NATGW UMN 20230525 version

Reviewed-by: Hasko, Vladimir <vladimir.hasko@t-systems.com>
Co-authored-by: Qin Ying, Fan <fanqinying@huawei.com>
Co-committed-by: Qin Ying, Fan <fanqinying@huawei.com>
This commit is contained in:
Qin Ying, Fan 2023-08-13 18:20:51 +00:00 committed by zuul
parent 35cd899fe1
commit 139ab2d266
93 changed files with 1509 additions and 506 deletions

File diff suppressed because it is too large Load Diff

File diff suppressed because it is too large Load Diff

Binary file not shown.

After

Width:  |  Height:  |  Size: 24 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1004 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 1004 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 1004 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 2.5 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 1004 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 1004 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 34 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 173 B

Binary file not shown.

After

Width:  |  Height:  |  Size: 33 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 54 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 39 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 43 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 62 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 42 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 37 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 23 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 21 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 20 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 22 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 22 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 29 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 20 KiB

View File

@ -0,0 +1,15 @@
<a name="EN-US_TOPIC_0000001557248825"></a><a name="EN-US_TOPIC_0000001557248825"></a>
<h1 class="topictitle1">Public NAT Gateway Overview</h1>
<div id="body8662426"><p id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_p8060118">A public NAT gateway enables cloud and on-premises servers in a private subnet to access the Internet or provide services accessible from the Internet. Cloud servers are in a VPC. On-premises servers are servers in on-premises data centers that connect to a VPC through Direct Connect or VPN. A public NAT gateway supports up to 20 Gbit/s of bandwidth.</p>
<p id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_p61619562914">The process of using a public NAT gateway is as follows.</p>
<div class="fignone" id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_fig2550154814438"><span class="figcap"><b>Figure 1 </b>Process of using a public NAT gateway</span><br><span><img id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_image1552174814435" src="en-us_image_0260388437.png"></span></div>
<div class="note" id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_note275893214114"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_p7988121918126">An SNAT rule and a DNAT rule cannot share the same <span id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_text85701193310"></span><span id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_text957811103312">EIP</span>. If you need to create an SNAT rule and a DNAT rule, <span id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_ph1542144015280">assign</span> two <span id="EN-US_TOPIC_0000001557248825__en-us_topic_0259136076_ph184125101515">EIPs</span>.</p>
</div></div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="nat_nat_0000.html">Managing NAT Gateways</a></div>
</div>
</div>

View File

@ -1,7 +1,7 @@
<a name="en-us_topic_0086739750"></a><a name="en-us_topic_0086739750"></a>
<h1 class="topictitle1">Notes and Constraints</h1>
<div id="body44798466"><div class="p" id="en-us_topic_0086739750__p51636249">When using a NAT gateway:<ul id="en-us_topic_0086739750__ul19936322151214"><li id="en-us_topic_0086739750__li21523698151214">Multiple rules for one NAT gateway can use the same EIP, but the rules for different NAT gateways must use different EIPs.</li><li id="en-us_topic_0086739750__li59495558151214">Each VPC can only have one NAT gateway.</li><li id="en-us_topic_0086739750__li65697982151214">Manually adding the default route for a VPC is not allowed.</li><li id="en-us_topic_0086739750__li54410930151214">Each VPC subnet can only be used in one SNAT rule.</li><li id="en-us_topic_0086739750__li26824967151221">SNAT and DNAT rules cannot share the same EIP.</li><li id="en-us_topic_0086739750__li3734117115216">DNAT rules do not support the mapping between an EIP and a virtual IP address.</li><li id="en-us_topic_0086739750__li13934170151245">If both an EIP and a NAT gateway are configured for a server, data will be forwarded through the EIP.</li><li id="en-us_topic_0086739750__li72493121160">When you add an SNAT rule, if the rule is used in the VPC scenario, the custom CIDR block must be a subset of the NAT gateway's VPC subnets. If the rule is used in the Direct Connect scenario, the custom CIDR block must be a CIDR block of a Direct Connect connection and cannot overlap with the NAT gateway's VPC subnets.</li><li id="en-us_topic_0086739750__li0411182717138">You can configure only one DNAT rule for each port of a server. One port can be mapped to only one EIP.</li></ul>
<div id="body44798466"><div class="p" id="en-us_topic_0086739750__p51636249">When using a NAT gateway:<ul id="en-us_topic_0086739750__ul19936322151214"><li id="en-us_topic_0086739750__li21523698151214">Multiple rules for one NAT gateway can use the same EIP, but the rules for different NAT gateways must use different EIPs.</li><li id="en-us_topic_0086739750__li59495558151214">Each VPC can only have one NAT gateway.</li><li id="en-us_topic_0086739750__li65697982151214">Manually adding the default route for a VPC is not allowed.</li><li id="en-us_topic_0086739750__li54410930151214">Each VPC subnet can only be used in one SNAT rule.</li><li id="en-us_topic_0086739750__li26824967151221">SNAT and DNAT rules cannot share the same EIP.</li><li id="en-us_topic_0086739750__li3734117115216">DNAT rules do not support the mapping between an EIP and a virtual IP address.</li><li id="en-us_topic_0086739750__li13934170151245">If both an EIP and a NAT gateway are configured for a server, data will be forwarded through the EIP.</li><li id="en-us_topic_0086739750__li72493121160">When you add an SNAT rule, if the rule is used in the VPC scenario, the custom CIDR block must be a subset of the NAT gateway's VPC subnets. If the rule is used in the Direct Connect scenario, the custom CIDR block must be a CIDR block of a Direct Connect connection and cannot overlap with the NAT gateway's VPC subnets.</li><li id="en-us_topic_0086739750__li0411182717138">You can configure only one DNAT rule for each port of a server. One port can be mapped to only one EIP.</li><li id="en-us_topic_0086739750__li119011149194">The DNAT rules of a NAT gateway are irrelevant to the NAT gateway specifications. A maximum of 200 DNAT rules can be added to a NAT gateway. The number of SNAT rules that you can add for a NAT gateway has no relationship with the NAT gateway specifications.</li></ul>
</div>
</div>
<div>

View File

@ -1,13 +1,10 @@
<a name="en-us_topic_0086739762"></a><a name="en-us_topic_0086739762"></a>
<h1 class="topictitle1">What Is NAT Gateway?</h1>
<div id="body48115835"><p id="en-us_topic_0086739762__p65776999">The NAT Gateway service provides network address translation (NAT) with 20 Gbit/s of bandwidth for Elastic Cloud Servers (ECSs) and Bare Metal Servers (BMSs) in a Virtual Private Cloud (VPC), or servers that connect to a VPC through Direct Connect or Virtual Private Network (VPN) in on-premises data centers, allowing these servers to share elastic IP addresses (EIPs) to access the Internet or to provide services accessible from the Internet.</p>
<div id="body48115835"><p id="en-us_topic_0086739762__p65776999">NAT Gateway is a network address translation (NAT) service. It enables cloud and on-premises servers to share elastic IP addresses (EIPs) to access the Internet or to provide services accessible from the Internet. Cloud servers are Elastic Cloud Servers (ECSs) and Bare Metal Servers (BMSs) in a Virtual Private Cloud (VPC). On-premises servers are servers in on-premises data centers that connect to a VPC through Direct Connect or Virtual Private Network (VPN). NAT Gateway supports up to 20 Gbit/s of bandwidth.</p>
<p id="en-us_topic_0086739762__p644338185415">NAT Gateway supports source NAT (SNAT) and destination NAT (DNAT).</p>
<ul id="en-us_topic_0086739762__ul1229332415511"><li id="en-us_topic_0086739762__li1298193215017">SNAT translates private IP addresses into EIPs, allowing servers in a VPC to share an EIP to access the Internet in a secure and efficient way.<div class="p" id="en-us_topic_0086739762__p458793316019"><a name="en-us_topic_0086739762__li1298193215017"></a><a name="li1298193215017"></a><a href="#en-us_topic_0086739762__fig439218341217">Figure 1</a> shows the SNAT architecture.<div class="fignone" id="en-us_topic_0086739762__fig439218341217"><a name="en-us_topic_0086739762__fig439218341217"></a><a name="fig439218341217"></a><span class="figcap"><b>Figure 1 </b>SNAT architecture</span><br><span><img class="vsd" id="en-us_topic_0086739762__image759251514578" src="en-us_image_0201532914.png"></span></div>
</div>
<p id="en-us_topic_0086739762__p925812315216"></p>
</li><li id="en-us_topic_0086739762__li1761018322558">DNAT enables servers in a VPC to share an EIP to provide services accessible from the Internet through IP address mapping or port mapping.<p id="en-us_topic_0086739762__p206751417117"><a name="en-us_topic_0086739762__li1761018322558"></a><a name="li1761018322558"></a><a href="#en-us_topic_0086739762__fig13245644101814">Figure 2</a> shows the DNAT architecture.</p>
<div class="fignone" id="en-us_topic_0086739762__fig13245644101814"><a name="en-us_topic_0086739762__fig13245644101814"></a><a name="fig13245644101814"></a><span class="figcap"><b>Figure 2 </b>DNAT architecture</span><br><span><img class="vsd" id="en-us_topic_0086739762__image634317311714" src="en-us_image_0201532822.png"></span></div>
<ul id="en-us_topic_0086739762__ul1229332415511"><li id="en-us_topic_0086739762__li1298193215017">SNAT translates private IP addresses into EIPs, allowing servers in a VPC to share an EIP to access the Internet in a secure and efficient way.<div class="fignone" id="en-us_topic_0086739762__fig134081312124818"><span class="figcap"><b>Figure 1 </b>NAT gateway with an SNAT rule</span><br><span><img id="en-us_topic_0086739762__image1040801294816" src="en-us_image_0000001251223489.png"></span></div>
</li><li id="en-us_topic_0086739762__li1761018322558">DNAT enables servers in a VPC to share an EIP to provide services accessible from the Internet through IP address mapping or port mapping.<div class="fignone" id="en-us_topic_0086739762__fig1134494812133"><span class="figcap"><b>Figure 2 </b>NAT gateway with a DNAT rule</span><br><span><img id="en-us_topic_0086739762__image1634404811131" src="en-us_image_0000001206143558.png"></span></div>
</li></ul>
</div>
<div>

