AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryMedium
A SysOps administrator is troubleshooting intermittent connectivity issues for an EC2 instance in a private subnet. The instance needs to connect to an external API over the internet. The security groups and network ACLs are correctly configured. The instance has no public IP address. What is the most likely missing component that prevents the instance from reaching the internet?
- AA NAT Gateway in a public subnet with a route from the private subnet.
- BAn Internet Gateway attached to the VPC.
- CA VPC Endpoint configured for the external API.
- DAn Elastic IP address associated with the EC2 instance.
Show answer & explanationAnswer & explanation
Correct answer: A. A NAT Gateway in a public subnet with a route from the private subnet.
EC2 instances in a private subnet with no public IP address cannot directly initiate outbound connections to the internet. A NAT Gateway, placed in a public subnet, allows instances in private subnets to connect to the internet while preventing inbound connections initiated from the internet. The private subnet's route table must have a route to the NAT Gateway.
Why the other options are wrong
- B. An Internet Gateway is necessary for the NAT Gateway to work, but the direct problem for the private instance is the lack of a NAT Gateway.
- C. VPC Endpoints are for AWS services, not external APIs over the internet.
- D. Associating an Elastic IP would expose the instance directly to the internet, which might not be desired for a 'private' subnet instance.
NAT Gateway
A NAT Gateway enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a connection with those instances.
- Resides in a public subnet.
- Requires an Elastic IP address.
- Private subnets route outbound internet traffic to the NAT Gateway.
Memory trick: Private instances need a 'NAT' to 'navigate' the internet safely and one-way.