Overview
Both connect a VPC to the internet, but they serve opposite purposes: an Internet Gateway lets public-facing resources send and receive traffic directly, while a NAT Gateway lets private resources reach out without ever being reachable from outside. Picking the wrong one either exposes resources you meant to keep private or silently blocks the outbound access your servers need.
Comparison Diagram
Comparison Table
| Aspect | Internet Gateway | NAT Gateway |
|---|---|---|
| Primary purpose | Enables communication between a VPC and the internet in both directions | Enables outbound-only internet access for resources without public IPs |
| Traffic direction | Bidirectional — accepts inbound connections and sends outbound | Outbound only — inbound traffic allowed only as replies to established connections |
| Placement | Attaches directly to the VPC as a whole | Deployed inside a specific public subnet |
| IP address handling | 1:1 NAT between a private IP and an Elastic/public IP | Many-to-one PAT — many private IPs share the gateway’s public IP |
| Which resources use it | Instances with a public/Elastic IP routed via a public subnet route table | Instances with only private IPs routed via a private subnet route table |
| Scaling and availability | Managed, horizontally scaled, highly available with no bandwidth cap | Bandwidth-bounded per gateway; needs one per AZ for high availability |
| Cost model | No hourly charge and no data processing fee | Hourly charge plus per-GB data processing fee |
| Failure impact | Loss cuts off all direct internet reachability for the public subnet | Loss cuts off outbound internet access for the private subnet only |
Key Differences
- Internet Gateway provides bidirectional access; NAT Gateway only permits outbound connections.
- Internet Gateway attaches to the whole VPC; NAT Gateway lives inside a specific subnet.
- Internet Gateway does 1:1 Elastic IP mapping; NAT Gateway does many-to-one PAT.
- NAT Gateway bills per GB processed; Internet Gateway is free.
When to Use Each
Internet Gateway
- Public-facing web servers: Load balancers or web servers that must accept inbound connections from arbitrary internet clients need an Internet Gateway.
- Bastion or jump hosts: A host that administrators SSH into from outside the VPC needs direct, inbound-reachable internet access.
NAT Gateway
- Private backend patching: Database or app servers in a private subnet need outbound access to pull OS updates without ever accepting inbound connections.
- Protecting backend tiers: Keeping application and database instances without public IPs while still allowing them to call external APIs.
- Multi-AZ egress resilience: Deploying one NAT Gateway per availability zone avoids a single point of failure and cross-AZ data transfer charges.