← AWS Advanced Networking: networks and production
20 / 22 · 120 MIN

NAT and IPv6: capacity, diagnosis and migration

Distinguish zonal and regional modes, identify the egress address and prepare changes with capacity and continuity evidence.

1. Identify the path translating the address

A partner allowlist must use the address the partner observes on the actual path. For a zonal public NAT, Internet egress through the same VPC's IGW uses its Elastic IP. If traffic goes through TGW or VGW, the relevant translated address is private. A private NAT does not become public egress merely by adding an IGW route; that path is rejected. Draw the destination, route and translations before changing the allowlist. An instance's private location alone does not determine the path used. For a financial service, confirm the source in partner logs with an authorized operation containing no real data, and associate that evidence with the route and NAT mode active at the time.

2. Choose availability with an explicit mode

Instructions for a zonal NAT do not describe every current mode. In a zonal design, one gateway in a single AZ creates a dependency for other zones using it. Distribution across AZs must include corresponding routes. Regional mode provides a common ID and manages presence across zones; it does not require a public subnet to host the gateway. Automatic expansion into a new AZ is not instantaneous and can temporarily process traffic in another zone. In manual mode, the team manages that expansion. Private NAT still requires zonal mode under the capabilities reviewed. Specify the selected mode, address ownership and expansion behavior in the design instead of approving only a box labelled highly available NAT.

3. Separate resolution, synthesis and IPv6 transport

An IPv6-only application querying an IPv4-only destination needs more than a DNS answer. DNS64 can synthesize an address using the 64:ff9b::/96 prefix and the IPv4 value; traffic for that prefix must reach a NAT gateway performing NAT64. If an IPv6 answer already exists, resolution retains that native path. For native IPv6 egress without Internet-initiated connections, use an egress-only internet gateway's behavior; it does not convert IPv6 into IPv4. In the exercise, verify the name, answer, more specific route and operation separately. The local model demonstrates only selection between a synthesized and a native destination; it does not query DNS or show that the application accepts both families. Keep that limit visible in the acceptance record.

4. Read capacity in the correct units

Failure to open connections can coexist with low bandwidth. Port capacity depends on concurrent connections to the same destination, defined by address, port and protocol. In the reviewed documentation, each IPv4 address adds up to 55,000 concurrent connections per destination; this is not a global HTTP requests-per-second limit. Check limits and quotas for the selected mode before sizing addresses. ErrorPortAllocation indicates source-port allocation failures and needs correlation with concurrency and connection reuse. For regional NAT, include the AvailabilityZone dimension as well as its ID. Compare metrics with matching intervals and units. Average bytes can hide packet-rate peaks, and an established-connection count including retransmissions does not, by itself, provide a transaction success rate.

5. Diagnose sessions without inventing availability

A client reusing a TCP connection after a long period without traffic can receive RST: the documented idle timeout is 350 seconds. Distinguish time without traffic from total transaction duration. Evaluate connection-pool behavior, keepalive and safe repetition without increasing retries for non-idempotent instructions. Pinging the gateway itself is not sufficient evidence of path health; test a suitable destination and the relevant operation. Supported protocols, MTU and fragmentation also matter. Raw IPsec and IPsec encapsulated in UDP through NAT-T are different cases. Do not automatically apply old sysctl advice found on a troubleshooting page: check the operating-system version and parameter availability before proposing a change to production Linux. Record what the observation proves and what remains uncertain.

6. Migrate with address and session contracts

Migrating from zonal to regional NAT can change addresses, interrupt connections, or both. Reusing an Elastic IP does not transfer session state; the documented reuse approach requires an interruption window. If new addresses are used, coordinate partner allowlists beforehand and retain an approved reversal strategy. During the exercise, track reconnections, acknowledged and pending instructions, port errors and the source observed by the destination. One successful HTTP test is insufficient to accept a batch using persistent connections. The RUN handover should include expected addresses and zones, team-defined thresholds, external-contract owners and criteria for stopping the change. Record the actual state before retiring old infrastructure. Keep the rollback decision tied to business recovery evidence, not only the gateway's provisioning state.

from ipaddress import IPv4Address, IPv6Address, IPv6Network

prefix = IPv6Network("64:ff9b::/96")
def synthesize(v4):
 return IPv6Address(int(prefix.network_address) | int(IPv4Address(v4)))

def conceptual_route(address):
 return "NAT64" if IPv6Address(address) in prefix else "native-IPv6"

assert str(synthesize("192.0.2.7")) == "64:ff9b::c000:207"
assert conceptual_route(synthesize("192.0.2.7")) == "NAT64"
assert conceptual_route("2001:db8::7") == "native-IPv6"
assert int(synthesize("192.0.2.7")) & 0xffffffff == int(IPv4Address("192.0.2.7"))
assert synthesize("192.0.2.7")!= synthesize("192.0.2.8")
print("five synthesis checks passed; no DNS query or network translation performed")
IN PRACTICE

Fictional example: a batch moves to regional NAT with new addresses. Internal calls work, but the partner rejects the source. The team identifies the unchanged allowlist, stops advancing the change and coordinates address acceptance with reconciliation of pending instructions.

Common pitfalls

Applying zonal limits to every mode; confusing an EIP with a private source through TGW; treating DNS64 as transport; interpreting IP reuse as session preservation.

Related topics: IPv6 and DNS · Capacity and observability · Cutover and partners

Take this idea with you

Design resolution, translation, capacity and continuity with the mode and path explicitly stated.

Create account

Reference: NAT gateways · ANS-C01

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.