<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Vpc on IT Comparison</title><link>https://comparison.metacog.co.kr/tags/vpc/</link><description>Recent content in Vpc on IT Comparison</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 03 Aug 2026 06:27:51 +0900</lastBuildDate><atom:link href="https://comparison.metacog.co.kr/tags/vpc/index.xml" rel="self" type="application/rss+xml"/><item><title>NAT Gateway vs Internet Gateway: Who Gets to Talk to the Internet</title><link>https://comparison.metacog.co.kr/posts/2026-08-03-nat-gateway-vs-internet-gateway-who-gets-to-talk-to-the-inte/</link><pubDate>Mon, 03 Aug 2026 06:27:51 +0900</pubDate><guid>https://comparison.metacog.co.kr/posts/2026-08-03-nat-gateway-vs-internet-gateway-who-gets-to-talk-to-the-inte/</guid><description>&lt;h2 id="overview"&gt;Overview&lt;/h2&gt;
&lt;p&gt;Both connect a VPC to the internet, but they serve opposite purposes: an &lt;strong class="kw"&gt;Internet Gateway&lt;/strong&gt; lets public-facing resources send and receive traffic directly, while a &lt;strong class="kw"&gt;NAT Gateway&lt;/strong&gt; lets private resources reach out without ever being reachable from outside. Picking the wrong one either exposes resources you meant to keep private or silently blocks the outbound access your servers need.&lt;/p&gt;
&lt;h2 id="comparison-diagram"&gt;Comparison Diagram&lt;/h2&gt;
&lt;div class="compare-diagram"&gt;
&lt;svg viewBox="0 0 640 360" xmlns="http://www.w3.org/2000/svg"&gt;&lt;defs&gt;&lt;marker id="arrowA" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 Z" style="fill:var(--compare-a)"/&gt;&lt;/marker&gt;&lt;marker id="arrowB" viewBox="0 0 10 10" refX="5" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"&gt;&lt;path d="M0,0 L10,5 L0,10 Z" style="fill:var(--compare-b)"/&gt;&lt;/marker&gt;&lt;/defs&gt;&lt;line x1="320" y1="20" x2="320" y2="340" style="stroke:var(--border)" stroke-width="1" stroke-dasharray="4 4"/&gt;&lt;text x="160" y="25" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;Internet Gateway&lt;/text&gt;&lt;text x="480" y="25" text-anchor="middle" font-size="16" font-weight="bold" style="fill:var(--primary)"&gt;NAT Gateway&lt;/text&gt;&lt;rect x="110" y="45" width="100" height="36" rx="18" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="160" y="68" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Internet&lt;/text&gt;&lt;rect x="430" y="45" width="100" height="36" rx="18" style="fill:none;stroke:var(--border)" stroke-width="1.5"/&gt;&lt;text x="480" y="68" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Internet&lt;/text&gt;&lt;line x1="160" y1="82" x2="160" y2="109" style="stroke:var(--compare-a)" stroke-width="2" marker-start="url(#arrowA)" marker-end="url(#arrowA)"/&gt;&lt;line x1="480" y1="110" x2="480" y2="82" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;circle cx="560" cy="95" r="10" style="fill:none;stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;line x1="553" y1="88" x2="567" y2="102" style="stroke:var(--secondary)" stroke-width="1.5"/&gt;&lt;text x="560" y="120" text-anchor="middle" font-size="9" style="fill:var(--secondary)"&gt;no inbound&lt;/text&gt;&lt;rect x="110" y="110" width="100" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="134" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;IGW&lt;/text&gt;&lt;rect x="430" y="110" width="100" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="134" text-anchor="middle" font-size="11" style="fill:var(--content)"&gt;NAT Gateway&lt;/text&gt;&lt;line x1="160" y1="150" x2="160" y2="189" style="stroke:var(--compare-a)" stroke-width="2" marker-start="url(#arrowA)" marker-end="url(#arrowA)"/&gt;&lt;line x1="480" y1="190" x2="480" y2="151" style="stroke:var(--compare-b)" stroke-width="2" marker-end="url(#arrowB)"/&gt;&lt;rect x="70" y="190" width="180" height="120" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4 3"/&gt;&lt;text x="160" y="206" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Public Subnet&lt;/text&gt;&lt;rect x="110" y="228" width="100" height="40" rx="6" style="fill:var(--compare-a-soft);stroke:var(--compare-a)" stroke-width="1.5"/&gt;&lt;text x="160" y="252" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Instance&lt;/text&gt;&lt;text