View File

@ -1,11 +1,11 @@
<a name="en-us_topic_0086739763"></a><a name="en-us_topic_0086739763"></a>
<h1 class="topictitle1">NAT Gateway Types</h1>
<div id="body53775824"><p id="en-us_topic_0086739763__p1863217173361">A NAT gateway type specifies the maximum number of SNAT connections supported by a NAT gateway.</p>
<p id="en-us_topic_0086739763__p8060118">An SNAT connection consists of the source IP address, source port, destination IP address, destination port, and transmission-layer protocol. The source IP address refers to the EIP, and the source port refers to the EIP port. They will be used to access the destination IP address and port of the Internet. These five elements identify a connection as a unique session.</p>
<h1 class="topictitle1">NAT Gateway Specifications</h1>
<div id="body53775824"><p id="en-us_topic_0086739763__p1863217173361">NAT gateway specifications determines the maximum number of SNAT connections supported by a NAT gateway.</p>
<p id="en-us_topic_0086739763__p8060118">An SNAT connection consists of the source IP address, source port, destination IP address, destination port, and a transport layer protocol. The source IP address is the EIP, and the source port is the EIP port. An SNAT connection uniquely identifies a session.</p>
<p id="en-us_topic_0086739763__p3355543392418">The data throughput of a NAT gateway is determined by the sum of the EIP bandwidths used by its DNAT rules. For example, if a NAT gateway has two DNAT rules, and their EIP bandwidths are 10 Mbit/s and 5 Mbit/s, respectively, the throughput of the NAT gateway is 15 Mbit/s.</p>
<div class="p" id="en-us_topic_0086739763__p289201164020">When creating a NAT gateway, select the type based on your service requirements. <a href="#en-us_topic_0086739763__table39923257151849">Table 1</a> lists the NAT gateway types.
<div class="tablenoborder"><a name="en-us_topic_0086739763__table39923257151849"></a><a name="table39923257151849"></a><table cellpadding="4" cellspacing="0" summary="" id="en-us_topic_0086739763__table39923257151849" frame="border" border="1" rules="all"><caption><b>Table 1 </b>NAT gateway types</caption><thead align="left"><tr id="en-us_topic_0086739763__row26507130151849"><th align="left" class="cellrowborder" valign="top" width="48.96065968046727%" id="mcps1.3.4.2.2.3.1.1"><p id="en-us_topic_0086739763__p10919583151849"><strong id="en-us_topic_0086739763__b49779767">Type</strong></p>
<div class="p" id="en-us_topic_0086739763__p289201164020">When creating a NAT gateway, select the specifications based on your service requirements. <a href="#en-us_topic_0086739763__table39923257151849">Table 1</a> lists the NAT gateway specifications.
<div class="tablenoborder"><a name="en-us_topic_0086739763__table39923257151849"></a><a name="table39923257151849"></a><table cellpadding="4" cellspacing="0" summary="" id="en-us_topic_0086739763__table39923257151849" frame="border" border="1" rules="all"><caption><b>Table 1 </b>NAT gateway specifications</caption><thead align="left"><tr id="en-us_topic_0086739763__row26507130151849"><th align="left" class="cellrowborder" valign="top" width="48.96065968046727%" id="mcps1.3.4.2.2.3.1.1"><p id="en-us_topic_0086739763__p10919583151849"><strong id="en-us_topic_0086739763__b49779767">Specifications</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="51.03934031953272%" id="mcps1.3.4.2.2.3.1.2"><p id="en-us_topic_0086739763__p38230083151849"><strong id="en-us_topic_0086739763__b842352706135953">Maximum Number of SNAT Connections</strong></p>
</th>
@ -35,7 +35,7 @@
</table>
</div>
</div>
<div class="note" id="en-us_topic_0086739763__note7817161164315"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><ul id="en-us_topic_0086739763__ul582319291915"><li id="en-us_topic_0086739763__li3823142121917">If the requests exceed the maximum connections allowed by your NAT gateway, your services will be adversely affected. To avoid this situation, create alarm rules for the SNAT connection in Cloud Eye.</li><li id="en-us_topic_0086739763__li119011149194">A maximum of 200 DNAT rules can be added for each NAT gateway. The number of DNAT rules that you can add for a NAT gateway has no relationship with the NAT gateway type. The number of SNAT rules that you can add for a NAT gateway has no relationship with the NAT gateway type.</li></ul>
<div class="note" id="en-us_topic_0086739763__note7817161164315"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><ul id="en-us_topic_0086739763__ul582319291915"><li id="en-us_topic_0086739763__li3823142121917">If the requests exceed the maximum connections allowed by your NAT gateway, your services will be adversely affected. To avoid this situation, create alarm rules for the SNAT connection in Cloud Eye.</li><li id="en-us_topic_0086739763__li119011149194">The DNAT rules of a NAT gateway are irrelevant to the NAT gateway specifications. A maximum of 200 DNAT rules can be added to a NAT gateway. The number of SNAT rules that you can add for a NAT gateway has no relationship with the NAT gateway specifications.</li></ul>
</div></div>
</div>
<div>

View File

@ -1,7 +1,7 @@
<a name="en-us_topic_0087895790"></a><a name="en-us_topic_0087895790"></a>
<h1 class="topictitle1"><strong id="b267001633517">Overview</strong></h1>
<div id="body1534986796066"><p id="en-us_topic_0087895790__p10902119154811">If servers (ECSs and BMSs) without EIPs bound need to access the Internet, the servers can share one or more EIPs to access the Internet through a NAT gateway. This method provides access without exposing their IP addresses. <a href="#en-us_topic_0087895790__fig3421331131416">Figure 1</a> illustrates the process.</p>
<div id="body1534986796066"><p id="en-us_topic_0087895790__p10902119154811">If servers (<span id="en-us_topic_0087895790__text2205923172514">ECS</span>s and <span id="en-us_topic_0087895790__text144931944162519">BMS</span>s) without EIPs bound need to access the Internet, the servers can share one or more EIPs to access the Internet through a NAT gateway. This method provides access without exposing their IP addresses. <a href="#en-us_topic_0087895790__fig3421331131416">Figure 1</a> illustrates the process.</p>
<div class="fignone" id="en-us_topic_0087895790__fig3421331131416"><a name="en-us_topic_0087895790__fig3421331131416"></a><a name="fig3421331131416"></a><span class="figcap"><b>Figure 1 </b>Flowchart</span><br><span><img class="vsd" id="en-us_topic_0087895790__image442123112143" src="en-us_image_0201532815.png"></span></div>
</div>
<div>

View File

@ -3,8 +3,8 @@
<h1 class="topictitle1">Creating Alarm Rules</h1>
<div id="body1527071529095"><div class="section" id="en-us_topic_0113772081__section38299792222911"><h4 class="sectiontitle">Scenarios</h4><p id="en-us_topic_0113772081__p40311482223529">You can set NAT gateway alarm rules to customize the monitored objects and notification policies. Then, you can learn NAT gateway running status in a timely manner. </p>
</div>
<div class="section" id="en-us_topic_0113772081__section7969360222918"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0113772081__ol4340316622382"><li id="en-us_topic_0113772081__li93918114239">Log in to the management console.</li><li id="en-us_topic_0113772081__li840318282158">Click <span><img id="en-us_topic_0113772081__en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0113772081__li2599558622382">Under <strong id="en-us_topic_0113772081__b58911511711">Management &amp; Deployment</strong>, select <strong id="en-us_topic_0113772081__b898215251712">Cloud Eye</strong>.</li><li id="en-us_topic_0113772081__li13187821225633">In the left navigation pane, choose <strong id="en-us_topic_0113772081__b9948171393614">Alarm Management</strong> &gt; <strong id="en-us_topic_0113772081__b894811132362">Alarm Rules</strong>.</li><li id="en-us_topic_0113772081__li32623014182110">On the <strong id="en-us_topic_0113772081__b842352706163218">Alarm Rules</strong> page, click <strong id="en-us_topic_0113772081__b842352706163235">Create Alarm Rule</strong> and specify required parameters.</li><li id="en-us_topic_0113772081__li3591727112520">Click <strong id="en-us_topic_0113772081__b842352706104736">Next</strong> and specify rule parameters as prompted.</li><li id="en-us_topic_0113772081__li1189243473116">Click <strong id="en-us_topic_0113772081__b11691135671712">Finish</strong>. After the alarm rule is set, the system automatically notifies you when an alarm is triggered.</li></ol>
<div class="note" id="en-us_topic_0113772081__note1389233473114"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0113772081__p11892163463116">For more information about how to set alarm rules, see <em id="en-us_topic_0113772081__i842352697151939">Cloud Eye User Guide</em>.</p>
<div class="section" id="en-us_topic_0113772081__section7969360222918"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0113772081__ol4340316622382"><li id="en-us_topic_0113772081__li93918114239">Log in to the management console.</li><li id="en-us_topic_0113772081__li840318282158">Click <span><img id="en-us_topic_0113772081__en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0113772081__li2599558622382">Under <strong id="en-us_topic_0113772081__b3739115018443">Management &amp; Deployment</strong>, select <strong id="en-us_topic_0113772081__b898215251712">Cloud Eye</strong>.</li><li id="en-us_topic_0113772081__li13187821225633">In the left navigation pane, choose <strong id="en-us_topic_0113772081__b9948171393614">Alarm Management</strong> &gt; <strong id="en-us_topic_0113772081__b894811132362">Alarm Rules</strong>.</li><li id="en-us_topic_0113772081__li32623014182110">On the <strong id="en-us_topic_0113772081__b842352706163218">Alarm Rules</strong> page, click <strong id="en-us_topic_0113772081__b842352706163235">Create Alarm Rule</strong> and specify required parameters.</li><li id="en-us_topic_0113772081__li3591727112520">Click <strong id="en-us_topic_0113772081__b842352706104736">Next</strong> and specify rule parameters as prompted.</li><li id="en-us_topic_0113772081__li1189243473116">Click <strong id="en-us_topic_0113772081__b11691135671712">Finish</strong>. After the alarm rule is set, the system automatically notifies you when an alarm is triggered.</li></ol>
<div class="note" id="en-us_topic_0113772081__note1389233473114"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="en-us_topic_0113772081__p11892163463116">For more information about how to set alarm rules, see the <a href="https://docs.otc.t-systems.com/cloud-eye/umn/" target="_blank" rel="noopener noreferrer"><em id="en-us_topic_0113772081__i88441531145019">Cloud Eye User Guide</em></a>.</p>
</div></div>
</div>
</div>

View File

@ -1,13 +1,13 @@
<a name="en-us_topic_0127489529"></a><a name="en-us_topic_0127489529"></a>
<h1 class="topictitle1">Adding an SNAT Rule</h1>
<div id="body8662426"><div class="section" id="en-us_topic_0127489529__en-us_topic_0127293981_section18103401105119"><h4 class="sectiontitle">Scenarios</h4><p id="en-us_topic_0127489529__en-us_topic_0127293981_p45075714105130">After a NAT gateway is created, add SNAT rules. With the SNAT rule, servers in a VPC subnet or servers that are connected to a VPC through Direct Connect or VPN can access the Internet by sharing an <span id="en-us_topic_0127489529__text19978444133619">EIP</span><span id="en-us_topic_0127489529__text169781344143611"></span>.</p>
<p id="en-us_topic_0127489529__en-us_topic_0127293981_p16973952192016">Each SNAT rule is configured for one subnet. If there are multiple subnets in a VPC, you can create several SNAT rules to share EIPs.</p>
<div id="body8662426"><div class="section" id="en-us_topic_0127489529__en-us_topic_0127293981_section18103401105119"><h4 class="sectiontitle">Scenarios</h4><p id="en-us_topic_0127489529__en-us_topic_0127293981_p45075714105130">After a NAT gateway is created, add SNAT rules. With the SNAT rule, servers in a VPC subnet or servers that are connected to a VPC through Direct Connect or VPN can access the Internet by sharing an <span id="en-us_topic_0127489529__text19978444133619"></span><span id="en-us_topic_0127489529__text169781344143611">EIP</span>.</p>
<p id="en-us_topic_0127489529__en-us_topic_0127293981_p16973952192016">Each SNAT rule is configured for one subnet. If there are subnets in a VPC, you can create several SNAT rules to share EIPs.</p>
</div>
<div class="section" id="en-us_topic_0127489529__en-us_topic_0127293981_section27241609"><h4 class="sectiontitle"><strong id="en-us_topic_0127489529__b14876208462">Prerequisites</strong></h4><ul id="en-us_topic_0127489529__ul1732114535152"><li id="en-us_topic_0127489529__li1132135317151">A NAT gateway has been created.</li></ul>
<div class="section" id="en-us_topic_0127489529__en-us_topic_0127293981_section27241609"><h4 class="sectiontitle">Prerequisites</h4><ul id="en-us_topic_0127489529__ul1732114535152"><li id="en-us_topic_0127489529__li1132135317151">A NAT gateway has been created.</li></ul>
</div>
<div class="section" id="en-us_topic_0127489529__en-us_topic_0127293981_section43847892"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0127489529__en-us_topic_0127293981_ol5426870018482"><li id="en-us_topic_0127489529__en-us_topic_0127293981_li25980584101236">Log in to the management console.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li840318282158">Click <span><img id="en-us_topic_0127489529__en-us_topic_0127293981_en-us_topic_0118498823_image338921514480" src="en-us_image_0201532864.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li1049617094325">Under <strong id="en-us_topic_0127489529__b384155103713">Network</strong>, choose <strong id="en-us_topic_0127489529__b1845512371">NAT Gateway</strong>.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li8610102724918">On the displayed page, click the name of the NAT gateway for which you want to add the SNAT rule.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li7563844165416">On the <strong id="en-us_topic_0127489529__b109893106452">SNAT Rules</strong> tab, click <strong id="en-us_topic_0127489529__b799021024511">Add SNAT Rule</strong>.<p id="en-us_topic_0127489529__p163554331436"></p>
<div class="fignone" id="en-us_topic_0127489529__fig7424951145214"><span class="figcap"><b>Figure 1 </b>Add SNAT Rule</span><br><span><img id="en-us_topic_0127489529__nat_qs_0004_image10874193014462" src="en-us_image_0201532851.png"></span></div>
<div class="section" id="en-us_topic_0127489529__en-us_topic_0127293981_section43847892"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0127489529__en-us_topic_0127293981_ol5426870018482"><li id="en-us_topic_0127489529__en-us_topic_0127293981_li25980584101236">Log in to the management console.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li840318282158">Click <span><img id="en-us_topic_0127489529__en-us_topic_0127293981_en-us_topic_0118498823_image338921514480" src="en-us_image_0201532864.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li1049617094325">Under <strong id="en-us_topic_0127489529__b384155103713">Network</strong>, select <strong id="en-us_topic_0127489529__b1845512371">NAT Gateway</strong>.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li8610102724918">On the displayed page, click the name of the NAT gateway for which you want to add the SNAT rule.</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li7563844165416">On the <strong id="en-us_topic_0127489529__b109893106452">SNAT Rules</strong> tab, click <strong id="en-us_topic_0127489529__b799021024511">Add SNAT Rule</strong>.<p id="en-us_topic_0127489529__p163554331436"></p>
<div class="fignone" id="en-us_topic_0127489529__fig7424951145214"><span class="figcap"><b>Figure 1 </b>Add SNAT Rule</span><br><span><img id="en-us_topic_0127489529__nat_qs_0004_image57175541501" src="en-us_image_0000001567533894.png"></span></div>
</li><li id="en-us_topic_0127489529__en-us_topic_0127293981_li704280616453">Configure the parameters as prompted. For details, see <a href="#en-us_topic_0127489529__en-us_topic_0127293981_table4272024117597">Table 1</a>.
<div class="tablenoborder"><a name="en-us_topic_0127489529__en-us_topic_0127293981_table4272024117597"></a><a name="en-us_topic_0127293981_table4272024117597"></a><table cellpadding="4" cellspacing="0" summary="" id="en-us_topic_0127489529__en-us_topic_0127293981_table4272024117597" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameter descriptions</caption><thead align="left"><tr id="en-us_topic_0127489529__en-us_topic_0127293981_row3248015417597"><th align="left" class="cellrowborder" valign="top" width="18.01%" id="mcps1.3.3.2.6.2.2.4.1.1"><p id="en-us_topic_0127489529__en-us_topic_0127293981_p1364683317597"><strong id="en-us_topic_0127489529__b537195719457">Parameter</strong></p>
</th>
@ -26,28 +26,27 @@
<p id="en-us_topic_0127489529__p21892752716">Select <strong id="en-us_topic_0127489529__b1473363111231">Direct Connect</strong> if the servers that are connected to a VPC through Direct Connect in your data center need to access the Internet.</p>
</td>
</tr>
<tr id="en-us_topic_0127489529__en-us_topic_0127293981_row5681056546"><td class="cellrowborder" valign="top" width="18.01%" headers="mcps1.3.3.2.6.2.2.4.1.1 "><p id="en-us_topic_0127489529__en-us_topic_0127293981_p26815562411">Type</p>
<tr id="en-us_topic_0127489529__row156086508277"><td class="cellrowborder" valign="top" width="18.01%" headers="mcps1.3.3.2.6.2.2.4.1.1 "><p id="en-us_topic_0127489529__p13308273285">CIDR Block</p>
</td>
<td class="cellrowborder" valign="top" width="30.91%" headers="mcps1.3.3.2.6.2.2.4.1.2 "><p id="en-us_topic_0127489529__p10582494228">This parameter is available only when you select <strong id="en-us_topic_0127489529__b1814518360">VPC</strong> for <strong id="en-us_topic_0127489529__b1112543615">Scenario</strong>.</p>
<td class="cellrowborder" valign="top" width="30.91%" headers="mcps1.3.3.2.6.2.2.4.1.2 "><ul id="en-us_topic_0127489529__ul143052712818"><li id="en-us_topic_0127489529__li163012711284">Configure this parameter when you select <strong id="en-us_topic_0127489529__b262256114314">VPC</strong> for <strong id="en-us_topic_0127489529__b363155610437">Scenario</strong> and <strong id="en-us_topic_0127489529__b2631356194315">Custom</strong> for <strong id="en-us_topic_0127489529__b1563195644315">CIDR Block</strong>.</li><li id="en-us_topic_0127489529__li887114315444">This parameter is available only when you select <strong id="en-us_topic_0127489529__b9391774427">VPC</strong> for <strong id="en-us_topic_0127489529__b143921973420">Scenario</strong> and <strong id="en-us_topic_0127489529__b83938794217">Custom</strong> for <strong id="en-us_topic_0127489529__b13393117114214">CIDR Block</strong>.</li><li id="en-us_topic_0127489529__li05711322103615">Configure this parameter when you select <strong id="en-us_topic_0127489529__b39417133127">VPC</strong> for <strong id="en-us_topic_0127489529__b1794116130120">Scenario</strong>.</li></ul>
</td>
<td class="cellrowborder" valign="top" width="51.080000000000005%" headers="mcps1.3.3.2.6.2.2.4.1.3 "><p id="en-us_topic_0127489529__en-us_topic_0127293981_p206811656248">You can set it to <strong id="en-us_topic_0127489529__b1557628124418">Subnet</strong> or <strong id="en-us_topic_0127489529__b357152824410">Custom</strong> based on service requirements.</p>
<p id="en-us_topic_0127489529__p12207182812381">Select <strong id="en-us_topic_0127489529__b1646181161514">Subnet</strong> if all servers in a VPC subnet need to access the Internet through the SNAT rule.</p>
<p id="en-us_topic_0127489529__p18916248300">Select <strong id="en-us_topic_0127489529__b1320241441519">Custom</strong> if only specific servers in a VPC subnet need to access the Internet through the SNAT rule.</p>
<td class="cellrowborder" valign="top" width="51.080000000000005%" headers="mcps1.3.3.2.6.2.2.4.1.3 "><ul id="en-us_topic_0127489529__ul105801851125014"><li id="en-us_topic_0127489529__li8580651145013">In a VPC scenario with <strong id="en-us_topic_0127489529__b87442685012">CIDR Block</strong> as <strong id="en-us_topic_0127489529__b775122618503">Custom</strong>, specify an IPv4 CIDR block, which must be a subset of the VPC subnets.</li><li id="en-us_topic_0127489529__li18581125175017">In a VPC scenario with <strong id="en-us_topic_0127489529__b13165253253">CIDR Block</strong> as <strong id="en-us_topic_0127489529__b161662533517">Existing</strong>, specify a VPC subnet in which servers can access the Internet through the SNAT rule.</li><li id="en-us_topic_0127489529__li1058112513501">In a Direct Connect scenario, specify a CIDR block of your data center to enable your on-premises servers to access the Internet through the SNAT rule.</li></ul>
</td>
</tr>
<tr id="en-us_topic_0127489529__en-us_topic_0127293981_row3209331417597"><td class="cellrowborder" valign="top" width="18.01%" headers="mcps1.3.3.2.6.2.2.4.1.1 "><p id="en-us_topic_0127489529__en-us_topic_0127293981_p4942162717597">Subnet</p>
<tr id="en-us_topic_0127489529__en-us_topic_0127293981_row5801532217597"><td class="cellrowborder" valign="top" width="18.01%" headers="mcps1.3.3.2.6.2.2.4.1.1 "><p id="en-us_topic_0127489529__p02871145345"><span id="en-us_topic_0127489529__text437564583717"></span><span id="en-us_topic_0127489529__text1537514450373">EIP</span></p>
</td>
<td class="cellrowborder" valign="top" width="30.91%" headers="mcps1.3.3.2.6.2.2.4.1.2 "><p id="en-us_topic_0127489529__p360149192215">This parameter is available only when you select <strong id="en-us_topic_0127489529__b18244173914362">VPC</strong> for <strong id="en-us_topic_0127489529__b32491839123612">Scenario</strong>, and <strong id="en-us_topic_0127489529__b1249143919363">Subnet</strong> for <strong id="en-us_topic_0127489529__b1524914391368">Type</strong>.</p>
</td>
<td class="cellrowborder" valign="top" width="51.080000000000005%" headers="mcps1.3.3.2.6.2.2.4.1.3 "><p id="en-us_topic_0127489529__en-us_topic_0127293981_p4372884917597">The subnet in which servers can access the Internet through the SNAT rule.</p>
</td>
</tr>
<tr id="en-us_topic_0127489529__en-us_topic_0127293981_row5801532217597"><td class="cellrowborder" valign="top" width="18.01%" headers="mcps1.3.3.2.6.2.2.4.1.1 "><p id="en-us_topic_0127489529__p02871145345"><span id="en-us_topic_0127489529__text437564583717">EIP</span><span id="en-us_topic_0127489529__text1537514450373"></span></p>
</td>
<td class="cellrowborder" valign="top" width="30.91%" headers="mcps1.3.3.2.6.2.2.4.1.2 "><ul id="en-us_topic_0127489529__ul12621049122212"><li id="en-us_topic_0127489529__li2063949162213">This parameter is available only when you select <strong id="en-us_topic_0127489529__b1365915811132">VPC</strong> for <strong id="en-us_topic_0127489529__b186641583133">Scenario</strong>.</li><li id="en-us_topic_0127489529__li7641749172213">This parameter is available only when you select <strong id="en-us_topic_0127489529__b5506601411">Direct Connect</strong> for <strong id="en-us_topic_0127489529__b185066161415">Scenario</strong>.</li></ul>
<td class="cellrowborder" valign="top" width="30.91%" headers="mcps1.3.3.2.6.2.2.4.1.2 "><p id="en-us_topic_0127489529__p155981522172412">N/A</p>
</td>
<td class="cellrowborder" valign="top" width="51.080000000000005%" headers="mcps1.3.3.2.6.2.2.4.1.3 "><p id="en-us_topic_0127489529__en-us_topic_0127293981_p94462428451">The EIP used for accessing the Internet.</p>
<p id="en-us_topic_0127489529__en-us_topic_0127293981_p578114194614">You can select an EIP that either is not bound to any resource, has been bound to a DNAT rule with <strong id="en-us_topic_0127489529__b187051038301">Port Type</strong> set to <strong id="en-us_topic_0127489529__b1870518381020">Specific port</strong> of the current NAT gateway, or has been bound to an SNAT rule of the current NAT gateway.</p>
<p id="en-us_topic_0127489529__p1270810226152">You can select multiple EIPs at once. Up to 20 EIPs can be selected for each SNAT rule. The EIP used for the SNAT rule is randomly chosen from the ones you select when you add the rule.</p>
</td>
</tr>
<tr id="en-us_topic_0127489529__row153111641748"><td class="cellrowborder" valign="top" width="18.01%" headers="mcps1.3.3.2.6.2.2.4.1.1 "><p id="en-us_topic_0127489529__p5274235692544">Description</p>
</td>
<td class="cellrowborder" valign="top" width="30.91%" headers="mcps1.3.3.2.6.2.2.4.1.2 "><p id="en-us_topic_0127489529__p164312400527">N/A</p>
</td>
<td class="cellrowborder" valign="top" width="51.080000000000005%" headers="mcps1.3.3.2.6.2.2.4.1.3 "><p id="en-us_topic_0127489529__p4427248192544">Supplementary information about the NAT gateway. The description can contain up to 255 characters.</p>
</td>
</tr>
</tbody>

View File

@ -8,7 +8,7 @@
</div>
<div class="section" id="en-us_topic_0127489530__en-us_topic_0127293986_section61166376152513"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0127489530__en-us_topic_0127293986_ol59255157152617"><li id="en-us_topic_0127489530__en-us_topic_0127293986_li63534365152617">Log in to the management console.</li><li id="en-us_topic_0127489530__en-us_topic_0127293986_li840318282158">Click <span><img id="en-us_topic_0127489530__en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0127489530__en-us_topic_0127293986_li1049617094325">Under <strong id="en-us_topic_0127489530__b147154310545">Network</strong>, choose <strong id="en-us_topic_0127489530__b194711843175412">NAT Gateway</strong>.</li><li id="en-us_topic_0127489530__en-us_topic_0127293986_li8610102724918">On the displayed page, click the name of the NAT gateway for which you want to add the DNAT rule.</li><li id="en-us_topic_0127489530__en-us_topic_0127293986_li188821748185212">On the NAT gateway details page, click the <strong id="en-us_topic_0127489530__b124202481546">DNAT Rules</strong> tab.</li><li id="en-us_topic_0127489530__en-us_topic_0127293986_li7563844165416">Click <strong id="en-us_topic_0127489530__b18950165119541">Add DNAT Rule</strong>.<div class="notice" id="en-us_topic_0127489530__note8499857814"><span class="noticetitle"><img src="public_sys-resources/notice_3.0-en-us.png"> </span><div class="noticebody"><p id="en-us_topic_0127489530__p7499175712111">Add security group rules to allow inbound or outbound traffic after you add a DNAT rule. Otherwise, the DNAT rule does not take effect.</p>
</div></div>
<div class="fignone" id="en-us_topic_0127489530__fig34824518713"><span class="figcap"><b>Figure 1 </b>Add DNAT Rule</span><br><span><img id="en-us_topic_0127489530__nat_qs_0010_image15489314494" src="en-us_image_0201532842.png"></span></div>
<div class="fignone" id="en-us_topic_0127489530__fig34824518713"><span class="figcap"><b>Figure 1 </b>Add DNAT Rule</span><br><span><img id="en-us_topic_0127489530__nat_qs_0010_image173284386186" src="en-us_image_0000001576425382.png"></span></div>
<p id="en-us_topic_0127489530__en-us_topic_0127293986_p575717274335"></p>
</li><li id="en-us_topic_0127489530__en-us_topic_0127293986_li54168351144127">Configure the parameters as prompted. For details, see <a href="#en-us_topic_0127489530__en-us_topic_0127293986_table30787259144637">Table 1</a>.
<div class="tablenoborder"><a name="en-us_topic_0127489530__en-us_topic_0127293986_table30787259144637"></a><a name="en-us_topic_0127293986_table30787259144637"></a><table cellpadding="4" cellspacing="0" summary="" id="en-us_topic_0127489530__en-us_topic_0127293986_table30787259144637" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameter descriptions</caption><thead align="left"><tr id="en-us_topic_0127489530__en-us_topic_0127293986_row1287982144637"><th align="left" class="cellrowborder" valign="top" width="23.189999999999998%" id="mcps1.3.3.2.7.2.2.3.1.1"><p id="en-us_topic_0127489530__en-us_topic_0127293986_p66523784144637"><strong id="en-us_topic_0127489530__b9146819105510">Parameter</strong></p>
@ -34,7 +34,7 @@
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__en-us_topic_0127293986_p1747101415356">The protocol can be TCP or UDP. This parameter is available if you select <strong id="en-us_topic_0127489530__b07761805311">Specific port</strong> for <strong id="en-us_topic_0127489530__b1977161845317">Port Type</strong>. If you select <strong id="en-us_topic_0127489530__b97701885316">All ports</strong>, the value of this parameter will be <strong id="en-us_topic_0127489530__b1578181805311">All</strong> by default.</p>
</td>
</tr>
<tr id="en-us_topic_0127489530__en-us_topic_0127293986_row43238809144637"><td class="cellrowborder" valign="top" width="23.189999999999998%" headers="mcps1.3.3.2.7.2.2.3.1.1 "><p id="en-us_topic_0127489530__en-us_topic_0127293986_p1901342115116"><span id="en-us_topic_0127489530__text437564583717">EIP</span><span id="en-us_topic_0127489530__text1537514450373"></span></p>
<tr id="en-us_topic_0127489530__en-us_topic_0127293986_row43238809144637"><td class="cellrowborder" valign="top" width="23.189999999999998%" headers="mcps1.3.3.2.7.2.2.3.1.1 "><p id="en-us_topic_0127489530__en-us_topic_0127293986_p1901342115116"><span id="en-us_topic_0127489530__text437564583717"></span><span id="en-us_topic_0127489530__text1537514450373">EIP</span></p>
</td>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__en-us_topic_0127293986_p480029104814">The EIP that will be used by the server to provide services accessible from the Internet.</p>
<p id="en-us_topic_0127489530__en-us_topic_0127293981_p578114194614">You can select an EIP that either is not bound to any resource, has been bound to a DNAT rule with <strong id="en-us_topic_0127489530__b1453623719512">Port Type</strong> set to <strong id="en-us_topic_0127489530__b1454183712517">Specific port</strong> of the current NAT gateway, or has been bound to an SNAT rule of the current NAT gateway.</p>
@ -42,7 +42,7 @@
</tr>
<tr id="en-us_topic_0127489530__en-us_topic_0127293986_row189841183384"><td class="cellrowborder" valign="top" width="23.189999999999998%" headers="mcps1.3.3.2.7.2.2.3.1.1 "><p id="en-us_topic_0127489530__en-us_topic_0127293986_p89861618173810">Outside Port</p>
</td>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__p18986618153813">The port of the EIP. This parameter is available if you select <strong id="en-us_topic_0127489530__b10538124224010">Specific port</strong> for <strong id="en-us_topic_0127489530__b553911429409">Port Type</strong>. Value range: 165535</p>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__p18986618153813">The port of the EIP. This parameter is available if you select <strong id="en-us_topic_0127489530__b591652715111">Specific port</strong> for <strong id="en-us_topic_0127489530__b15924727195111">Port Type</strong>. The value ranges from 1 to 65535.</p>
<p id="en-us_topic_0127489530__p1213391252">You can enter a single port number, for example, 80.</p>
</td>
</tr>
@ -51,12 +51,28 @@
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><ul id="en-us_topic_0127489530__ul6112191010186"><li id="en-us_topic_0127489530__li17112210191812">In a VPC scenario, set this parameter to the IP address of the server in a VPC. This IP address is used by the server to provide services accessible from the Internet through DNAT.</li><li id="en-us_topic_0127489530__li147761202515">In a Direct Connect scenario, set this parameter to the IP address of the server in the local data center or the user's private IP address. This IP address is used by local servers that are connected to a VPC through Direct Connect or VPN to provide services accessible from the Internet through DNAT.</li><li id="en-us_topic_0127489530__li56365613251">Configure the port of <strong id="en-us_topic_0127489530__b842352706174822">Private IP Address</strong> if you select <strong id="en-us_topic_0127489530__b2915537113914">Specific port</strong> for <strong id="en-us_topic_0127489530__b119151372397">Port Type</strong>.</li></ul>
</td>
</tr>
<tr id="en-us_topic_0127489530__row1878615015218"><td class="cellrowborder" valign="top" width="23.189999999999998%" headers="mcps1.3.3.2.7.2.2.3.1.1 "><p id="en-us_topic_0127489530__p57875013218">Instance Type</p>
</td>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__p79556174353">The type of the instance that will be providing services accessible from on-premises data centers or remote VPCs. Possible values are:</p>
<ul id="en-us_topic_0127489530__ul595515177355"><li id="en-us_topic_0127489530__li1195581793510"><strong id="en-us_topic_0127489530__b196606372634631">Server</strong></li><li id="en-us_topic_0127489530__li1495512177350"><strong id="en-us_topic_0127489530__b148505906934633">Virtual IP address</strong></li><li id="en-us_topic_0127489530__li6558685388"><strong id="en-us_topic_0127489530__b28844087634634">Custom</strong></li></ul>
</td>
</tr>
<tr id="en-us_topic_0127489530__row1799423939"><td class="cellrowborder" valign="top" width="23.189999999999998%" headers="mcps1.3.3.2.7.2.2.3.1.1 "><p id="en-us_topic_0127489530__p999182312310">NIC</p>
</td>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__p19569176359">The NIC of the server. This parameter is available when you set <strong id="en-us_topic_0127489530__b157713695434642">Instance Type</strong> to <strong id="en-us_topic_0127489530__b25956050034642">Server</strong>.</p>
</td>
</tr>
<tr id="en-us_topic_0127489530__en-us_topic_0127293986_row1423724123219"><td class="cellrowborder" valign="top" width="23.189999999999998%" headers="mcps1.3.3.2.7.2.2.3.1.1 "><p id="en-us_topic_0127489530__en-us_topic_0127293986_p1323715410320">Inside Port</p>
</td>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__p4994201474513">The port of the server that provides services accessible from the Internet through the DNAT rule. This parameter is available if you select <strong id="en-us_topic_0127489530__b9607165012400">Specific port</strong> for <strong id="en-us_topic_0127489530__b8608135034016">Port Type</strong>. Value range: 165535</p>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__p4994201474513">The port of the server that provides services accessible from the Internet through the DNAT rule. This parameter is available if you select <strong id="en-us_topic_0127489530__b15477113195120">Specific port</strong> for <strong id="en-us_topic_0127489530__b1447863115112">Port Type</strong>. The value ranges from 1 to 65535.</p>
<p id="en-us_topic_0127489530__p22373473214">You can enter a single port number, for example, 80.</p>
</td>
</tr>
<tr id="en-us_topic_0127489530__row1629375132119"><td class="cellrowborder" valign="top" width="23.189999999999998%" headers="mcps1.3.3.2.7.2.2.3.1.1 "><p id="en-us_topic_0127489530__p12211135512110">Description</p>
</td>
<td class="cellrowborder" valign="top" width="76.81%" headers="mcps1.3.3.2.7.2.2.3.1.2 "><p id="en-us_topic_0127489530__p921111551214">Supplementary information about the DNAT rule. The description can contain up to 255 characters.</p>
</td>
</tr>
</tbody>
</table>
</div>

View File

@ -1,31 +1,34 @@
<a name="en-us_topic_0150270259"></a><a name="en-us_topic_0150270259"></a>
<h1 class="topictitle1">Creating a NAT Gateway</h1>
<div id="body8662426"><div class="section" id="en-us_topic_0150270259__nat_qs_0003_section141051954102215"><h4 class="sectiontitle">Scenarios</h4><p id="en-us_topic_0150270259__nat_qs_0003_p10333111152318">This section guides you on how to create a NAT gateway to enable your servers to access the Internet or to provide services available from the Internet.</p>
<h1 class="topictitle1">Creating a Public NAT Gateway</h1>
<div id="body8662426"><div class="section" id="en-us_topic_0150270259__nat_qs_0003_section141051954102215"><h4 class="sectiontitle">Scenarios</h4><p id="en-us_topic_0150270259__nat_qs_0003_p10333111152318">This section guides you on how to create a <span id="en-us_topic_0150270259__nat_qs_0003_ph8941752122618">public NAT gateway</span> to enable your servers to access the Internet or to provide services available from the Internet.</p>
</div>
<div class="section" id="en-us_topic_0150270259__nat_qs_0003_section1825861973713"><h4 class="sectiontitle">Prerequisites</h4><ul id="en-us_topic_0150270259__nat_qs_0003_ul636110619419"><li id="en-us_topic_0150270259__nat_qs_0003_li1254158594232">When creating a NAT gateway, you must specify its VPC, subnet, and type.</li><li id="en-us_topic_0150270259__nat_qs_0003_li5084053611843">Ensure that the VPC does not have the default route. </li></ul>
<div class="section" id="en-us_topic_0150270259__nat_qs_0003_section1825861973713"><h4 class="sectiontitle">Prerequisites</h4><ul id="en-us_topic_0150270259__nat_qs_0003_ul636110619419"><li id="en-us_topic_0150270259__nat_qs_0003_li1254158594232">When creating a public NAT gateway, you must specify its VPC and subnet.</li><li id="en-us_topic_0150270259__nat_qs_0003_li5452164124220">To allow traffic to pass through the public NAT gateway, a route to the public NAT gateway in the VPC is required. When you <span id="en-us_topic_0150270259__nat_qs_0003_ph128345147562">buy</span> a public NAT gateway, a default route 0.0.0.0/0 to the public NAT gateway is automatically added to the default route table of the VPC. If the default route 0.0.0.0/0 already exists in the default route table of the VPC before you <span id="en-us_topic_0150270259__nat_qs_0003_ph864111188566">buy</span> the public NAT gateway, the default route that points to the public NAT gateway will fail to be added automatically. In this case, perform the following operations after the public NAT gateway is successfully created: Manually add a different route that points to the gateway or create a default route 0.0.0.0/0 pointing to the gateway in the new routing table.</li></ul>
</div>
<div class="section" id="en-us_topic_0150270259__nat_qs_0003_section82633199366"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0150270259__nat_qs_0003_ol2070251494311"><li id="en-us_topic_0150270259__nat_qs_0003_li53188416141933">Log in to the management console.</li><li id="en-us_topic_0150270259__nat_qs_0003_li840318282158">Click <span><img id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0150270259__nat_qs_0003_li1049617094325">Under <strong id="en-us_topic_0150270259__nat_qs_0003_b103494306165">Network</strong>, choose <strong id="en-us_topic_0150270259__nat_qs_0003_b3356930191617">NAT Gateway</strong>.</li><li id="en-us_topic_0150270259__nat_qs_0003_li28802123174347">On the displayed page, click <strong id="en-us_topic_0150270259__nat_qs_0003_b38801018792">Create NAT Gateway</strong>.</li><li id="en-us_topic_0150270259__nat_qs_0003_li1053628121954">Configure the parameters as prompted. For details, see <a href="#en-us_topic_0150270259__nat_qs_0003_table27487005195751">Table 1</a>.
<div class="tablenoborder"><a name="en-us_topic_0150270259__nat_qs_0003_table27487005195751"></a><a name="nat_qs_0003_table27487005195751"></a><table cellpadding="4" cellspacing="0" summary="" id="en-us_topic_0150270259__nat_qs_0003_table27487005195751" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameter descriptions</caption><thead align="left"><tr id="en-us_topic_0150270259__nat_qs_0003_row9940336195751"><th align="left" class="cellrowborder" valign="top" width="25%" id="mcps1.3.3.2.5.2.2.3.1.1"><p id="en-us_topic_0150270259__nat_qs_0003_p5995559819588"><strong id="en-us_topic_0150270259__nat_qs_0003_b24725868162658">Parameter</strong></p>
<div class="section" id="en-us_topic_0150270259__nat_qs_0003_section82633199366"><h4 class="sectiontitle">Procedure</h4><ol id="en-us_topic_0150270259__nat_qs_0003_ol2070251494311"><li id="en-us_topic_0150270259__nat_qs_0003_li53188416141933">Log in to the management console.</li><li id="en-us_topic_0150270259__nat_qs_0003_li840318282158">Click <span><img id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0150270259__nat_qs_0003_li1049617094325">Under <strong id="en-us_topic_0150270259__nat_qs_0003_b103494306165">Network</strong>, select <strong id="en-us_topic_0150270259__nat_qs_0003_b3356930191617">NAT Gateway</strong>.</li><li id="en-us_topic_0150270259__nat_qs_0003_li28802123174347">On the displayed page, click <strong id="en-us_topic_0150270259__nat_qs_0003_b84071953191717">Create Public NAT Gateway</strong>.<div class="fignone" id="en-us_topic_0150270259__nat_qs_0003_fig962115511086"><span class="figcap"><b>Figure 1 </b>Create NAT Gateway</span><br><span><img id="en-us_topic_0150270259__nat_qs_0003_image13495511775" src="en-us_image_0000001575387178.png"></span></div>
</li><li id="en-us_topic_0150270259__nat_qs_0003_li1053628121954">Configure the parameters as prompted. For details, see <a href="#en-us_topic_0150270259__nat_qs_0003_table27487005195751">Table 1</a>.
<div class="tablenoborder"><a name="en-us_topic_0150270259__nat_qs_0003_table27487005195751"></a><a name="nat_qs_0003_table27487005195751"></a><table cellpadding="4" cellspacing="0" summary="" id="en-us_topic_0150270259__nat_qs_0003_table27487005195751" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Parameter descriptions of a public NAT gateway</caption><thead align="left"><tr id="en-us_topic_0150270259__nat_qs_0003_row9940336195751"><th align="left" class="cellrowborder" valign="top" width="25%" id="mcps1.3.3.2.5.2.2.3.1.1"><p id="en-us_topic_0150270259__nat_qs_0003_p5995559819588"><strong id="en-us_topic_0150270259__nat_qs_0003_b24725868162658">Parameter</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="75%" id="mcps1.3.3.2.5.2.2.3.1.2"><p id="en-us_topic_0150270259__nat_qs_0003_p2456526519588">Description</p>
</th>
</tr>
</thead>
<tbody><tr id="en-us_topic_0150270259__nat_qs_0003_row11053428162048"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p22912486162048">Region</p>
<tbody><tr id="en-us_topic_0150270259__nat_qs_0003_row6416175117325"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p22912486162048">Region</p>
</td>
<td class="cellrowborder" valign="top" width="75%" headers="mcps1.3.3.2.5.2.2.3.1.2 "><p id="en-us_topic_0150270259__nat_qs_0003_p43972101162048">The region where the NAT gateway is located.</p>
</td>
</tr>
<tr id="en-us_topic_0150270259__nat_qs_0003_row32613315195751"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p2832836319588">Name</p>
</td>
<td class="cellrowborder" valign="top" width="75%" headers="mcps1.3.3.2.5.2.2.3.1.2 "><p id="en-us_topic_0150270259__nat_qs_0003_p1289605119588">The name of the NAT gateway. The name can include up to 64 characters and can include digits, letters, underscores (_), and hyphens (-).</p>
<td class="cellrowborder" valign="top" width="75%" headers="mcps1.3.3.2.5.2.2.3.1.2 "><p id="en-us_topic_0150270259__nat_qs_0003_p1289605119588">The name of the NAT gateway. The name can contain a maximum of 64 characters and only digits, letters, underscores (_), and hyphens (-) are allowed.</p>
</td>
</tr>
<tr id="en-us_topic_0150270259__nat_qs_0003_row27553870195751"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p1464780019588">VPC</p>
</td>
<td class="cellrowborder" valign="top" width="75%" headers="mcps1.3.3.2.5.2.2.3.1.2 "><p id="en-us_topic_0150270259__nat_qs_0003_p4562116519588">The VPC that the NAT gateway belongs to. Select a VPC which is not used by any other NAT gateways and has no default route. </p>
<p id="en-us_topic_0150270259__nat_qs_0003_p13668174021018">You can change the VPC only when you are creating the NAT gateway. After the NAT gateway is created, you cannot modify the VPC.</p>
<div class="note" id="en-us_topic_0150270259__nat_qs_0003_note1378963764012"><span class="notetitle"> NOTE: </span><div class="notebody"><p id="en-us_topic_0150270259__nat_qs_0003_p279033714015">To allow traffic to pass through the public NAT gateway, a route to the public NAT gateway in the VPC is required. When you <span id="en-us_topic_0150270259__nat_qs_0003_ph195554115432">buy</span> a public NAT gateway, a default route 0.0.0.0/0 to the public NAT gateway is automatically added to the default route table of the VPC. If the default route 0.0.0.0/0 already exists in the default route table of the VPC before you <span id="en-us_topic_0150270259__nat_qs_0003_ph455541164313">buy</span> the public NAT gateway, the default route that points to the public NAT gateway will fail to be added automatically. In this case, perform the following operations after the public NAT gateway is successfully created: Manually add a different route that points to the gateway or create a default route 0.0.0.0/0 pointing to the gateway in the new routing table.</p>
</div></div>
</td>
</tr>
<tr id="en-us_topic_0150270259__nat_qs_0003_row47407746195751"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p17196519588">Subnet</p>
@ -35,10 +38,10 @@
<p id="en-us_topic_0150270259__nat_qs_0003_p14481165611919">You can change the subnet only when you are creating the NAT gateway. After the NAT gateway is created, you cannot change the subnet.</p>
</td>
</tr>
<tr id="en-us_topic_0150270259__nat_qs_0003_row3011590195751"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p1770884719588">Type</p>
<tr id="en-us_topic_0150270259__nat_qs_0003_row3011590195751"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p1770884719588">Specifications</p>
</td>
<td class="cellrowborder" valign="top" width="75%" headers="mcps1.3.3.2.5.2.2.3.1.2 "><p id="en-us_topic_0150270259__nat_qs_0003_p156313256519">The type of the NAT gateway.</p>
<p id="en-us_topic_0150270259__nat_qs_0003_p03201316191210">The value can be <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152120">Small</strong>, <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152124">Medium</strong>, <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152128">Large</strong>, and <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152132">Extra-large</strong>. You can click <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152252">Learn more</strong> on the page to view details about each type.</p>
<td class="cellrowborder" valign="top" width="75%" headers="mcps1.3.3.2.5.2.2.3.1.2 "><p id="en-us_topic_0150270259__nat_qs_0003_p156313256519">The specifications of the NAT gateway.</p>
<p id="en-us_topic_0150270259__nat_qs_0003_p03201316191210">The option can be <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152120">Small</strong>, <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152124">Medium</strong>, <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152128">Large</strong>, and <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152132">Extra-large</strong>. You can click <strong id="en-us_topic_0150270259__nat_qs_0003_b842352706152252">Learn more</strong> on the page to view details about each specifications.</p>
</td>
</tr>
<tr id="en-us_topic_0150270259__nat_qs_0003_row2219225792544"><td class="cellrowborder" valign="top" width="25%" headers="mcps1.3.3.2.5.2.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_p5274235692544">Description</p>
@ -64,14 +67,12 @@
</thead>
<tbody><tr id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_row5695691323119"><td class="cellrowborder" valign="top" width="12.049999999999999%" headers="mcps1.3.3.2.5.3.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_p5010724023119">Key</p>
</td>
<td class="cellrowborder" valign="top" width="87.94999999999999%" headers="mcps1.3.3.2.5.3.2.3.1.2 "><ul id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_ul2321196023222"><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li400332623222">Cannot be left blank.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li56235771151321">Must be unique for each NAT gateway.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li583414621171">Contains a maximum of 36 characters.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li852157223233">Can contain only the following character types:<ul id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_ul11049850105418"><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li11960040105258">Letter</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li674166910530">Digits</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_li77869551443">Special characters, including hyphens (-) and underscores (_)</li></ul>
</li></ul>
<td class="cellrowborder" valign="top" width="87.94999999999999%" headers="mcps1.3.3.2.5.3.2.3.1.2 "><ul id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_ul2321196023222"><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li400332623222">Cannot be left blank.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li56235771151321">Must be unique for each NAT gateway.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li583414621171">Contains a maximum of 36 characters.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li852157223233">Contains only letters, digits, hyphens (-), underscores (_), and at signs (@).</li></ul>
</td>
</tr>
<tr id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_row1973304523119"><td class="cellrowborder" valign="top" width="12.049999999999999%" headers="mcps1.3.3.2.5.3.2.3.1.1 "><p id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_p5487280123119">Value</p>
</td>
<td class="cellrowborder" valign="top" width="87.94999999999999%" headers="mcps1.3.3.2.5.3.2.3.1.2 "><ul id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_ul6706750105539"><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li3646980211638">Can contain a maximum of 43 characters.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li544437591169">Can contain only the following character types:<ul id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_ul4359364711615"><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li31940902105539">Letter</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li41841846105549">Digits</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_li13827436174517">Special characters, including hyphens (-) and underscores (_)</li></ul>
</li></ul>
<td class="cellrowborder" valign="top" width="87.94999999999999%" headers="mcps1.3.3.2.5.3.2.3.1.2 "><ul id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_ul6706750105539"><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li3646980211638">Can contain a maximum of 43 characters.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0030971658_en-us_topic_0013935842_en-us_topic_0067805752_en-us_topic_0013859511_li544437591169">Contains only letters, digits, hyphens (-), underscores (_), and at signs (@).</li></ul>
</td>
</tr>
</tbody>
@ -81,7 +82,7 @@
</li><li id="en-us_topic_0150270259__nat_qs_0003_li19473928211154">In the NAT gateway list, view the NAT gateway status. For details about the NAT gateway status, see <a href="#en-us_topic_0150270259__nat_qs_0003_table1213025114317">Table 3</a>.
<div class="tablenoborder"><a name="en-us_topic_0150270259__nat_qs_0003_table1213025114317"></a><a name="nat_qs_0003_table1213025114317"></a><table cellpadding="4" cellspacing="0" summary="" id="en-us_topic_0150270259__nat_qs_0003_table1213025114317" frame="border" border="1" rules="all"><caption><b>Table 3 </b>NAT gateway status</caption><thead align="left"><tr id="en-us_topic_0150270259__nat_qs_0003_row9131125119310"><th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.3.2.8.2.2.3.1.1"><p id="en-us_topic_0150270259__nat_qs_0003_p41311951532"><strong id="en-us_topic_0150270259__nat_qs_0003_b8423527062072">Status</strong></p>
</th>
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.3.2.8.2.2.3.1.2"><p id="en-us_topic_0150270259__nat_qs_0003_p313185110315"><strong>Description</strong></p>
<th align="left" class="cellrowborder" valign="top" width="50%" id="mcps1.3.3.2.8.2.2.3.1.2"><p id="en-us_topic_0150270259__nat_qs_0003_p313185110315"><strong id="en-us_topic_0150270259__nat_qs_0003_b364853913311">Description</strong></p>
</th>
</tr>
</thead>
@ -118,8 +119,16 @@
</tbody>
</table>
</div>
<p id="en-us_topic_0150270259__nat_qs_0003_p4610111811510">After the public NAT gateway is created, check whether a default route (0.0.0.0/0) that points to the public NAT gateway exists in the default route table of the VPC where the public NAT gateway is. If no, add a route pointing to the public NAT gateway to the default route table, alternatively, create a custom route table and add the default route 0.0.0.0/0 pointing to the public NAT gateway to the table. The following describes how to add a route to a custom route table.</p>
</li></ol>
</div>
<div class="section" id="en-us_topic_0150270259__section847381595912"><h4 class="sectiontitle">Adding a Default Route Pointing to the <span id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_ph14909153318152">Public NAT Gateway</span></h4><ol id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_ol1825183615367"><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li977516473364">Log in to the management console.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li1776154763610">Click <span><img id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li1877615472360">Under <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b19241819112412">Network</strong>, select <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b12293856202112">Virtual Private Cloud</strong>.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li2296185818371">In the navigation pane on the left, choose <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b175890662318">Route Tables</strong>.</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li11981013133911">On the <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b3223102682314">Route Tables</strong> page, click <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b6596831152315">Create Route Table</strong> in the upper right corner.<p id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_p32711746154616"><strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b167511542165614">VPC</strong>: Select the VPC to which the <span id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_ph156320278247">public NAT gateway</span> belongs.</p>
</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li001617291">After the custom route table is created, click its name.<p id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_p1228813142914"><a name="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li001617291"></a><a name="nat_qs_0003_en-us_topic_0259133770_li001617291"></a>The <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b16496151532813">Summary</strong> page is displayed.</p>
</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li1643168317">Click <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b8800122915184">Add Route</strong> and configure parameters as follows:<p id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_p898415251026"><strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b51111020191817">Destination</strong>: Set it to <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b1395011409186">0.0.0.0/0</strong>.</p>
<p id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_p174125558212"><strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b2017159199105831">Next Hop Type</strong>: Select <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b2088085659105831">NAT gateway</strong>.</p>
<p id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_p36051961039"><strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b1460241011188">Next Hop</strong>: Select the created NAT gateway.</p>
</li><li id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_li119436211920">Click <strong id="en-us_topic_0150270259__nat_qs_0003_en-us_topic_0259133770_b93674920105831">OK</strong>.</li></ol>
</div>
</div>
<div>
<div class="familylinks">

