AWS Certified Advanced Networking – Specialty (ANS-C01)Network Management and OperationsMedium
A company operates a web application with dynamic traffic patterns. During peak hours, users experience increased latency and connection timeouts. The current network configuration uses a single NAT Gateway in a public subnet for outbound internet access from private subnets. The NAT Gateway is showing high CPU utilization and dropped packets. What is the MOST effective way to optimize the network performance and improve resilience for outbound traffic?
- AMigrate the application to use VPC Endpoints for all external services.
- BDeploy multiple NAT Gateways, each in a different Availability Zone (AZ), and configure route tables accordingly.
- CIncrease the Elastic IP address count on the existing NAT Gateway.
- DChange the instance type of the NAT Gateway to a larger size.
Show answer & explanationAnswer & explanation
Correct answer: B. Deploy multiple NAT Gateways, each in a different Availability Zone (AZ), and configure route tables accordingly.
NAT Gateways are designed to scale automatically up to 45 Gbps, but they are zonal resources. High CPU and dropped packets indicate that the single NAT Gateway might be a bottleneck. Deploying multiple NAT Gateways across different AZs and configuring route tables to distribute traffic across them improves both performance and resilience by distributing the load and providing redundancy.
Why the other options are wrong
- A. VPC Endpoints are for accessing AWS services privately, not for general outbound internet access, and would not resolve NAT Gateway performance issues for non-AWS internet traffic.
- C. NAT Gateways are not scaled by increasing Elastic IP addresses; they are scaled by throughput capacity.
- D. NAT Gateway is a managed service; you cannot change its instance type. AWS automatically manages its underlying infrastructure.
NAT Gateway Scaling and Resilience
AWS NAT Gateways scale automatically but are zonal resources. For high availability and performance across AZs, multiple NAT Gateways should be used.
- Scales automatically up to 45 Gbps throughput.
- A single NAT Gateway is tied to a specific Availability Zone.
- Deploying one NAT Gateway per AZ and configuring route tables provides redundancy and load distribution.
Memory trick: To scale 'NAT' traffic, 'distribute' it across 'AZs'.