x="160" y="285" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;has public IP&lt;/text&gt;&lt;rect x="390" y="190" width="180" height="120" rx="8" style="fill:none;stroke:var(--border)" stroke-width="1.5" stroke-dasharray="4 3"/&gt;&lt;text x="480" y="206" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;Private Subnet&lt;/text&gt;&lt;rect x="430" y="228" width="100" height="40" rx="6" style="fill:var(--compare-b-soft);stroke:var(--compare-b)" stroke-width="1.5"/&gt;&lt;text x="480" y="252" text-anchor="middle" font-size="12" style="fill:var(--content)"&gt;Instance&lt;/text&gt;&lt;text x="480" y="285" text-anchor="middle" font-size="10" style="fill:var(--secondary)"&gt;private IP only&lt;/text&gt;&lt;text x="160" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;bidirectional traffic&lt;/text&gt;&lt;text x="480" y="330" text-anchor="middle" font-size="11" style="fill:var(--secondary)"&gt;outbound only&lt;/text&gt;&lt;/svg&gt;
&lt;/div&gt;
&lt;h2 id="comparison-table"&gt;Comparison Table&lt;/h2&gt;
&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Aspect&lt;/th&gt;
&lt;th&gt;Internet Gateway&lt;/th&gt;
&lt;th&gt;NAT Gateway&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Primary purpose&lt;/td&gt;
&lt;td&gt;Enables communication between a VPC and the internet in both directions&lt;/td&gt;
&lt;td&gt;Enables outbound-only internet access for resources without public IPs&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Traffic direction&lt;/td&gt;
&lt;td&gt;Bidirectional — accepts inbound connections and sends outbound&lt;/td&gt;
&lt;td&gt;Outbound only — inbound traffic allowed only as replies to established connections&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Placement&lt;/td&gt;
&lt;td&gt;Attaches directly to the VPC as a whole&lt;/td&gt;
&lt;td&gt;Deployed inside a specific public subnet&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;IP address handling&lt;/td&gt;
&lt;td&gt;1:1 NAT between a private IP and an Elastic/public IP&lt;/td&gt;
&lt;td&gt;Many-to-one PAT — many private IPs share the gateway&amp;rsquo;s public IP&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Which resources use it&lt;/td&gt;
&lt;td&gt;Instances with a public/Elastic IP routed via a public subnet route table&lt;/td&gt;
&lt;td&gt;Instances with only private IPs routed via a private subnet route table&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Scaling and availability&lt;/td&gt;
&lt;td&gt;Managed, horizontally scaled, highly available with no bandwidth cap&lt;/td&gt;
&lt;td&gt;Bandwidth-bounded per gateway; needs one per AZ for high availability&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Cost model&lt;/td&gt;
&lt;td&gt;No hourly charge and no data processing fee&lt;/td&gt;
&lt;td&gt;Hourly charge plus per-GB data processing fee&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Failure impact&lt;/td&gt;
&lt;td&gt;Loss cuts off all direct internet reachability for the public subnet&lt;/td&gt;
&lt;td&gt;Loss cuts off outbound internet access for the private subnet only&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="key-differences"&gt;Key Differences&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internet Gateway provides &lt;strong class="kw"&gt;bidirectional&lt;/strong&gt; access; NAT Gateway only permits &lt;strong class="kw"&gt;outbound&lt;/strong&gt; connections.&lt;/li&gt;
&lt;li&gt;Internet Gateway attaches to the whole &lt;strong class="kw"&gt;VPC&lt;/strong&gt;; NAT Gateway lives inside a specific &lt;strong class="kw"&gt;subnet&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Internet Gateway does 1:1 &lt;strong class="kw"&gt;Elastic IP&lt;/strong&gt; mapping; NAT Gateway does many-to-one &lt;strong class="kw"&gt;PAT&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;NAT Gateway bills per &lt;strong class="kw"&gt;GB processed&lt;/strong&gt;; Internet Gateway is &lt;strong class="kw"&gt;free&lt;/strong&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="when-to-use-each"&gt;When to Use Each&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Internet Gateway&lt;/strong&gt;&lt;/p&gt;</description></item></channel></rss>