Облачная платформаAdvanced

Notes and Constraints

Язык статьи: Английский
Перевести

Public NAT Gateway

When using a public NAT gateway, note the following:

  • Common restrictions
    • Rules on a public NAT gateway can use the same EIP, but rules on different NAT gateways must use different EIPs.
    • Each VPC can be associated with multiple public NAT gateways.
    • Only one NAT gateway can be created for a subnet.
    • SNAT and DNAT rules can use the same EIP to save resources. However, when Port Type of a DNAT rule is set to All ports, the resources configured for the DNAT rule will preferentially use all ports of the EIP. So an SNAT rule cannot share an EIP with such a DNAT rule.
    • If both an EIP and a public NAT gateway are configured for a server, data will be forwarded through the EIP.
    • Some carriers will block the following ports for security reasons. Do not use the ports in the table below.

      Protocol

      Port

      TCP

      42, 135, 137, 138, 139, 444, 445, 593, 1025, 1068, 1434, 3127, 3128, 3129, 3130, 4444, 4789, 4790, 5554, 5800, 5900, and 9996

      UDP

      135 to 139, 1026, 1027, 1028, 1068, 1433, 1434, 4789, 4790, 5554, and 9996

    • NAT Gateway supports TCP, UDP, and ICMP, but does not support application layer gateway (ALG)-related technologies. In addition, NAT Gateway does not support Encapsulating Security Payload (ESP) and Authentication Header (AH) used by Generic Routing Encapsulation (GRE) tunnels and Internet Protocol Security (IPsec). This is determined by the features of NAT Gateway.
  • SNAT restrictions
    • Only one SNAT rule can be added for each VPC subnet.
    • If an SNAT rule is added for a Direct Connect connection, the custom CIDR block must be the CIDR block of a Direct Connect connection and cannot overlap with that of the NAT gateway's VPC.
    • There is no limit on the number of SNAT rules that can be added on a public NAT gateway.
  • DNAT restrictions
    • Only one DNAT rule can be configured for each port on a server. One port can be mapped to only one EIP.
    • A maximum of 200 DNAT rules can be added on a public NAT gateway.