Internet Gateway, NAT Gateway & Route Tables

AWS Networking (ANS-C01 track) AWS console — free tier (GUI + CLI)

مقصدObjectiveObjective

انٹرنیٹ گیٹ وے اور NAT گیٹ وے لگا کر پبلک اور پرائیویٹ سب نیٹس کو انٹرنیٹ سے جوڑنا۔Internet Gateway aur NAT Gateway laga kar public aur private subnets ko internet se jorna.Connect public and private subnets to the internet using an Internet Gateway and a NAT Gateway.

آسان مثالSimple AnalogySimple Analogy

انٹرنیٹ گیٹ وے بلڈنگ کا مرکزی دروازہ ہے۔ NAT گیٹ وے وہ ریسپشن ہے جو اندر والوں (پرائیویٹ سب نیٹ) کو باہر بات کرنے دیتی ہے مگر باہر سے کوئی براہِ راست اندر نہیں آ سکتا۔ روٹ ٹیبل نقشہ ہے جو بتاتا ہے کس راستے سے جانا ہے۔Internet Gateway building ka main darwaza hai. NAT Gateway woh reception hai jo andar walon (private subnet) ko bahar baat karne deti hai magar bahar se koi direct andar nahi aa sakta. Route table naqsha hai jo batata hai kis rastay se jana hai.The Internet Gateway is the building's main door. The NAT Gateway is the reception desk that lets insiders (private subnet) talk outward, while nobody from outside can walk straight in. The route table is the map that says which road to take.

سیٹ اپLab SetupLab Setup

aws-01 کا LabVPC اور تینوں سب نیٹس موجود ہوں۔ NAT گیٹ وے کے لیے ایک Elastic IP چاہیے ہوگی (فری ٹیئر میں EIP مفت ہے جب تک چلتے وسائل سے جڑی رہے)۔aws-01 ka LabVPC aur teeno subnets maujood hon. NAT Gateway ke liye ek Elastic IP chahiye hogi (free tier mein EIP free hai jab tak chaltay resources se juri rahe).You need the LabVPC and all three subnets from aws-01. The NAT Gateway needs one Elastic IP (free in the free tier while attached to a running resource).

اقداماتStepsSteps

Step 1

انٹرنیٹ گیٹ وے (IGW) بنائیں اور اسے LabVPC سے جوڑیں۔ IGW کے بغیر VPC سے باہر انٹرنیٹ ٹریفک نہیں جا سکتی۔Internet Gateway (IGW) banayein aur isay LabVPC se jorein. IGW ke baghair VPC se bahar internet traffic nahi ja sakti.Create an Internet Gateway (IGW) and attach it to LabVPC. Without an IGW, no internet traffic can leave the VPC.

aws ec2 create-internet-gateway --tag-specifications 'ResourceType=internet-gateway,Tags=[{Key=Name,Value=LabIGW}]'
aws ec2 attach-internet-gateway --vpc-id vpc-0123456789abcdef0 --internet-gateway-id igw-0123456789abcdef0

🖱️ VPC > Internet Gateways > Create internet gateway > نام LabIGW > Create، پھر Actions > Attach to VPC > LabVPC > AttachVPC > Internet Gateways > Create internet gateway > Name LabIGW > Create, phir Actions > Attach to VPC > LabVPC > AttachVPC > Internet Gateways > Create internet gateway > Name LabIGW > Create, then Actions > Attach to VPC > LabVPC > Attach

Step 2

پبلک سب نیٹس کے لیے ایک روٹ ٹیبل بنائیں اور اس میں ڈیفالٹ روٹ 0.0.0.0/0 کو IGW کی طرف لگائیں۔ پھر دونوں پبلک سب نیٹس اس سے جوڑیں۔Public subnets ke liye ek route table banayein aur is mein default route 0.0.0.0/0 ko IGW ki taraf lagayein. Phir dono public subnets is se jorein.Create a route table for the public subnets and add the default route 0.0.0.0/0 pointing at the IGW. Then associate both public subnets with it.

