NAT gateways
In this article:
NAT gateways#
General information#
NAT gateways provide Internet access to private VPC networks. They act as egress-only gateways: cloud resources without Elastic IP addresses can initiate outbound connections to external networks, but external clients cannot establish connections to instances without associated Elastic IP addresses. To access the Internet, NAT gateways use Network Address Translation (NAT) technology. For outbound traffic, the private IP addresses of instances are replaced with the Elastic IP address associated with the NAT gateway in the same availability zone. The response traffic returns to the gateway and is correctly forwarded back to the private addresses of the request initiators.
Only one NAT gateway can be created for each VPC. A NAT gateway can be created only in a VPC to which the internet gateway is attached. For instances in a subnet to get Internet access through the NAT gateway, the subnet route table must have a 0.0.0.0/0 route via the NAT gateway.
Routing specifics in K2 Cloud#
The architecture of NAT gateways in K2 Cloud is designed with an emphasis on flexibility and simplification of the network infrastructure.
To provide Internet access to all instances in one subnet (with or without Elastic IP addresses), a route via the NAT gateway must be set in the route table. In this case, the cloud will correctly handle the traffic:
instances without associated Elastic IP addresses will access the Internet through the shared Elastic IP address of the NAT gateway in the same availability zone;
instances with associated Elastic IP addresses will access the Internet using their own addresses.
Note
If the default route is set via the internet gateway, instances without an associated Elastic IP address will not be able to access Internet.
Address association modes#
The NAT gateway uses Elastic IP addresses as public addresses. Only one Elastic IP address can be associated with a NAT gateway in each availability zone. When the NAT gateway is used to access the Internet, the private addresses of instances are translated to the Elastic IP address associated with this gateway in the same availability zone. If no address is associated with the NAT gateway in an availability zone, resources of this availability zone without an associated Elastic IP address will not be able to access Internet through the NAT gateway.
The address association mode is set when the NAT gateway is created:
Automatic mode — The cloud itself allocates and associates one Elastic IP address in each availability zone. 1
Manual mode — You specify pre-allocated Elastic IP addresses for the availability zones yourself. 2 In this mode, you can associate an Elastic IP address with the NAT gateway and disassociate already associated addresses.
- 1
In the automatic mode, Elastic IP addresses are allocated for each availability zone that has network resources associated with the VPC where the NAT gateway was created: instances, external networks connected to subnets, VPN connections, transit gateways. If there were no such resources in a particular availability zone at the time the NAT gateway was created, no address is allocated. When any of the above resources is created in the availability zone, an Elastic IP address is automatically allocated and associated with the NAT gateway. If all the associated resources are then deleted, the Elastic IP address is not released or deleted.
- 2
In the manual mode, you can use Elastic IP addresses from user pools or DDoS-protected pools.
Note
Elastic IP addresses are fixed to NAT gateways and do not change during the NAT gateway lifecycle.
When creating a NAT gateway, if the manual address allocation mode is selected, at least one Elastic IP address must be associated with it. If the manual mode is selected, all addresses can subsequently be disassociated from the NAT gateway — in this case, the VPC resources will not be able to access Internet through it.
Billing#
NAT gateways automatically created at the release of this functionality on October 1, 2026, and their addresses will be free of charge until February 1, 2027. Such gateways have a system tag with the AutoCreatedFromInternetGateway key and a value corresponding to the internet gateway ID.
Starting February 1, 2027, automatically created NAT gateways will be billed according to your tariff separately for each gateway and separately for each Elastic IP address associated with the gateway. If automatically created gateways and their Elastic IP addresses are not needed, they can be disabled and deleted to save money.
NAT gateways created by the user are billed from the moment of creation. If you delete an automatically created NAT gateway and create a new one instead, the new gateway and the Elastic IP addresses associated with it will be billed.
Available quotas#
The following default quotas and limits are provided for NAT gateways:
4 NAT gateways in a project;
1 NAT gateway per VPC (unchangeable limit).
If necessary, you can increase quotas. To do this, contact the support service via the support portal or by email support@k2.cloud.
Managing NAT gateways#
Create a NAT gateway#
Note
A NAT gateway can be created only in a VPC with an attached internet gateway.
Go to Virtual machines Networking NAT gateways.
Click Create.
In the NAT gateway creation wizard, specify the following parameters:
(Optional) Name tag.
The VPC where the gateway should be created.
The allocation mode for Elastic IP addresses.
Automatic — Elastic IP addresses are associated with the NAT gateway automatically (one in each availability zone);
Manual — You need to manually associate Elastic IP addresses with the NAT gateway (one in each availability zone).
Note
In the manual mode, you can use Elastic IP addresses from user pools or DDoS-protected pools.
If you need to set additional tags, go to the next step by clicking Add tags.
If you need to set a tag, click Add tag and specify the tag key and value. To assign more tags, click Add tag again.
If the Name tag has not been set, you can set its value by clicking Add Name tag.
After setting all the required parameters, click Create.
Associate an Elastic IP address#
Note
This option is available only if the manual allocation mode for Elastic IP addresses was selected when the NAT gateway was created.
