. Both are useful for confirming the route table is right before you debug anything else.
- Run a trace route from the private instance to an external destination. The trace should include the NAT gateway’s private IP as a hop on the way out.
- Run an external source-IP check from the same instance. On the public internet route, the address seen outside should be the NAT gateway’s Elastic IP, not the instance’s private address.
The AWS scenarios page with these suggestions is at NAT gateway use cases.
Rank #4
- OPTIMIZED FOR U.S. CARRIERS (CAT 6 SPEED): Powered by high-speed LTE Advanced CAT 6 (up to 300Mbps), featuring 2x Carrier Aggregation for smoother streaming and reliable connectivity. Supports critical North American frequency bands (including B14 FirstNet, B66, and B71), making it the ideal mobile internet solution for RVs, trucks, and rural homes using AT&T, Verizon, or T-Mobile networks.
- HIGH-PRECISION GNSS/GPS TRACKING: Equipped with a dedicated GNSS antenna interface (GPS/GLONASS/BeiDou/Galileo), the IR315-G provides real-time location tracking for your assets. Perfect for fleet management, food trucks, or Overlanders who need to monitor their vehicle's location remotely via the cloud or integrate NMEA location data into local navigation systems.
- 4 DIGITAL I/O FOR SMART MONITORING: Transform your connectivity hub into an automation controller. With 4 Digital Input/Output ports, DIY enthusiasts and industrial managers can connect sensors (e.g., door open, water leak, temperature) to trigger alerts, or remotely control devices (e.g., rebooting a server, turning on an auxiliary heater) directly through the router’s interface.
- UNBREAKABLE CONNECTION & DUAL SIM: Designed for mobility. The Dual SIM slots allow you to load cards from two different carriers (e.g., Verizon & T-Mobile) to eliminate dead zones while traveling. Features intelligent failover between Wired WAN, Wi-Fi (Client Mode), and Cellular to ensure your security cameras, POS systems, or Starlink failover networks stay online 24/7.
- SECURE VPN & RUGGED DESIGN: Built to military-grade standards with a fanless metal casing (operating -4°F to 158°F) to withstand vibration in moving vehicles. Supports enterprise security including WireGuard, OpenVPN, and IPsec, allowing secure remote access to your home lab or vehicle network without a static IP. Includes free InHand Device Manager for remote cloud configuration
When outbound access fails
- The private subnet’s route table has no
0.0.0.0/0route, or the route targets something other than the NAT gateway. - The NAT gateway sits in a private subnet. A public gateway belongs in a public subnet.
- The public subnet’s route table has no
0.0.0.0/0route to the internet gateway. - The public gateway has no Elastic IP associated with it.
- The NAT gateway has not reached the available state yet.
Availability Zones and resilience
Each NAT gateway is created in a single Availability Zone, and AWS states that it is implemented with redundancy within that zone. The consequence is that a single shared gateway creates a dependency across zones. If the zone holding the gateway fails, resources in other Availability Zones that route through it can lose internet access.
AWS recommends creating one NAT gateway in each Availability Zone that has resources needing egress, then routing each subnet’s traffic to the gateway in its own zone. This costs more, because each gateway is billed on its own, but it removes the cross-zone dependency. The basics page is at NAT gateway basics.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteService limits
The NAT gateway basics page lists these limits:
- 5 Gbps baseline bandwidth, scaling automatically up to 100 Gbps.
- One million packets per second, scaling up to 10 million.
- Up to 55,000 simultaneous connections per IPv4 address to each unique destination.
These figures are AWS’s published limits. The basics page as consulted in October 2026 shows no publication or update date, so check the current page before relying on the numbers for capacity planning, because limits can change.
Best Value
- Supports 4 SIP profiles through 4 FXS ports and dual Gigabit ports Includes a built-in Nat router which can handle routing speeds up to 100Mbps. Include TR-069 and XML Confit files Failover SIP server automatically switches to secondary server if Main server loses connection
- Tells and SRTP security encryption technology to protect calls and accounts Automated provisioning options
- Black
- 4 Port
Cost
AWS bills a NAT gateway in two dimensions: an hourly charge for each hour the gateway is available, and a per-gigabyte charge for data it processes. Rates vary by Region and change over time, so check the pricing page for your Region before estimating a bill.
AWS’s pricing guidance suggests two ways to reduce processing charges. The first is to keep high-volume resources in the same Availability Zone as the NAT gateway, or to create a gateway in each zone. The second is to consider interface or gateway endpoints when most of the traffic goes to supported AWS services, since that traffic can then avoid the gateway. The pricing page is at NAT gateway pricing.
The exact-title learner article also places NAT instances, an older self-managed approach, in the comparison and points readers toward VPC endpoints and routing strategies. A NAT instance is not automatically cheaper or equivalent. The right choice depends on service needs, operational effort, the data path, and current regional pricing.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Security boundaries
A NAT gateway is a routing and translation component, not a complete security policy. A security group cannot be attached to a NAT gateway. Instance traffic is controlled by security groups on the instances, and traffic at the NAT gateway’s subnet is controlled by network ACLs. Do not treat the NAT gateway as a firewall replacement.
Because the gateway blocks inbound-initiated connections, it reduces exposure from the internet. It does not decide which outbound destinations are acceptable, which ports an instance may use, or what an instance does with the connection once it is open. Those decisions belong to security groups, network ACLs, and the instance’s own configuration. The basics page is linked above.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

