Overview

Both connect a VPC to the internet, but they serve opposite purposes: an Internet Gateway lets public-facing resources send and receive traffic directly, while a NAT Gateway lets private resources reach out without ever being reachable from outside. Picking the wrong one either exposes resources you meant to keep private or silently blocks the outbound access your servers need.

Comparison Diagram

Internet GatewayNAT GatewayInternetInternetno inboundIGWNAT GatewayPublic SubnetInstancehas public IPPrivate SubnetInstanceprivate IP onlybidirectional trafficoutbound only

Comparison Table

AspectInternet GatewayNAT Gateway
Primary purposeEnables communication between a VPC and the internet in both directionsEnables outbound-only internet access for resources without public IPs
Traffic directionBidirectional — accepts inbound connections and sends outboundOutbound only — inbound traffic allowed only as replies to established connections
PlacementAttaches directly to the VPC as a wholeDeployed inside a specific public subnet
IP address handling1:1 NAT between a private IP and an Elastic/public IPMany-to-one PAT — many private IPs share the gateway’s public IP
Which resources use itInstances with a public/Elastic IP routed via a public subnet route tableInstances with only private IPs routed via a private subnet route table
Scaling and availabilityManaged, horizontally scaled, highly available with no bandwidth capBandwidth-bounded per gateway; needs one per AZ for high availability
Cost modelNo hourly charge and no data processing feeHourly charge plus per-GB data processing fee
Failure impactLoss cuts off all direct internet reachability for the public subnetLoss cuts off outbound internet access for the private subnet only

Key Differences

  • Internet Gateway provides bidirectional access; NAT Gateway only permits outbound connections.
  • Internet Gateway attaches to the whole VPC; NAT Gateway lives inside a specific subnet.
  • Internet Gateway does 1:1 Elastic IP mapping; NAT Gateway does many-to-one PAT.
  • NAT Gateway bills per GB processed; Internet Gateway is free.

When to Use Each

Internet Gateway

  • Public-facing web servers: Load balancers or web servers that must accept inbound connections from arbitrary internet clients need an Internet Gateway.
  • Bastion or jump hosts: A host that administrators SSH into from outside the VPC needs direct, inbound-reachable internet access.

NAT Gateway

  • Private backend patching: Database or app servers in a private subnet need outbound access to pull OS updates without ever accepting inbound connections.
  • Protecting backend tiers: Keeping application and database instances without public IPs while still allowing them to call external APIs.
  • Multi-AZ egress resilience: Deploying one NAT Gateway per availability zone avoids a single point of failure and cross-AZ data transfer charges.