Links

Overview

The Network Address Translation (NAT) gateway allows VMs, inside a Virtual Data Center (VDC), to access the Internet, without requiring a public network interface. The NAT gateway can act as a default gateway for private networks. This allows VMs to initiate connections to the Internet and receive a response (Source NAT or SNAT), but not to receive inbound connections initiated from the Internet (Destination NAT or DNAT). VMs are “hidden” from the Internet and thereby are not exposed to Internet threats.
Using a NAT gateway increases security, simplifies the VDC architecture, requires only one public IP address, has a fully managed service. For example, a NAT gateway can be used to connect private VMs to public repositories, for software updates, or to NTP (Network Time Protocol) servers. You can use the IONOS Backup Service for private VMs. In this case, the VM does not need to publish any service to the Internet, but only needs to consume services from the Internet. Furthermore, the NAT gateway can be configured only to allow access to specific and trusted internet services, protecting the application from malicious public endpoints.

Specifications

Specifications of the NAT gateway are as follows:
  • Supports TCP, UDP, ICMP, and up to six private networks per NAT gateway.
  • Multiple public IP addresses and SNAT rules per NAT gateway.
  • Multiple NAT Gateways per VDC.
  • Individual configuration of multiple NAT rules per listener.
  • Default resource limit for NAT gateway is set to five per account. If more are required, please contact our support.

Routing tables

The routing table must be modified for private VMs to send traffic to the NAT gateway. The default route must point to the NAT gateway or, if this is not possible, a dedicated route must be created for every service or target to be consumed from the Internet.
Note:
If DNS on a VM, which has the default route defined to use the SourceNAT gateway, is required, you must ensure that proper SNAT rules for UDP are in place. Failing to do so may result in default DNS resolution not working.

Maintenance Window

The Managed NAT Gateway will be regularly maintained by IONOS and updated with the latest software versions and new features. IONOS reserves a weekly maintenance window which it can use for regular updates. It is scheduled every Monday between 02:00 - 04:00 am local time of the data center in which the Managed NAT Gateway service is deployed. During maintenance, a service interruption of up to 5 seconds may occur. Aside from that service interruption, no further service impact is anticipated, and the Managed NAT Gateway will continue to operate within its service description and configuration.
Additional update deployments may be possible and carried out outside the maintenance window, for example, in the case of urgent security patches.

Limitations

Only private LANs can be connected to the Managed NAT Gateway. The Managed NAT Gateway cannot be connected to a public LAN. Furthermore, changing a LAN attribute from "private" to "public" is not possible if the LAN is connected to a Managed NAT Gateway.