Public NAT Gateway Overview

Last Updated At: 2025-10-29 17:57:02

Converge Cloud NAT Gateway maps EIPs and ports to the private IPs and ports of CVM instances, allowing VPC CVMs without public IPs to access and be accessed over the public network.

It provides a rich set of features, including:

  • Source Network Address Translation (SNAT)
  • Destination Network Address Translation (DNAT)
  • Gateway traffic control
  • Traffic alarms
  • Bandwidth packages
  • Anti-DDoS protection
  • Automatic disaster recovery

SNAT (Source Network Address Translation)

  • Enables multiple CVMs in a VPC to access the public network through the same public IP address.
  • Maximum forwarding capacity: 5 Gbps per NAT Gateway.
  • Multiple EIPs can be bound to the NAT Gateway, allowing CVMs to access the public network through any of them.
  • To specify a particular EIP for public network access, add it to the SNAT address pool.

DNAT (Destination Network Address Translation)

  • Maps public IP addresses, protocols, and ports to the private IPs, protocols, and ports of CVMs in the VPC.
  • Allows services hosted on CVMs to be accessible from the internet.

Bandwidth Packages

  • NAT Gateway can be paired with IP bandwidth packages to share public network bandwidth among multiple IPs.
  • After binding EIPs to the NAT Gateway and adding them to bandwidth packages, applications with staggered traffic can reduce bandwidth costs.

Gateway Traffic Control

  • Traffic control can manage bandwidth from a private IP to the NAT Gateway.
  • Supports IP-level speed limiting and visual monitoring to protect key services.

Traffic Alarm

  • Custom traffic alarms can be configured for NAT Gateway metrics.
  • Notifications are sent automatically via email or SMS when thresholds are exceeded.
  • Monitoring and alarms are free to help identify and resolve issues quickly.

Anti-DDoS Protection

  • Anti-DDoS Pro defends against DDoS and CC attacks with up to 310 Gbps protection bandwidth.
  • An Anti-DDoS Pro instance can be bound to the NAT Gateway to enhance security.

Automatic Disaster Recovery

  • NAT Gateway features dual-server hot backup and automatic disaster recovery.
  • Services on a failed server are seamlessly switched to the backup server.
  • Ensures up to 99.99% availability for critical applications.

Use Cases

1. Secure Internet Access for Private Instances

  • Private CVMs can initiate outbound internet connections without exposing them to inbound traffic.
  • Example: E-commerce platform fetching supplier API data securely.

2. High-Volume Web Scraping and Data Collection

  • Supports up to 10 million simultaneous connections and 5 Gbps bandwidth.
  • Example: Market research firm operating web crawlers for pricing data.

3. Multi-Tier Application Architecture

  • Middle-tier services can access external APIs without direct public IPs.
  • Example: SaaS platform processing payment gateways and analytics.

4. Centralized Internet Gateway for Multiple Workloads

  • Simplifies network management and reduces IP address consumption.
  • Example: Digital agency managing 50+ client websites.

5. Development and Testing Environments

  • Provides internet access for CI/CD pipelines without exposing non-production CVMs.
  • Example: Software development company accessing Docker, npm, GitHub.

6. Hybrid Cloud Connectivity

  • Enables cloud resources to communicate with on-premises systems securely.
  • Example: Financial institution accessing market data feeds from cloud analytics workloads.

7. Public-Facing Services with IP Preservation

  • DNAT allows multiple services behind NAT Gateway using a single set of public IPs.
  • Example: Media company hosting multiple customer portals on separate CVMs.

8. Cost-Optimized Bandwidth Management

  • Bandwidth package integration reduces over-provisioning costs.
  • Example: Online education platform optimizing traffic based on peak hours.

9. Compliance and Audit Requirements

  • Centralized internet egress allows traffic logging and auditing for regulations like HIPAA.
  • Example: Healthcare provider ensuring secure patient data processing.

10. High-Availability Critical Applications

  • Automatic failover ensures continuous internet connectivity.
  • Example: IoT platform managing thousands of devices.

NAT Gateway Packages

Public NAT Gateway

  • Allows CVMs without public IPs to access the internet and be accessed via mapped EIPs.
  • Types:
    • Traditional NAT Gateway: Small, Medium, Large
    • Standard NAT Gateway: Beta in the Philippines (requires request)

Notes:

  • Public NAT Gateway supports up to 10 EIPs.
  • SNAT max connections = # of EIPs × 55,000.
  • Hybrid ECMP between Standard and Traditional not supported.

Comparison: Standard vs Traditional NAT Gateway

Item Standard NAT Gateway Traditional NAT Gateway
High availability Multi-AZ disaster recovery Cross-AZ via rapid migration
Gateway specification 2,000,000 concurrent connections, 5 Gbps Small: 1M, Medium: 3M, Large: 10M connections; peak outbound: 10–5,000 Mbps
Gateway fee Instance fee + CU fee (hourly, postpaid) Instance fee + network fee
ECMP Supported Supported
Gateway traffic control Not yet supported Supported
Gateway traffic logs Not yet supported Supported

Private NAT Gateway

  • Enables CVMs to access other VPCs and be accessed from public VPCs.
  • Beta in the Philippines (requires request).

Network Products Related to NAT Gateway

  • EIP (Elastic IP): Alternative or combined public network access with NAT Gateway.
  • Bandwidth Package: Share bandwidth across multiple EIPs to reduce costs.
  • Other Related Products:
    • CVM: NAT Gateway enables internet access.
    • VPC: NAT Gateway is part of VPC.
    • Route Table: Configure subnet routing through NAT Gateway.
    • Public Gateway: CVM accessible by NAT Gateway.
    • Anti-DDoS Pro: Defend NAT Gateway from attacks.
    • Network ACL: Control subnet inbound/outbound traffic.

Accessing the Internet via NAT Gateway

Step 1: Create a NAT Gateway

  • Log in to NAT Gateway console → +New → configure:
    • Gateway Name: Up to 60 characters
    • Region: Select
    • VPC: Select
    • Gateway Type: Small, Medium, Large
    • Outbound Bandwidth Cap: 10–5,000 Mbps
    • EIP Configuration: Existing or new
  • Note: Outbound bandwidth cap ≤ total EIP bandwidth.

Step 2: Configure Route Table for Subnet

  • In NAT Gateway list → click VPC ID → Subnets → select subnet → click route table → +New routing policy:
    • Destination: Public IP range
    • Next Hop Type: NAT Gateway
    • Next Hop: Choose existing NAT Gateway → Create

Step 3: Enable Gateway Traffic Monitoring (Optional)

  • NAT Gateway console → select NAT Gateway → Monitoring tab → Enable Gateway Traffic Monitoring Details.

NAT Gateway Fee Description

Standard NAT Gateway

  • Instance Fees: Billed hourly