EC2 instances in private subnets must initiate all outbound requests, including traffic to the on-premises datacenter over Direct Connect. No external resource must initiate connections to these EC2 instances. The on-premises customer gateway uses a stateful firewall that filters traffic for multiple VPCs, and the company prefers to use a single IP match on the firewall to allow all EC2 traffic. Which option meets the requirements with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Deploy a NAT gateway into a private subnet in the VPC where the EC2 instances are deployed. Specify the NAT gateway type as private. Configure the on-premises firewall to allow connections from the IP address that is assigned to the NAT gateway..
Why this is the answer
The correct option is to deploy a private NAT Gateway. This allows EC2 instances in private subnets to initiate outbound connections to the on-premises datacenter via Direct Connect. The private NAT Gateway provides a single, static IP address that can be configured on the on-premises firewall, meeting the requirement for a single IP match. This approach ensures that no external resources can initiate connections to the EC2 instances, as the NAT Gateway only handles outbound-initiated traffic. It offers high availability and managed service benefits, leading to the least operational overhead. Creating a VPN over Direct Connect or configuring the on-premises firewall to filter requests directly from the on-premises network to EC2 instances would not provide a single source IP for all outbound traffic from the EC2 instances, making firewall management more complex. Deploying a NAT instance would require more operational overhead for management and scaling compared to a managed NAT Gateway.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed