skip to content

IPv6 addresses assigned inside an AWS VPC are globally routable. How do you give IPv6 instances outbound internet access while keeping them unreachable from the internet, and why is a NAT gateway not the answer?

level: middleimportance: nice to knowfreq 28%

answer

  1. VPC IPv6 is globally routable
  2. stateful, but no translation
  3. one route, the all-zeros IPv6 prefix
  4. NAT solves a scarcity you no longer have
  5. the exception points the other way

basics

~20 s

Use an egress-only internet gateway and route ::/0 to it from the private subnets. It is stateful, allowing outbound IPv6 and the replies while dropping anything initiated from outside. NAT exists to conserve scarce IPv4 addresses, a problem IPv6 does not have.

solid answer

~50 s

The device is an **egress-only internet gateway**. You attach one to the VPC and point `::/0` at it in the route tables of the subnets that should have outbound-only IPv6. Like a NAT gateway it is stateful — replies to connections started inside come back, unsolicited inbound packets are dropped — but it performs no address translation, because there is no address scarcity to solve. Every instance keeps its own globally unique IPv6 address on the wire. That also makes it cheap: unlike a NAT gateway there is no hourly charge and no per-GB data-processing charge for the gateway itself. The reason a NAT gateway is the wrong tool is that NAT solves an IPv4 problem — many hosts, one public address — so applying it to IPv6 would add cost and state for no benefit. The one place a NAT gateway *does* touch IPv6 is NAT64, translating traffic from IPv6-only subnets toward IPv4-only destinations, which is a different job entirely.

code

bash · 9 lines
bash
EIGW_ID=$(aws ec2 create-egress-only-internet-gateway \
  --vpc-id vpc-0123456789abcdef0 \
  --query 'EgressOnlyInternetGateway.EgressOnlyInternetGatewayId' \
  --output text)

aws ec2 create-route \
  --route-table-id rtb-0123456789abcdef0 \
  --destination-ipv6-cidr-block ::/0 \
  --egress-only-internet-gateway-id "$EIGW_ID"

go deeper

for a junior

Know the name of the device — an egress-only internet gateway — and that IPv6 addresses in a VPC are publicly routable, so outbound-only access has to be arranged deliberately rather than coming from the address type.

for a middle

Explain that the gateway is stateful but performs no translation, that the route is ::/0 to it, and that NAT exists to solve IPv4 scarcity which IPv6 does not have. Know that a dual-stack subnet uses both devices side by side.

for a senior

Show that you treat enabling IPv6 as a security review: every existing rule set written for IPv4 ranges is silent about IPv6, and a dual-stack rollout can quietly open or close paths. Be able to separate NAT64 from the outbound-only question cleanly.

for a principal

Own whether IPv6 is worth adopting at all for the estate — the egress cost it removes, the address-exhaustion pressure it relieves in large VPC footprints, and the governance burden of keeping two address families' policies in step.

## The premise candidates get wrong In a VPC, the IPv6 addresses AWS assigns are from a globally routable range. There is no private-versus-public split the way there is for IPv4 with RFC 1918 space. So an instance with an IPv6 address and a route to an internet gateway is genuinely reachable from the internet — subject to its own firewalling, but reachable at the routing layer, with no address translation standing in between. That changes what "private subnet" means for IPv6. For IPv4 the address itself was part of the protection; for IPv6 the protection has to come from routing and from explicit rules. ## The device: egress-only internet gateway An **egress-only internet gateway** is a VPC-attached, horizontally scaled, highly available component — architecturally much closer to an internet gateway than to a NAT gateway. It differs from the internet gateway in exactly one respect: it is **stateful and one-way**. Connections established from inside the VPC are allowed out and their replies come back; packets from the internet that do not correspond to an existing outbound flow are dropped. You create one per VPC and reference it as a route target for `::/0`: ``` aws ec2 create-egress-only-internet-gateway --vpc-id vpc-0123456789abcdef0 aws ec2 create-route \ --route-table-id rtb-0123456789abcdef0 \ --destination-ipv6-cidr-block ::/0 \ --egress-only-internet-gateway-id eigw-0123456789abcdef0 ``` A subnet can perfectly well have a `0.0.0.0/0` route to a NAT gateway for IPv4 and a `::/0` route to an egress-only internet gateway for IPv6 at the same time — that dual-stack arrangement is the normal shape of a private subnet that speaks both protocols. ## Why not just use NAT Because NAT is a workaround for IPv4 address exhaustion. Its purpose is to let many hosts share one scarce public address, and the outbound-only property everyone values is a *side effect* of the translation state, not its goal. With IPv6 there is no scarcity, so translating would mean paying an hourly charge and a per-GB data-processing charge, adding a stateful translator to the path, and losing per-instance address visibility — all to obtain a property you can have for free. The egress-only internet gateway gives you that property directly. The gateway itself carries no hourly or data-processing charge, so its cost profile is that of the plain internet gateway rather than the NAT gateway. And because there is no translation, logs and remote-side records still show which instance made a call, which is a genuine operational and forensic advantage. ## Where a NAT gateway does meet IPv6: NAT64 One exception is worth knowing. A NAT gateway supports **NAT64**, used with **DNS64** on the Route 53 Resolver, so instances in **IPv6-only** subnets can reach **IPv4-only** destinations. DNS64 synthesises an IPv6 address inside the well-known `64:ff9b::/96` prefix for a name that only has an `A` record, the subnet routes that prefix to the NAT gateway, and the gateway translates the flow onto IPv4 on the far side. Notice this is the opposite problem. It is not "how do I keep IPv6 hosts unreachable" but "how does an IPv6-only host talk to a service that never got an IPv6 address". Muddling the two is the classic confusion here, and a candidate who can separate them cleanly is demonstrating a real grip on dual-stack design. ## What still has to be configured The egress-only internet gateway is a routing device, not a policy device. Instance-level and subnet-level rules still have to permit the IPv6 traffic explicitly — and this is a frequent operational surprise, because rules written years ago for IPv4 ranges say nothing about IPv6, so a newly dual-stacked workload can end up with an unintentionally open or unintentionally closed IPv6 path while the IPv4 path behaves as expected. Adding IPv6 to a VPC is therefore a review of every existing rule set, not just a routing change. ## How to answer Name the device, give the route (`::/0` to the egress-only internet gateway), and explain the *reason* NAT does not belong: IPv6 has no address scarcity, so translation buys nothing and costs money. If you have room, add the NAT64 exception to show you know where the two worlds do meet, and note that the rule sets still need explicit IPv6 entries.

  • What is the practical cost difference between an egress-only internet gateway and a NAT gateway?
    The egress-only internet gateway carries no hourly charge and no per-GB data-processing charge for the gateway itself — you pay only normal data transfer. A NAT gateway charges per hour and per gigabyte processed in both directions. For heavy egress the gap is substantial, which is one of the practical arguments for dual-stacking a workload.
  • Can a subnet use an egress-only internet gateway for IPv6 and a NAT gateway for IPv4 at the same time?
    Yes, and that is the standard dual-stack private subnet. The route table holds a 0.0.0.0/0 entry targeting the NAT gateway and a ::/0 entry targeting the egress-only internet gateway; the two address families are routed independently and never interact.
  • When does a NAT gateway have anything to do with IPv6 at all?
    In NAT64, paired with DNS64 on the Route 53 Resolver, so instances in IPv6-only subnets can reach IPv4-only destinations. DNS64 synthesises an address in the 64:ff9b::/96 prefix, the subnet routes that prefix to the NAT gateway, and the gateway translates onto IPv4. That is a reachability problem, not a privacy one.

saying these in an interview costs you the question

  • Says a NAT gateway is the way to do outbound-only IPv6
  • Assumes VPC IPv6 addresses are private like RFC 1918 space
  • Thinks an egress-only internet gateway performs address translation
  • Believes existing IPv4 firewall rules automatically cover IPv6
  • Confuses NAT64 with keeping IPv6 instances unreachable

context