View File

@ -1,13 +1,14 @@
<a name="nat_01_0001"></a><a name="nat_01_0001"></a>
<h1 class="topictitle1">Modifying a NAT Gateway</h1>
<div id="body1516611239704"><div class="section" id="nat_01_0001__section5439700611149"><h4 class="sectiontitle">Scenarios</h4><p id="nat_01_0001__p4055678211159">This section describes how to modify the name, type, or description of a NAT gateway.</p>
<p id="nat_01_0001__p11993153883912">Increasing the size of the NAT gateway type does not affect services, but if you switch to a smaller NAT gateway, make sure the reduced capacity will still be enough to meet your service requirements.</p>
<h1 class="topictitle1">Modifying a Public NAT Gateway</h1>
<div id="body1516611239704"><div class="section" id="nat_01_0001__section5439700611149"><h4 class="sectiontitle">Scenarios</h4><p id="nat_01_0001__p4055678211159">This section describes how to modify the name, specifications, or description of a NAT gateway.</p>
<p id="nat_01_0001__p19964155117218">Using a public NAT gateway of more robust specifications does not affect services, but if you switch to a public NAT gateway of less robust specifications, make sure the reduced capacity will still be enough to meet your service requirements. </p>
<p id="nat_01_0001__p11993153883912">Using a NAT gateway of more robust specifications does not affect services, but if you switch to a NAT gateway of less robust specifications, make sure the reduced capacity will still be enough to meet your service requirements.</p>
</div>
<div class="section" id="nat_01_0001__section24081145174428"><h4 class="sectiontitle">Prerequisites</h4><p id="nat_01_0001__p58721079174435">A NAT gateway has been created.</p>
</div>
<div class="section" id="nat_01_0001__section25378358174522"><h4 class="sectiontitle">Procedure</h4><ol id="nat_01_0001__ol37874592165515"><li id="nat_01_0001__li7332756163236">Log in to the management console.</li><li id="nat_01_0001__li840318282158">Click <span><img id="nat_01_0001__en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="nat_01_0001__li1049617094325">Under <strong id="nat_01_0001__b6538202603012">Network</strong>, choose <strong id="nat_01_0001__b2539112619308">NAT Gateway</strong>.</li><li id="nat_01_0001__li8610102724918">On the displayed page, locate the row that contains the target NAT gateway and click <strong id="nat_01_0001__b2807143213502">Modify</strong> in the <strong id="nat_01_0001__b11242836195014">Operation</strong> column.</li><li id="nat_01_0001__li5535256111148">Modify the name, type, or description of the NAT gateway as prompted.<p id="nat_01_0001__p42090456113428"><a name="nat_01_0001__li5535256111148"></a><a name="li5535256111148"></a></p>
</li><li id="nat_01_0001__li1596314397533">Click <strong id="nat_01_0001__b5682170205316">Next</strong>.</li><li id="nat_01_0001__li166843965418">Click <strong id="nat_01_0001__b1835750836">Submit</strong>.</li></ol>
<div class="section" id="nat_01_0001__section25378358174522"><h4 class="sectiontitle">Procedure</h4><ol id="nat_01_0001__ol37874592165515"><li id="nat_01_0001__li7332756163236">Log in to the management console.</li><li id="nat_01_0001__li840318282158">Click <span><img id="nat_01_0001__en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="nat_01_0001__li1049617094325">Under <strong id="nat_01_0001__b6538202603012">Network</strong>, select <strong id="nat_01_0001__b2539112619308">NAT Gateway</strong>.</li><li id="nat_01_0001__li8610102724918">On the displayed page, locate the row that contains the target NAT gateway and click <strong id="nat_01_0001__b2807143213502">Modify</strong> in the <strong id="nat_01_0001__b11242836195014">Operation</strong> column.</li><li id="nat_01_0001__li5535256111148">Modify the name, specifications, or description of the NAT gateway as prompted.<p id="nat_01_0001__p42090456113428"><a name="nat_01_0001__li5535256111148"></a><a name="li5535256111148"></a></p>
</li><li id="nat_01_0001__li1596314397533">Click <strong id="nat_01_0001__b5682170205316">Next</strong>.</li><li id="nat_01_0001__li166843965418">Click <strong id="nat_01_0001__b1081197616">Submit</strong>.</li></ol>
</div>
</div>
<div>

