NAT Instance Lab In this lab, we are going to learn how to create a NAT instance. A NAT instance provides network address translation (NAT) , and acts as a bastion host A bastion host is a specially hardened server that acts as a secure gateway between the public internet and a private network, controlling access to internal resources like private instances via protocols like SSH or RDP You can use a NAT instance to allow resources in a private subnet to communicate with destinations outside the virtual private cloud (VPC), such as the internet or an on - premises network. The resources in the private subnet can initiate outbound IPv4 traffi c to the internet, but they can't receive inbound traffic initiated on the internet. NAT instance basics The following figure illustrates the NAT instance basics. The route table associated with the private subnet sends internet traffic from the instances in the private subnet to the NAT instance in the public subnet. The NAT instance then sends the traffic t o the internet gateway. The traffic is attributed to the public IP address of the NAT instance. The NAT instance specifies a high port number for the response; if a response comes back, the NAT instance sends it to an instance in the private subnet based o n the port number for the response. The NAT instance must have internet access, so it must be in a public subnet (a subnet that has a route table with a route to the internet gateway), and it must have a public IP address or an Elastic IP address. Step 1. Create a VPC | Name: NAT - VPC | IPv4 CIDR: 10.0.0.0/16 | Step 1a. Create 3 Subnet s | Choose NAT - VPC | Subnet name: Public Subnet1 | Availability Zone: us - east - 1a | IPv4 subnet CIDR block: 10.0.0.0/24 | Subnet name: Public Subnet 2 | Availability Zone: us - east - 1 b | IPv4 subnet CIDR block: 10.0. 1 .0/24 | Subnet name: Private Subnet | Availability Zone : us - east - 1 c | IPv4 subnet CIDR block: 10.0. 2 .0/24 | Step 1b. Create an Internet Gateway and attach to VPC | Name: nat - igw | | Click on Actions: Attach to VPC | | Available VPC: NAT - VPC | Step 1c. Create 2 Route Table s, 1 public and 1 private | Name: public - route - table | | VPC: NAT - VPC | | Name: private - route - table | VPC: NAT - VPC | Step 1d. Click on Edit routes for public - route - table | Add route | Destination: 0.0.0.0/0 | Target: Internet gateway | Step 1e. Edit subnet association s for public - route - table | Select the Public Subnet1 & Public Subnet2 and Save associations | Step 1f. Edit subnet associati ons for private - route - table | Select the PrivateSubnet and S ave associations | Step 2. Create a security group for the NAT instance we will be launching later. | Security group name and Description: NATSG | VPC: NAT - VPC | Inbound rules: | Add rule Inbound rule 1 | Type: HTTP | Source type: Anywhere - IPv4 | | Add rule Inbound rule 2 | Type: HTTP S | Source type: Anywhere - IPv4 | | Add rule Inbound rule 3 | Type: ALL ICMP - IPV4 | Source type: Anywhere - IPv4 | | Outbound rules: Default | Step 3. Create a NAT AMI for Amazon Linux and l aunch an EC2 instance | Name: NAT INSTANCE CONFIG AMI | AMI: Amazon Linux and free tier eligible | Instance type: t 3 .micro | Keypair: select your existing key pair | Step 3a. Edit Network settings | VPC: NAT - VPC | Subnet: Public Subnet1 | Auto - assign public IP: Enable | | Security groups: Leave as default (SSH PORT 22) | Configure storage: leave as default | Step 3b. Review and launch the ec2 instance Step 4. Connect on to your EC2 instance and run commands | sudo su | yum update - y | Step 4a. Run the following commands on the instance to enable iptables | sudo yum install iptables - services - y | | sudo systemctl enable iptables | | sudo systemctl start iptables | Step 4b. Do the following on the instance to enable IP forwarding such that it persists after reboot Using a text editor nano , create the following configuration file | nano /etc/sysctl.d/custom - ip - forwarding.conf | Add the following line to the configuration file | net.ipv4.ip_forward=1 | | Ctrl S to save and CTRL X to exit | - Run the following command to apply the configuration file for ip forwarding | sudo sysctl - p /etc/sysctl.d/custom - ip - forwarding.conf | You will receive a message showing : net.ipv4.ip_forward = 1 - T his means it has been applied successful ly Step 4c. Run the following command on the instance and note the name of the primary network interface . You'll need this information for the next step | netstat - i | In the following output below, enX0 is the primary network interface , and lo is the loopback interface. In the following example output below , the primary network interface is ens5 Note: It could change between eth0, enX0, ens5. Step 4d. Run the following 3 commands on the instance to configure NAT. If the primary network interface is not e nX0 , replace enX0 with the primary network interface that you noted in the previous step. | sudo /sbin/iptables - t nat - A POSTROUTING - o enX0 - j MASQUERADE | sudo /sbin/iptables - F FORWARD | sudo service iptables save | Step 5. Right click on your instance, and c reate a NAT instance Amazon Machine Image (AMI) Image Name: | nat - instance - ami | | Leave everything else as default and create image | Step 6. Check to see if your image is in A vailable state (1 – 2 minutes) | After you have verified that the status is A vailable , Go back to your EC2 instance Dashboard and T erminate your “ NAT INSTANCE CONFIG AMI ” EC2 instance | Step 7 L aunch a public facing Amazon Linux EC2 Instance | Name : Jump Server | Network Settings: | VPC: NAT_VPC | | Subnet: PublicSubnet 1 | | Auto - assign public IP : Enable | | Security Groups: DEFAULT (SSH Port 22) | Step 8: Connect onto your EC2 Instance (Jump Server) and run commands: | sudo su | yum update - y | Now you are ready to move on and create a Private facing (Intranet) EC2 Instance. Step 9. Launch a private Amazon Linux EC 2 instance | Name : SECURE EC2 | Network Settings: | VPC: NAT_VPC | | Subnet: PrivateSubnet | | Auto - assign public IP : Disable | | Security Groups: DEFAULT (SSH Port 22) |