NAT GW Flashcards

1
Q

What does NAT mean?

A

Network address translation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Definition of NAT

A

Set of different processes that can address IP packets by changing their source or destination addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What does IP Masquerading do? What does IP Masquerading allow?

A

it hides CIDR blocks behind one IP. It allows many IPv4 addresses to use one public IP for “outgoing only” internet access.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What does normally happen to incoming connections when using NAT or IP masquerading?

A

The incoming connections don’t work unless they are a response to an outgoing communication.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What does normally happen to outgoing connections when using NAT or IP masquerading?

A

NAT is designed to let outgoing communication pass, any response traffic result of the outgoing communication is allowed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Which type of subnet should be chosen for using NAT GWs? Private or public and why?

A

Public, to be able to allocate a public IPv4 to the NAT GW.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

For what are public subnets needed in your VPC when using NAT GWs?

A

To allocate public IPv4 addresses.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Is there anything to be configured in Route tables to use NAT GWs?

A

Default routes are required to point to the IGW so that the traffic can be routed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which type of IPs are used by NAT GWs?

A

Elastic IPs (static public IPv4.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Where are elastic IPs allocated?

A

To your account in a region.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What type of resilience do NAT GWs offer?

A

AZ resilience.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Are NAT GWs highly available?

A

Yes, they are highly available within the AZ.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What happens to NAT GWs if a whole AZ fails?

A

As NAT GWs are AZ resilient, there would not be any recovery.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What can you do to have a fully region resilient service?

A

You must deploy one NATGW in each AZ with a route table in each AZ with NATGW as target

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Is there any disadvantage when designing a fully region resilient service?

A

Yes, it is pricy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Are NAT GWs managed by AWS?

A

Yes, they are provided as a managed service

17
Q

What can you do to increase bandwidth?

A

you can deploy multiple NAT GWs and distribute your services to use more NAT GWs.

18
Q

What are NAT GWs billed for?

A
  1. Usage per hour - 4 cents per hour approx.

2. Data volume processed - 4 cents per GB of processed data.

19
Q

Can NAT GWs be used to do port forwarding or be bastion hosts?

A

No, EC2 instances are used for this, you can run a NAT EC2 instance.

20
Q

What do you need to adjust in the EC2 configuration to use EC2 as a NAT?

A

You must disable the feature “Source/Destination Checks”

21
Q

What do NAT EC2 and NAT GWs have in common?

A

They need to run in a public subnet.

They both need a functional IGW.

22
Q

Which is easier to be used, NAT GWs or NAT EC2 instances?

A

In most situations, NAT GWs.

23
Q

What are the disadvantages of using NAT EC2 instances?

A
  1. It has more points of failure (Storage, instance itself, network, AZ)
  2. Limited to the resources assigned to the EC2 instance
24
Q

When are NAT EC2 instances good?

A
  1. Test VPC
  2. For scenarios with really low volume
  3. Costs are predictable
  4. It can be used for multiple purposes (it is an EC2 in the end)
25
Q

When are NAT GWs better than NAT EC2 instances?

A

If you prefer:

  1. Availability
  2. Bandwidth
  3. Lower level of maintenance
  4. High performance
26
Q

What are the limitations of NAT GWs?

A

It is not free tier.
It can’t do portforwarding.
It can’t be used as a bastion host.
It can only use NACLs, not SGs.

27
Q

Are NATs required for IPv6 addresses?

A

No, IPv6 addresses are publicly routable.

28
Q

How do you configure your route tables and IGW to have bi-directional traffic when using IPv6 addreses?

A

::/0 route pointing to the IGW

29
Q

How do you configure your route tables and IGW to have outbound-only traffic when using IPv6 addreses?

A

::/0 route pointing to a Egress-only internet gateway

30
Q

When creating a NAT GW, does it get automatically an elastic IP?

A

No, this is a manual configuration

31
Q

What is the main use for NAT GWs?

A

It is used to allow private instances to have outgoing-only communication to the public internet, this can be for example Software updates…