View File

@ -11,7 +11,7 @@
<div class="section" id="nat_az_0000__en-us_topic_0184026189_section193971112578"><h4 class="sectiontitle">Selecting an AZ</h4><p id="nat_az_0000__en-us_topic_0184026189_p859161416717">When deploying resources, consider your applications' requirements on disaster recovery (DR) and network latency.</p>
<ul id="nat_az_0000__en-us_topic_0184026189_ul157203571473"><li id="nat_az_0000__en-us_topic_0184026189_li7720175710711">For high DR capability, deploy resources in different AZs within the same region.</li><li id="nat_az_0000__en-us_topic_0184026189_li109763595719">For lower network latency, deploy resources in the same AZ.</li></ul>
</div>
<div class="section" id="nat_az_0000__en-us_topic_0184026189_section1110135820407"><h4 class="sectiontitle">Regions and Endpoints</h4><p id="nat_az_0000__en-us_topic_0184026189_p361784821111">Before you use an API to call resources, specify its region and endpoint. For more details, see <a href="https://docs.otc.t-systems.com/en-us/endpoint/index.html" target="_blank" rel="noopener noreferrer">Regions and Endpoints</a>.</p>
<div class="section" id="nat_az_0000__en-us_topic_0184026189_section1110135820407"><h4 class="sectiontitle">Regions and Endpoints</h4><p id="nat_az_0000__en-us_topic_0184026189_p361784821111">Before you use an API to call resources, specify its region and endpoint. For more details, see <a href="https://docs.otc.t-systems.com/additional/endpoints.html" target="_blank" rel="noopener noreferrer">Regions and Endpoints</a>.</p>
</div>
</div>
<div>

File diff suppressed because it is too large Load Diff

View File

@ -1,11 +1,11 @@
<a name="nat_ces_0003"></a><a name="nat_ces_0003"></a>
<h1 class="topictitle1">Viewing Metrics</h1>
<div id="body1527071529095"><div class="section" id="nat_ces_0003__en-us_topic_0027371530_section8439794224022"><h4 class="sectiontitle">Prerequisites</h4><ul id="nat_ces_0003__en-us_topic_0027371530_ul3164004322451"><li id="nat_ces_0003__li14876037123711">The NAT gateway is running properly and SNAT rules have been created.</li><li id="nat_ces_0003__en-us_topic_0027371530_li6253115215042">It can take a period of time to obtain and transfer the monitoring data. Therefore, wait for a while and then check the data.</li></ul>
<div id="body1527071529095"><div class="section" id="nat_ces_0003__en-us_topic_0027371530_section8439794224022"><h4 class="sectiontitle">Prerequisites</h4><ul id="nat_ces_0003__en-us_topic_0027371530_ul3164004322451"><li id="nat_ces_0003__li14876037123711">The NAT gateway is running properly and SNAT rules have been created.</li><li id="nat_ces_0003__en-us_topic_0027371530_li6253115215042">It can take a period of time to obtain and transfer the monitoring data. Wait for a while and then check the data.</li></ul>
</div>
<div class="section" id="nat_ces_0003__section53841197455"><h4 class="sectiontitle">Scenarios</h4><p id="nat_ces_0003__p964131413450">This section describes how to view NAT Gateway metrics.</p>
</div>
<div class="section" id="nat_ces_0003__en-us_topic_0027371530_section44667294224513"><h4 class="sectiontitle">Procedure</h4><ol id="nat_ces_0003__en-us_topic_0027371530_ol52641911224530"><li id="nat_ces_0003__en-us_topic_0027371530_li4015157224530">Log in to the management console.</li><li id="nat_ces_0003__li45573243468">In the upper left corner, select the target region.</li><li id="nat_ces_0003__en-us_topic_0027371530_li56082099224530">Under <strong id="nat_ces_0003__b11805117198">Management &amp; Deployment</strong>, select <strong id="nat_ces_0003__b1719151151917">Cloud Eye</strong>.</li><li id="nat_ces_0003__li8839354101513">In the navigation pane on the left, choose <strong id="nat_ces_0003__b1364526653141156">Cloud Service Monitoring</strong> &gt; <strong id="nat_ces_0003__b842352706125643">NAT Gateway</strong>.</li><li id="nat_ces_0003__li144940413176">Locate the row that contains the target metric and click <strong id="nat_ces_0003__b11461771468">View Metric</strong> in the <strong id="nat_ces_0003__b842352706125827">Operation</strong> column to check detailed information.<p id="nat_ces_0003__p1654217277316">You can view data of the last one, three, or twelve hours.</p>
<div class="section" id="nat_ces_0003__en-us_topic_0027371530_section44667294224513"><h4 class="sectiontitle">Procedure</h4><ol id="nat_ces_0003__en-us_topic_0027371530_ol52641911224530"><li id="nat_ces_0003__en-us_topic_0027371530_li4015157224530">Log in to the management console.</li><li id="nat_ces_0003__li45573243468">In the upper left corner, select the target region.</li><li id="nat_ces_0003__en-us_topic_0027371530_li56082099224530">Under <strong id="nat_ces_0003__b753403817496">Management &amp; Deployment</strong>, select <strong id="nat_ces_0003__b1719151151917">Cloud Eye</strong>.</li><li id="nat_ces_0003__li8839354101513">In the navigation pane on the left, choose <strong id="nat_ces_0003__b1364526653141156">Cloud Service Monitoring</strong> &gt; <strong id="nat_ces_0003__b842352706125643">NAT Gateway</strong>.</li><li id="nat_ces_0003__li144940413176">Locate the row that contains the target metric and click <strong id="nat_ces_0003__b4695757163816">View Metric</strong> in the <strong id="nat_ces_0003__b842352706125827">Operation</strong> column to check detailed information.<p id="nat_ces_0003__p1654217277316">You can view data of the last one, three, or twelve hours.</p>
</li></ol>
<p id="nat_ces_0003__p890810251115"></p>
</div>

View File

@ -8,6 +8,8 @@
</li>
<li class="ulchildlink"><strong><a href="nat_dnat_0001.html">Viewing a DNAT Rule</a></strong><br>
</li>
<li class="ulchildlink"><strong><a href="nat_dnat_0002.html">Modifying a DNAT Rule</a></strong><br>
</li>
<li class="ulchildlink"><strong><a href="nat_dnat_0003.html">Deleting a DNAT Rule</a></strong><br>
</li>
</ul>

View File

@ -0,0 +1,17 @@
<a name="nat_dnat_0002"></a><a name="nat_dnat_0002"></a>
<h1 class="topictitle1">Modifying a DNAT Rule</h1>
<div id="body1548154434843"><div class="section" id="nat_dnat_0002__section44788855152716"><h4 class="sectiontitle">Scenarios</h4><p id="nat_dnat_0002__p4622986152723">After a DNAT rule is added, you can modify parameters in the DNAT rule as required.</p>
</div>
<div class="section" id="nat_dnat_0002__section45365749152921"><h4 class="sectiontitle">Prerequisites</h4><p id="nat_dnat_0002__p55701220152933">A DNAT rule has been added for the NAT gateway.</p>
</div>
<div class="section" id="nat_dnat_0002__section30069985153038"><h4 class="sectiontitle">Procedure</h4><ol id="nat_dnat_0002__ol58162347153051"><li id="nat_dnat_0002__li7332756163236">Log in to the management console.</li><li id="nat_dnat_0002__li840318282158">Click <span><img id="nat_dnat_0002__en-us_topic_0118498823_image338921514480" src="en-us_image_0141273034.png"></span> in the upper left corner and select the desired region and project.</li><li id="nat_dnat_0002__li1049617094325">Under <strong id="nat_dnat_0002__b11508102620191">Network</strong>, choose <strong id="nat_dnat_0002__b195082026141914">NAT Gateway</strong>.</li><li id="nat_dnat_0002__li8610102724918">On the displayed page, click the name of the target NAT gateway.</li><li id="nat_dnat_0002__li17425138164911">On the NAT gateway details page, click the <strong id="nat_dnat_0002__b8560183019191">DNAT Rules</strong> tab.</li><li id="nat_dnat_0002__li190116535015">Locate the row that contains the DNAT rule you want to modify and click <strong id="nat_dnat_0002__b5123123417194">Modify</strong> in the <strong id="nat_dnat_0002__b3125203441919">Operation</strong> column.</li><li id="nat_dnat_0002__li17673104019579">In the displayed dialog box, modify the required parameters. <div class="fignone" id="nat_dnat_0002__fig423204217614"><span class="figcap"><b>Figure 1 </b>Modify DNAT Rule</span><br><span><img id="nat_dnat_0002__image19226231967" src="en-us_image_0000001626339129.png"></span></div>
</li><li id="nat_dnat_0002__li8835108115112">Click <strong id="nat_dnat_0002__b7600422204">OK</strong>.</li></ol>
</div>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="nat_dnat_0000.html">Managing DNAT Rules</a></div>
</div>
</div>

View File

@ -1,8 +1,8 @@
<a name="nat_faq_0002"></a><a name="nat_faq_0002"></a>
<h1 class="topictitle1">What Are SNAT Connections?</h1>
<div id="body1531445624883"><p id="nat_faq_0002__p8060118">An SNAT connection consists of the source IP address, source port, destination IP address, destination port, and transmission-layer protocol. These five elements identify a connection as a unique session. The source IP address refers to the EIP, and the source port refers to the EIP port. They will be used to access the destination IP address and port of the Internet.</p>
<p id="nat_faq_0002__p20617117185216">SNAT supports three protocols: TCP, UDP, and ICMP. A NAT gateway supports up to 55,000 concurrent connections for each destination IP address and port. If any of the destination IP address, port number, and protocol (TCP/UDP/ICMP) changes, you can create another 55,000 connections. The number of connections you query on an ECS may be different from the actual number of SNAT connections. (You can run the <strong id="nat_faq_0002__b1651883184717">netstat</strong> command to query the number of connections.) Assume that an ECS creates 100 connections to a fixed destination every second. 55,000 connections will be used up in about 10 minutes without considering the dropped idle connections. As a result, new connections cannot be established.</p>
<div id="body1531445624883"><p id="nat_faq_0002__p8060118">An SNAT connection consists of the source IP address, source port, destination IP address, destination port, and a transport layer protocol. These five elements identify a connection as a unique session. The source IP address refers to the EIP, and the source port refers to the EIP port. They will be used to access the destination IP address and port of the Internet.</p>
<p id="nat_faq_0002__p20617117185216">SNAT supports three protocols: TCP, UDP, and ICMP. A NAT gateway supports up to 55,000 concurrent connections for each destination IP address and port. If any of the destination IP address, port number, and protocol (TCP/UDP/ICMP) changes, you can create another 55,000 connections. The number of connections you query on an <span id="nat_faq_0002__text20171168152416">ECS</span> may be different from the actual number of SNAT connections. (You can run the <strong id="nat_faq_0002__b1651883184717">netstat</strong> command to query the number of connections.) Assume that an <span id="nat_faq_0002__text14312205279">ECS</span> creates 100 connections to a fixed destination every second. 55,000 connections will be used up in about 10 minutes without considering the dropped idle connections. As a result, new connections cannot be established.</p>
<p id="nat_faq_0002__p691421205812">If there is no data packet passing through the SNAT connection for a long time, the connection will be timed out. </p>
</div>
<div>

