1. Identify the path translating the address
A partner allowlist must use the address the partner observes on the actual path. For a zonal public NAT, Internet egress through the same VPC's IGW uses its Elastic IP. If traffic goes through TGW or VGW, the relevant translated address is private. A private NAT does not become public egress merely by adding an IGW route; that path is rejected. Draw the destination, route and translations before changing the allowlist. An instance's private location alone does not determine the path used. For a financial service, confirm the source in partner logs with an authorized operation containing no real data, and associate that evidence with the route and NAT mode active at the time.
2. Choose availability with an explicit mode
Instructions for a zonal NAT do not describe every current mode. In a zonal design, one gateway in a single AZ creates a dependency for other zones using it. Distribution across AZs must include corresponding routes. Regional mode provides a common ID and manages presence across zones; it does not require a public subnet to host the gateway. Automatic expansion into a new AZ is not instantaneous and can temporarily process traffic in another zone. In manual mode, the team manages that expansion. Private NAT still requires zonal mode under the capabilities reviewed. Specify the selected mode, address ownership and expansion behavior in the design instead of approving only a box labelled highly available NAT.
3. Separate resolution, synthesis and IPv6 transport
An IPv6-only application querying an IPv4-only destination needs more than a DNS answer. DNS64 can synthesize an address using the 64:ff9b::/96 prefix and the IPv4 value; traffic for that prefix must reach a NAT gateway performing NAT64. If an IPv6 answer already exists, resolution retains that native path. For native IPv6 egress without Internet-initiated connections, use an egress-only internet gateway's behavior; it does not convert IPv6 into IPv4. In the exercise, verify the name, answer, more specific route and operation separately. The local model demonstrates only selection between a synthesized and a native destination; it does not query DNS or show that the application accepts both families. Keep that limit visible in the acceptance record.
4. Read capacity in the correct units
Failure to open connections can coexist with low bandwidth. Port capacity depends on concurrent connections to the same destination, defined by address, port and protocol. In the reviewed documentation, each IPv4 address adds up to 55,000 concurrent connections per destination; this is not a global HTTP requests-per-second limit. Check limits and quotas for the selected mode before sizing addresses. ErrorPortAllocation indicates source-port allocation failures and needs correlation with concurrency and connection reuse. For regional NAT, include the AvailabilityZone dimension as well as its ID. Compare metrics with matching intervals and units. Average bytes can hide packet-rate peaks, and an established-connection count including retransmissions does not, by itself, provide a transaction success rate.
5. Diagnose sessions without inventing availability
A client reusing a TCP connection after a long period without traffic can receive RST: the documented idle timeout is 350 seconds. Distinguish time without traffic from total transaction duration. Evaluate connection-pool behavior, keepalive and safe repetition without increasing retries for non-idempotent instructions. Pinging the gateway itself is not sufficient evidence of path health; test a suitable destination and the relevant operation. Supported protocols, MTU and fragmentation also matter. Raw IPsec and IPsec encapsulated in UDP through NAT-T are different cases. Do not automatically apply old sysctl advice found on a troubleshooting page: check the operating-system version and parameter availability before proposing a change to production Linux. Record what the observation proves and what remains uncertain.
6. Migrate with address and session contracts
Migrating from zonal to regional NAT can change addresses, interrupt connections, or both. Reusing an Elastic IP does not transfer session state; the documented reuse approach requires an interruption window. If new addresses are used, coordinate partner allowlists beforehand and retain an approved reversal strategy. During the exercise, track reconnections, acknowledged and pending instructions, port errors and the source observed by the destination. One successful HTTP test is insufficient to accept a batch using persistent connections. The RUN handover should include expected addresses and zones, team-defined thresholds, external-contract owners and criteria for stopping the change. Record the actual state before retiring old infrastructure. Keep the rollback decision tied to business recovery evidence, not only the gateway's provisioning state.
from ipaddress import IPv4Address, IPv6Address, IPv6Network
prefix = IPv6Network("64:ff9b::/96")
def synthesize(v4):
return IPv6Address(int(prefix.network_address) | int(IPv4Address(v4)))
def conceptual_route(address):
return "NAT64" if IPv6Address(address) in prefix else "native-IPv6"
assert str(synthesize("192.0.2.7")) == "64:ff9b::c000:207"
assert conceptual_route(synthesize("192.0.2.7")) == "NAT64"
assert conceptual_route("2001:db8::7") == "native-IPv6"
assert int(synthesize("192.0.2.7")) & 0xffffffff == int(IPv4Address("192.0.2.7"))
assert synthesize("192.0.2.7")!= synthesize("192.0.2.8")
print("five synthesis checks passed; no DNS query or network translation performed")
Fictional example: a batch moves to regional NAT with new addresses. Internal calls work, but the partner rejects the source. The team identifies the unchanged allowlist, stops advancing the change and coordinates address acceptance with reconciliation of pending instructions.
Common pitfalls
Applying zonal limits to every mode; confusing an EIP with a private source through TGW; treating DNS64 as transport; interpreting IP reuse as session preservation.
Related topics: IPv6 and DNS · Capacity and observability · Cutover and partners
Design resolution, translation, capacity and continuity with the mode and path explicitly stated.
Reference: NAT gateways · ANS-C01