Got it

What Is NAT Gateway?

Latest reply: Jan 22, 2022 05:52:11 282 8 6 4 0

Public NAT gateways and private NAT gateways are used in different scenarios to provide network address translation (NAT).

Public NAT Gateways

Public NAT gateways provide NAT with 20 Gbit/s of bandwidth for Elastic Cloud Servers (ECSs) and Bare Metal Servers (BMSs) in a Virtual Private Cloud (VPC), or servers in on-premises data centers that connect to a VPC through Direct Connect or Virtual Private Network (VPN), allowing these servers to share elastic IP addresses (EIPs) to access the Internet or to provide services accessible from the Internet.

Public NAT gateways support source NAT (SNAT) and destination NAT (DNAT).

  • SNAT translates private IP addresses into EIPs, allowing servers in a VPC to share an EIP to access the Internet in a secure and efficient way.

    Figure 1 shows the SNAT architecture.
    Figure 1 SNAT architecture
    en-us_image_0201532914.png


  • DNAT enables servers in a VPC to share an EIP to provide services accessible from the Internet through IP address mapping or port mapping.

    Figure 2 shows the DNAT architecture.

    Figure 2 DNAT architecture
    en-us_image_0201532822.png

Private NAT Gateways

Private NAT gateways provide private address translation services for Elastic Cloud Servers (ECSs) and Bare Metal Servers (BMSs) in a VPC. You can configure SNAT and DNAT rules to translate the source and destination IP addresses into transit IP addresses, so that servers in the VPC can communicate with other VPCs or on-premises data centers.

Specifically,

  • SNAT enables multiple servers across AZs in a VPC to share a transit IP address to access on-premises data centers or other VPCs.

  • DNAT enables servers that share the same transit IP address in a VPC to provide services accessible from on-premises data centers or other VPCs.

Transit Subnet

A transit subnet functions as a transit network. You can configure a transit IP address for the transit subnet so that servers in a local VPC can share the transit IP address to access on-premises data centers or other VPCs.

Transit VPC

The transit VPC is the VPC that the transit subnet is a part of.

Figure 3 Private NAT gateway
en-us_image_0000001112858352.png

The preceding figure shows two ways a private NAT gateway can be deployed.

  • Communications between two VPCs with an overlapping CIDR block

    Under normal conditions, VPCs with an overlapping CIDR block cannot access each other. But with private NAT gateways, you can configure SNAT and DNAT rules to translate the private IP addresses of the VPCs to transit IP addresses. In this way, servers in the two VPCs can communicate with each other.

  • Using a specific IP address to access a remote private network

    A private NAT gateway lets you use a specific IP address to access an on-premises data center or a VPC on a remote private network. The on-premises data center is connected to the transit VPC through Direct Connect or VPN. The VPC is connected to the transit VPC through a VPC Peering connection. In the figure, VPC 1 uses a private NAT gateway to access the remote private network. To do this, SNAT rules need to be configured to translate the private IP address in VPC 1 into specific IP addresses that can communicate with the private network, on the left.

support-doc-new-note.svgNOTE:

Private NAT gateways are available for OBT in the following regions: CN North-Beijing4, CN North-Ulanqab1, CN East-Shanghai1, CN South-Guangzhou, CN Southwest-Guiyang1, CN-Hong Kong, AP-Bangkok, AP-Singapore, and LA-Sao Paulo1.


How Do I Access the NAT Gateway Service?

You can access the NAT Gateway service through the management console or using HTTPS-based APIs.
  • Management console

    You can use the console to perform operations on NAT gateways. Log in to the management console and choose NAT Gateway from the service list.

  • APIs

    Use APIs if you need to integrate NAT Gateway into a third-party system for secondary development. For details, see NAT Gateway API Reference.


thanks
View more
  • x
  • convention:

Saqibaz
Saqibaz Created Jan 17, 2022 05:36:54 (4) (4)
Thank you dear  
Very helpful
View more
  • x
  • convention:

Saqibaz
Saqibaz Created Feb 19, 2022 03:38:45 (4) (0)
Thank You for the Feedback !  
Very helpful
View more
  • x
  • convention:

Saqibaz
Saqibaz Created Feb 19, 2022 03:38:52 (4) (0)
Thank You for the Feedback !  
Thank you!
View more
  • x
  • convention:

Saqibaz
Saqibaz Created Feb 19, 2022 03:38:58 (4) (0)
Thank You for the Feedback !  

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.