View File

@ -1,7 +1,7 @@
<a name="nat_faq_0003"></a><a name="nat_faq_0003"></a>
<h1 class="topictitle1">What Is the Relationship Between a VPC, NAT Gateway, EIP Bandwidth, and ECS?</h1>
<div id="body1513321406402"><ul id="nat_faq_0003__ul6422493815350"><li id="nat_faq_0003__li2659561415350">A VPC is a secure, isolated, logical network environment.</li><li id="nat_faq_0003__li2193374815413">A NAT gateway enables ECSs in the VPC to access the Internet.</li><li id="nat_faq_0003__li4739003315343">EIP is a service that provides valid static IP addresses on the Internet. The throughput of a VPC is determined by the EIP bandwidth.</li><li id="nat_faq_0003__li3747920415346">An ECS is a running instance in the VPC and uses the NAT gateway to access the Internet.</li></ul>
<h1 class="topictitle1">What Is the Relationship Between a VPC and a NAT Gateway, <span id="text437564583717"></span><span id="text1537514450373">EIP</span> Bandwidth, and <span id="text9276195163416">ECS</span>s in the VPC?</h1>
<div id="body1513321406402"><ul id="nat_faq_0003__ul6422493815350"><li id="nat_faq_0003__li2659561415350">A VPC is a secure, isolated, logical network environment.</li><li id="nat_faq_0003__li2193374815413">The NAT gateway enables <span id="nat_faq_0003__text16624920203411">ECS</span>s in the VPC to access the Internet.</li><li id="nat_faq_0003__li4739003315343">EIP is a service that provides valid static IP addresses on the Internet. The throughput of a VPC is determined by the EIP bandwidth.</li><li id="nat_faq_0003__li3747920415346"><span id="nat_faq_0003__text4242812341">ECS</span>s are instances running in the VPC and use the NAT gateway to access the Internet.</li></ul>
</div>
<div>
<div class="familylinks">

View File

@ -1,7 +1,7 @@
<a name="nat_faq_0005"></a><a name="nat_faq_0005"></a>
<h1 class="topictitle1">Do the NAT Gateway and SNAT Rule Support the Update Operation?</h1>
<div id="body1513321406402"><p id="nat_faq_0005__p24956662153532">NAT gateways can be updated. SNAT rules cannot be updated.</p>
<div id="body1513321406402"><p id="nat_faq_0005__p24956662153532">NAT gateways can be updated, and SNAT rules cannot be updated.</p>
</div>
<div>
<div class="familylinks">

View File

@ -1,7 +1,7 @@
<a name="nat_faq_0006"></a><a name="nat_faq_0006"></a>
<h1 class="topictitle1">Why Is DNAT Used?</h1>
<div id="body1557818061702"><p id="nat_faq_0006__p1054811712154">DNAT enables servers in a VPC to share an EIP to provide services accessible from the Internet through IP address mapping or port mapping.</p>
<div id="body1557818061702"><p id="nat_faq_0006__p1054811712154">DNAT enables servers in a VPC to share an EIP to provide services accessible from the Internet. For details, see <a href="en-us_topic_0127489530.html">Adding a DNAT Rule</a>.</p>
</div>
<div>
<div class="familylinks">

View File

@ -0,0 +1,12 @@
<a name="nat_faq_0009"></a><a name="nat_faq_0009"></a>
<h1 class="topictitle1">What Is the Bandwidth of the NAT Gateway When a Server Accesses the Internet Through the NAT Gateway? Where Can I Configure the Bandwidth?</h1>
<div id="body1566956326598"><p id="nat_faq_0009__p1354675718212">NAT Gateway SNAT translates a private IP address to a public IP address by binding <span id="nat_faq_0009__text1913390195412"></span><span id="nat_faq_0009__text613312085418">EIP</span>s to servers in a VPC. When a server accesses the Internet through the NAT gateway, the bandwidth is related to the bandwidth of the <span id="nat_faq_0009__text15668641666"></span><span id="nat_faq_0009__text196681411568">EIP</span> assigned to you.</p>
<p id="nat_faq_0009__p14547135792117"></p>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="nat_faq_0200.html">SNAT</a></div>
</div>
</div>

View File

@ -1,7 +1,7 @@
<a name="nat_faq_001"></a><a name="nat_faq_001"></a>
<h1 class="topictitle1">Why Is SNAT Used?</h1>
<div id="body1531445921401"><p id="nat_faq_001__p1380619353919">Besides requiring services provided by the system, some ECSs also need to access the Internet to obtain information or download software. However, assigning a public IP address to each ECS consumes already-limited IPv4 addresses, incurs additional costs, and may increase the attack surface in a virtual environment. Enabling multiple ECSs to share a single public IP address is preferable and more practical. This can be done using SNAT.</p>
<div id="body1531445921401"><p id="nat_faq_001__p1380619353919">Besides requiring services provided by the system, some <span id="nat_faq_001__text20171168152416">ECS</span>s also need to access the Internet to obtain information or download software. However, assigning a public IP address to each <span id="nat_faq_001__text18348153519265">ECS</span> consumes already-limited IPv4 addresses, incurs additional costs, and may increase the attack surface in a virtual environment. Enabling multiple <span id="nat_faq_001__text2054712580264">ECS</span>s to share a single public IP address is preferable and more practical. This can be done using SNAT.</p>
</div>
<div>
<div class="familylinks">

View File

@ -10,10 +10,10 @@
</div>
<div class="section" id="nat_faq_0010__section457218466261"><h4 class="sectiontitle">How Do I Apply for a Higher Quota?</h4><p id="nat_faq_0010__en-us_topic_0040259342_p133802054172617">The system does not support online quota adjustment. If you need to adjust a quota, call the hotline or send an email to the customer service mailbox. Customer service personnel will timely process your request for quota adjustment and inform you of the real-time progress by making a call or sending an email.</p>
<p id="nat_faq_0010__en-us_topic_0040259342_p13745144852611">Before dialing the hotline number or sending an email, make sure that the following information has been obtained:</p>
<ul id="nat_faq_0010__en-us_topic_0040259342_ul37351029162712"><li id="nat_faq_0010__en-us_topic_0040259342_li12735132932714">Domain name, project name, and project ID, which can be obtained by performing the following operations:<p id="nat_faq_0010__en-us_topic_0040259342_p1973542918275"><a name="nat_faq_0010__en-us_topic_0040259342_li12735132932714"></a><a name="en-us_topic_0040259342_li12735132932714"></a>Log in to the management console using the cloud account, click the username in the upper right corner, select <strong id="nat_faq_0010__en-us_topic_0040259342_b1637292748">My Credentials</strong> from the drop-down list, and obtain the domain name, project name, and project ID on the <strong id="nat_faq_0010__en-us_topic_0040259342_b600826191">My Credentials</strong> page.</p>
<ul id="nat_faq_0010__en-us_topic_0040259342_ul37351029162712"><li id="nat_faq_0010__en-us_topic_0040259342_li12735132932714">Domain name, project name, and project ID, which can be obtained by performing the following operations:<p id="nat_faq_0010__en-us_topic_0040259342_p1973542918275"><a name="nat_faq_0010__en-us_topic_0040259342_li12735132932714"></a><a name="en-us_topic_0040259342_li12735132932714"></a>Log in to the management console using the cloud account, click the username in the upper right corner, select <strong id="nat_faq_0010__en-us_topic_0040259342_b171181053141511">My Credentials</strong> from the drop-down list, and obtain the domain name, project name, and project ID on the <strong id="nat_faq_0010__en-us_topic_0040259342_b1956165671712">My Credentials</strong> page.</p>
</li><li id="nat_faq_0010__en-us_topic_0040259342_li13735182917270">Quota information, which includes:<ul id="nat_faq_0010__en-us_topic_0040259342_ul6735102912273"><li id="nat_faq_0010__en-us_topic_0040259342_li1073516296277">Service name</li><li id="nat_faq_0010__en-us_topic_0040259342_li6735152972712">Quota type</li><li id="nat_faq_0010__en-us_topic_0040259342_li773592992718">Required quota</li></ul>
</li></ul>
<p id="nat_faq_0010__en-us_topic_0040259342_p126761744182712"><a href="https://docs.otc.t-systems.com/en-us/public/learnmore.html" target="_blank" rel="noopener noreferrer">Learn how to obtain the service hotline and email address.</a></p>
<p id="nat_faq_0010__en-us_topic_0040259342_p126761744182712"><a href="https://open-telekom-cloud.com/en/contact" target="_blank" rel="noopener noreferrer">Learn how to obtain the service hotline and email address.</a></p>
</div>
</div>
<div>

View File

@ -0,0 +1,12 @@
<a name="nat_faq_0011"></a><a name="nat_faq_0011"></a>
<h1 class="topictitle1">What Should I Do If I Fail to Access the Internet Through a NAT Gateway?</h1>
<div id="body1547778691779"><p id="nat_faq_0011__p1166770113215">If your server cannot access the Internet through a NAT gateway, you may have configured the VPC route table incorrectly. Perform the following steps to reset the route table:</p>
<ol id="nat_faq_0011__ol134664911547"><li id="nat_faq_0011__li9347749125412">Locate the route table associated with the subnet in the VPC.</li><li id="nat_faq_0011__li1828410916555">Check whether the route table contains the route to the NAT gateway. If not, add the route.</li><li id="nat_faq_0011__li416411240106">Ensure that the destination address of the route to be added contain the target address.</li></ol>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="nat_faq_0100.html">NAT Gateway</a></div>
</div>
</div>

View File

@ -1,11 +1,11 @@
<a name="nat_faq_0013"></a><a name="nat_faq_0013"></a>
<h1 class="topictitle1">What Are the Differences Between Using a NAT Gateway and Using an EIP for an ECS?</h1>
<div id="body1566956326598"><p id="nat_faq_0013__p919024111146">A NAT gateway provides SNAT and DNAT, so multiple ECSs can share an EIP.</p>
<p id="nat_faq_0013__p5190174191414">An ECS can also have an EIP bound to it. The EIP does not have to be shared.</p>
<p id="nat_faq_0013__p280016112012">If both SNAT and EIP are configured for an ECS, data will be forwarded through the EIP.</p>
<h1 class="topictitle1">For an <span id="text178571910141212">ECS</span>, Is There Any Difference Between Using a NAT Gateway and Directly Having an <span id="text437564583717"></span><span id="text1537514450373">EIP</span> Bound?</h1>
<div id="body1566956326598"><p id="nat_faq_0013__p919024111146">The NAT gateway provides the SNAT and DNAT functions, allowing multiple <span id="nat_faq_0013__text0867203517126">ECS</span>s to share one <span id="nat_faq_0013__text1923417381021"></span><span id="nat_faq_0013__text12234438625">EIP</span>.</p>
<p id="nat_faq_0013__p5190174191414">The <span id="nat_faq_0013__text44268323416">ECS</span> that has an <span id="nat_faq_0013__text691674154112"></span><span id="nat_faq_0013__text391624110412">EIP</span> bound is exclusively using the IP address.</p>
<p id="nat_faq_0013__p280016112012">If both SNAT and EIP are configured for an <span id="nat_faq_0013__text12921848201214">ECS</span>, data will be preferentially forwarded through the <span id="nat_faq_0013__text186291250194114"></span><span id="nat_faq_0013__text46291650184111">EIP</span>.</p>
<p id="nat_faq_0013__p10403798201">If both DNAT and EIP are configured for an ECS, the ECS will have two EIPs, one that is directly bound to the ECS and one that is associated with the DNAT rule. Incoming data will be forwarded by one of the two EIPs, which is determined by the client user. Outgoing data will be forwarded by the EIP directly bound to the ECS in priority. If the two EIPs are different, data forwarding will fail.</p>
<p id="nat_faq_0013__p1792725919162">Configuring both a NAT gateway and an EIP for an ECS is not recommended.</p>
<p id="nat_faq_0013__p1792725919162">Therefore, you are not advised to use a NAT gateway and bind an <span id="nat_faq_0013__text1940627184211"></span><span id="nat_faq_0013__text1294082714425">EIP</span> to the same <span id="nat_faq_0013__text46819238136">ECS</span> at the same time.</p>
</div>
<div>
<div class="familylinks">

Some files were not shown because too many files have changed in this diff Show More