Go to Virtual machines Networking NAT gateways.
Select a NAT gateway in the resource table and click Associate with Elastic IP.
In the dialog that appears, select Elastic IP addresses (one for each availability zone).
Click Assign.
In addition, Elastic IP addresses can be associated on the page of a specific NAT gateway. To do this, go to the IP addresses tab and click Associate with Elastic IP.
Note
Internet access via the NAT gateway will be provided only in those availability zones for which an Elastic IP address has been provided.
Disassociate an Elastic IP address#
Note
This option is available only if the manual allocation mode for an Elastic IP address was selected when the NAT gateway was created.
Go to Virtual machines Networking NAT gateways.
Select a NAT gateway in the resource table and click Disassociate Elastic IP.
From the drop-down list, select Elastic IP addresses (you can select several addresses)
Click Disassociate.
In addition, Elastic IP addresses can be disassociated on the page of a specific NAT gateway. To do this, go to the IP addresses tab and click Disassociate Elastic IP.
Attention
After performing this operation, Internet access from the availability zones where Elastic IP addresses were disassociated from the NAT gateway will become impossible.
Delete a NAT gateway#
Attention
Before deleting a NAT gateway, reconfigure the routes in the route tables in this VPC. If you delete a NAT gateway through which a route was created in the VPC route table, such a route automatically becomes a blackhole route. This will cause traffic with the corresponding destination to be dropped.
Go to Virtual machines Networking NAT gateways.
Select a NAT gateway in the resource table and click Delete. You can select several NAT gateways at the same time.
In the window that opens, confirm the deletion.
In addition, a specific NAT gateway can be deleted on its page. To do this, go to the Information tab and click Delete.
Alarm setup#
You can use alarms to configure the execution of a pre-defined action when the traffic volume through a NAT gateway exceeds a specified critical value.
Create alarm#
Note
Alarm can also be created in the section Monitoring Alarms.
Go to Virtual machines Networking NAT gateways.
Find the required NAT gateway in the resource table and click the resource name to go to its page.
Open the Alarms tab and click Create.
In the window that opens, select the metrics to be monitored:
InternetTrafficIn — The amount of incoming Internet traffic over the selected interval.
InternetTrafficOut — The amount of outgoing Internet traffic over the selected interval.
BilledInternetTrafficIn — The amount of billable incoming Internet traffic over the selected interval.
BilledInternetTrafficOut — The amount of billable outgoing Internet traffic over the selected interval.
Click Next.
Set alarm metrics (for details, see Alarms section):
the alarm name and, optionally, its description;
statistics;
the condition of triggering an alarm for the selected metric. It includes a comparison operator and a threshold value;
the number and duration of time periods, over which metric values are collected.
If necessary, you can also change the metric selected in the previous step.
If you do not need to configure alarm actions, skip this step. Otherwise click Set actions. The available actions include sending email notifications or executing a policy for an Auto Scaling group.
Once you have made all the required adjustments, click Create.
Change the alarm#
To change the alarm:
Go to Virtual machines Networking NAT gateways.
Find the required NAT gateway in the resource table and click the resource name to go to its page.
Open the Alarms tab, select the desired alarm in the table and click Modify.
The dialog window will open at the Parameters step. Modify the required alarm parameters:
description;
statistics;
monitored metrics;
the condition of triggering an alarm for the selected metric. It includes a comparison operator and a threshold value;
the number and duration of time periods, over which metric values are collected.
If you do not need to edit alarm actions, skip this step. Otherwise, click Set actions. As possible actions, you can:
add new alarm actions;
edit existing actions (change the email address or the Auto Scaling policy);
delete alarm actions.
Once you have made the required changes, click Modify to save them.
Delete the alarm#
Go to Virtual machines Networking NAT gateways.
Find the required NAT gateway in the resource table and click the resource name to go to its page.
Open the Alarms tab and select the alarm to be deleted in the alarm table. You can select multiple alarms at once.
Click Delete and confirm the action in the dialog window.
Information about NAT gateways#
The Information tab displays the main characteristics of a NAT gateway:
name (Name tag);
VPC;
state;
the selected allocation mode for Elastic IP addresses;
creation date.
The IP addresses tab displays a table with information about Elastic IP addresses assigned to this NAT gateway:
availability zone;
Elastic IP address;
allocation ID;
allocation status.
Here you can associate other Elastic IP addresses or disassociate addresses.
Note
This option is available only if the manual allocation mode for Elastic IP addresses was selected when the NAT gateway was created.
In the Metrics tab, you can view the graphs of the monitored metrics. You can set the period the metric graph covers, statistics, and metric calculation interval. To automatically refresh the graph, enable Auto-refresh; to refresh it manually, click Refresh.
Important
Automatic refresh is not possible when a custom period and/or interval is selected.
The Alarms tab displays details of alarms configured for the resource:
state;
alarm name;
triggering condition.
Alarms can be filtered by a state and/or metrics.
In addition, here you can create, modify or delete alarms.
The Tags tab displays all tags assigned to the NAT gateway. Here you can add new, modify existing, and delete no-longer-needed tags.