QuestionQ47

Networking and Content Delivery

A CloudOps engineer is troubleshooting a VPC that has public and private subnets using custom network ACLs. Instances in the private subnet cannot access the internet. An internet gateway is attached to the public subnet. The private subnet routes traffic to a NAT gateway that is also attached to the public subnet. The Amazon EC2 instances use the VPC's default security group.

What is causing the issue in this scenario?

Explanation

A network ACL filters traffic at the subnet level and can explicitly deny outbound traffic. Because network ACLs are stateless, a deny-all outbound rule on the private subnet prevents the instances’ internet-bound traffic from reaching the NAT gateway. A public NAT gateway belongs in a public subnet, and the default VPC security group allows all outbound IPv4 traffic.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!