NAT GW Flashcards

1
Q

What does NAT mean?

A

Network address translation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Definition of NAT

A

Set of different processes that can address IP packets by changing their source or destination addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does IP Masquerading do? What does IP Masquerading allow?

A

it hides CIDR blocks behind one IP. It allows many IPv4 addresses to use one public IP for “outgoing only” internet access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does normally happen to incoming connections when using NAT or IP masquerading?

A

The incoming connections don’t work unless they are a response to an outgoing communication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does normally happen to outgoing connections when using NAT or IP masquerading?

A

NAT is designed to let outgoing communication pass, any response traffic result of the outgoing communication is allowed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which type of subnet should be chosen for using NAT GWs? Private or public and why?

A

Public, to be able to allocate a public IPv4 to the NAT GW.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

For what are public subnets needed in your VPC when using NAT GWs?

A

To allocate public IPv4 addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is there anything to be configured in Route tables to use NAT GWs?

A

Default routes are required to point to the IGW so that the traffic can be routed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which type of IPs are used by NAT GWs?

A

Elastic IPs (static public IPv4.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where are elastic IPs allocated?

A

To your account in a region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What type of resilience do NAT GWs offer?

A

AZ resilience.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Are NAT GWs highly available?

A

Yes, they are highly available within the AZ.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What happens to NAT GWs if a whole AZ fails?

A

As NAT GWs are AZ resilient, there would not be any recovery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What can you do to have a fully region resilient service?

A

You must deploy one NATGW in each AZ with a route table in each AZ with NATGW as target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Is there any disadvantage when designing a fully region resilient service?

A

Yes, it is pricy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Are NAT GWs managed by AWS?

A

Yes, they are provided as a managed service

17
Q

What can you do to increase bandwidth?

A

you can deploy multiple NAT GWs and distribute your services to use more NAT GWs.

18
Q

What are NAT GWs billed for?

A
  1. Usage per hour - 4 cents per hour approx.

2. Data volume processed - 4 cents per GB of processed data.

19
Q

Can NAT GWs be used to do port forwarding or be bastion hosts?

A

No, EC2 instances are used for this, you can run a NAT EC2 instance.

20
Q

What do you need to adjust in the EC2 configuration to use EC2 as a NAT?

A

You must disable the feature “Source/Destination Checks”

21
Q

What do NAT EC2 and NAT GWs have in common?

A

They need to run in a public subnet.

They both need a functional IGW.

22
Q

Which is easier to be used, NAT GWs or NAT EC2 instances?

A

In most situations, NAT GWs.

23
Q

What are the disadvantages of using NAT EC2 instances?

A
  1. It has more points of failure (Storage, instance itself, network, AZ)
  2. Limited to the resources assigned to the EC2 instance
24
Q

When are NAT EC2 instances good?

A
  1. Test VPC
  2. For scenarios with really low volume
  3. Costs are predictable
  4. It can be used for multiple purposes (it is an EC2 in the end)
25
When are NAT GWs better than NAT EC2 instances?
If you prefer: 1. Availability 2. Bandwidth 3. Lower level of maintenance 4. High performance
26
What are the limitations of NAT GWs?
It is not free tier. It can't do portforwarding. It can't be used as a bastion host. It can only use NACLs, not SGs.
27
Are NATs required for IPv6 addresses?
No, IPv6 addresses are publicly routable.
28
How do you configure your route tables and IGW to have bi-directional traffic when using IPv6 addreses?
::/0 route pointing to the IGW
29
How do you configure your route tables and IGW to have outbound-only traffic when using IPv6 addreses?
::/0 route pointing to a Egress-only internet gateway
30
When creating a NAT GW, does it get automatically an elastic IP?
No, this is a manual configuration
31
What is the main use for NAT GWs?
It is used to allow private instances to have outgoing-only communication to the public internet, this can be for example Software updates...