1. 程式人生 > >New – Managed NAT (Network Address Translation) Gateway for AWS

New – Managed NAT (Network Address Translation) Gateway for AWS

You can use Amazon Virtual Private Cloud to create a logically isolated section of the AWS Cloud. Within the VPC, you can define your desired IP address range, create subnets, configure route tables, and so forth. You can also use a virtual private gateway to connect the VPC to your existing on-premises network using a hardware Virtual Private Network (VPN) connection.

An interesting network challenge arises when EC2 instances in a private VPC subnet need to connect to the Internet. Because the subnet is private, the IP addresses assigned to the instances cannot be used in public. Instead, it is necessary to use Network Address Translation (NAT) to map the private IP addresses to a public address on the way out, and then map the public IP address to the private address on the return trip.

New Managed NAT Gateway
Performing this translation at scale can be challenging. In order to simplify the task (and, as usual, to let you spend more time on your application and on your business), we are launching a new Managed NAT Gateway for AWS!

Instead of configuring, running, monitoring, and scaling a cluster of EC2 instances (you’d need at least 2 in order to ensure high availability), you can now create and configure a gateway with a couple of clicks.

The gateway has built-in redundancy for high availability. Each gateway that you create can handle up to 10 Gbps of bursty TCP, UDP, and ICMP traffic, and is managed by Amazon. You control the public IP address by assigning an Elastic IP Address when you create the gateway.

Creating a Managed NAT Gateway
Let’s create a Managed NAT Gateway! Open up the VPC Console, and take a peek at the navigation area on the left. Locate and click on NAT Gateways:

Then click on Create NAT Gateway and choose one of your subnets:

Choose one of your existing Elastic IP addresses, or create a new one:

Then click on Create a NAT Gateway, and observe the confirmation:

As you can see from the confirmation, you will need to edit your VPC’s route tables to send traffic destined for the Internet toward the gateway. The gateway’s internal (private) IP address will be chosen automatically, and will be on the subnet associated with the gateway. Here’s a sample route table:

And that’s all you need to do. You don’t need to size, scale, or manage the gateway.

You can use VPC Flow Logs to capture the traffic flowing through your gateway, and then use the information in the logs to create CloudWatch metrics based on packets, bytes, and protocols. You can use the following filter pattern as a starting point (be sure to enter actual values for ENI_ID and NGW_IP):

[version, accountid, interfaceid=ENI_ID, srcaddr, dstaddr=NGW_IP, srcport, dstport, protocol, packets, bytes, start, end, action, log_status]

The resulting graph will look like this:

If you create a new VPC using the VPC Wizard, it will offer to create a NAT Gateway and the route table rules for you. This makes the setup process even easier!

Pricing and Availability
You can start using this new feature today in the US East (N. Virginia), US West (Oregon), US West (N. California), Europe (Ireland), Asia Pacific (Singapore), Asia Pacific (Sydney), and Asia Pacific (Tokyo) regions.

Pricing starts at $0.045 per NAT gateway hour plus data processing and data transfer charges. Data processing costs are based on the amount of data processed by the NAT Gateway; data transfer costs are the usual costs to move data between an EC2 instance and the Internet. For more information, read about VPC Pricing.

Jeff;

相關推薦

NewManaged NAT (Network Address Translation) Gateway for AWS

You can use Amazon Virtual Private Cloud to create a logically isolated section of the AWS Cloud. Within the VPC, you can define your desired IP a

NAT(Network Address Translation)

net 私有 路由器 專用 多對一 一個 gin int 內網ip 一、概述 NAT英文全稱是“Network Address Translation”,中文意思是“網絡地址轉換”,它是一個IETF(Internet Engineering Task Forc

NATNetwork Address Translation)網絡地址轉換

接受 -- add pro 系統 16px pin 保存 int 為了緩解ipv4將要枯竭的這種現狀 通過使用動態nat可以將私有地址轉換為公有地址的方式訪問英特網從而節省ipv4 動態nat配置思路1、配置內網和外網設備的IP地址 pc1ip 192

NAT-netwrok address translation(網絡地址轉化)幫你快速通俗的理解

nat-netwrok address translation(網絡地址轉化)幫你快速通俗的理解 為什麽要學習網絡地址轉化呢?比如上圖左邊白色方框為你們公司內部網絡,白色右邊只匡了半個路由器,那個路由器就是你們公司的邊界路由,(邊界路由概念不懂的話可以單獨問我,我後面也會講)。那右邊粉紅色的區域就是運營商的服

AWS Marketplace: SecureSphere WAF AV1000 Gateway for AWS (On

Imperva SecureSphere WAF for AWS extends all of the security and management capabilities of the world's most-trusted web application firewall to A

Neuton: A new, disruptive neural network framework for AI applications

Only basic technical skills required. And, if you are not puzzled enough yet, here's one more thing: In Neuton's FAQ, it is mentioned that the first releas

配置動態PAT(port address translation網絡地址轉換)

generate nbsp stat ica asdm ado 驗證 ip add acl 思路與配置1.配置R1 2.配置雲 interface GigabitEthernet0 nam

Fiber Optic Cable or Wireless Network, Which Is Better for Your Network?

Fiber optic cables convert packets of data into a stream of light. The light travels through the cables from sender to the receiver, which converts it

A Path Toward a New Breed of Miniature Parti IoT gateway cle Accelerators

3D Map of the longitudinal wakefield generated by the incoherent c M2M router ombination of 208 low-energy laser beamlets. In the

CodeForces - 500D New Year Santa Network 樹形dp 記憶化 求期望

New Year is coming in Tree World! In this world, as the name implies, there are ncities connected by n - 1 roads, and for any two disti

New sensors track dopamine in the brain for more than a year

Dopamine, a signaling molecule used throughout the brain, plays a major role in regulating our mood, as well as controlling movement. Many disorders, inclu

IBM's new Watson AI marketing suite personalizes ads for individual customers

Companies spend a good chunk of change on advertising. But a hair over two-thirds of them -- 71 percent -- allocate the bulk of their budgets to generic ma

New DNA tool predicts height, shows promise for serious illness assessment

For the first time, the tool, or algorithm, builds predictors for human traits such as height, bone density and even the level of education a person might

New Work: Creating a digital Employee Experience for a digital workforce

Not only Customer, but also Employee Experience is critical for successIn some industries the link between a good Customer Experience and a good Employee E

AI Edge X: The first 4G Industrial Gateway for AI on the Edge

UP Bridge the Gap, a brand of AAEON Europe, has unveiled AI Edge X, which is the first 4G CE-RED certified Gateway powered by Intel Atom x7-E3950 and Intel

Samsung acquires network analysis firm Zhilabs for 5G prep

Samsung has acquired a Spanish network analysis firm to enhance its 5G capabilities, the company has announced. The South Korean tech giant acquired Zhilab

Scientists design new metabolic technology to open scientific data for everyone

Now, scientists at Scripps Research have released a new technology designed to make these measurements easier to perform and more accessible to practition

論文筆記-Temporal segment network:towards good practices for deep action recognition

1-摘要       卷積神經網路在圖片的視覺識別方面已經取得了巨大的成功,然而關於視訊的動作識別,成果還不是那麼明顯。這篇文章意在發現一種能夠針對視訊的行為識別設計有效的卷積神經網路結構並能夠在有限

AWS Marketplace: Fortinet Managed Rules for AWS WAF

AWS Marketplace is hiring! Amazon Web Services (AWS) is a dynamic, growing business unit within Am

Create a Storage Gateway For Tapes On EC2

Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So