aws ec2 create-route-table --vpc-id vpc-0123456789abcdef0 --tag-specifications 'ResourceType=route-table,Tags=[{Key=Name,Value=LabPublicRT}]'
aws ec2 create-route --route-table-id rtb-0123456789abcdef0 --destination-cidr-block 0.0.0.0/0 --gateway-id igw-0123456789abcdef0
aws ec2 associate-route-table --route-table-id rtb-0123456789abcdef0 --subnet-id subnet-aaaapublica
aws ec2 associate-route-table --route-table-id rtb-0123456789abcdef0 --subnet-id subnet-bbbbpublicb

🖱️ VPC > Route Tables > Create route table > نام LabPublicRT، VPC LabVPC > Create۔ پھر Routes > Edit routes > Add route: 0.0.0.0/0، Target: Internet Gateway LabIGW > Save۔ Subnet associations > Edit > LabPublicA اور LabPublicB منتخب کریں۔VPC > Route Tables > Create route table > Name LabPublicRT, VPC LabVPC > Create. Phir Routes > Edit routes > Add route: 0.0.0.0/0, Target: Internet Gateway LabIGW > Save. Subnet associations > Edit > LabPublicA aur LabPublicB select karein.VPC > Route Tables > Create route table > Name LabPublicRT, VPC LabVPC > Create. Then Routes > Edit routes > Add route: 0.0.0.0/0, Target: Internet Gateway LabIGW > Save. Subnet associations > Edit > select LabPublicA and LabPublicB.

Step 3

NAT گیٹ وے کے لیے ایک Elastic IP لیں۔ NAT گیٹ وے ہمیشہ پبلک سب نیٹ میں بنتا ہے کیونکہ اسے خود انٹرنیٹ تک رسائی چاہیے۔NAT Gateway ke liye ek Elastic IP lein. NAT Gateway hamesha public subnet mein banta hai kyunke isay khud internet tak rasai chahiye.Allocate an Elastic IP for the NAT Gateway. A NAT Gateway always lives in a public subnet because it needs internet access itself.

aws ec2 allocate-address --domain vpc --tag-specifications 'ResourceType=elastic-ip,Tags=[{Key=Name,Value=LabNATEIP}]'

🖱️ VPC > Elastic IPs > Allocate Elastic IP address > Amazon's pool of IPv4 addresses > AllocateVPC > Elastic IPs > Allocate Elastic IP address > Amazon's pool of IPv4 addresses > AllocateVPC > Elastic IPs > Allocate Elastic IP address > Amazon's pool of IPv4 addresses > Allocate

Step 4

NAT گیٹ وے بنائیں اور اسے LabPublicA سب نیٹ میں رکھیں۔ بننے میں 1-2 منٹ لگتے ہیں، حالت Available ہونے کا انتظار کریں۔NAT Gateway banayein aur isay LabPublicA subnet mein rakhein. Banne mein 1-2 minute lagtay hain, state Available honay ka intezar karein.Create the NAT Gateway in the LabPublicA subnet. It takes 1–2 minutes to create — wait until its state is Available.

aws ec2 create-nat-gateway --subnet-id subnet-aaaapublica --allocation-id eipalloc-0123456789abcdef0 --tag-specifications 'ResourceType=natgateway,Tags=[{Key=Name,Value=LabNAT}]'

🖱️ VPC > NAT Gateways > Create NAT gateway > نام LabNAT، Subnet LabPublicA، Elastic IP: نئی مختص شدہ IP > CreateVPC > NAT Gateways > Create NAT gateway > Name LabNAT, Subnet LabPublicA, Elastic IP: newly allocated IP > CreateVPC > NAT Gateways > Create NAT gateway > Name LabNAT, Subnet LabPublicA, Elastic IP: the newly allocated IP > Create

Step 5

پرائیویٹ سب نیٹ کے لیے الگ روٹ ٹیبل بنائیں اور 0.0.0.0/0 کو NAT گیٹ وے کی طرف لگائیں۔ پھر LabPrivateA اس سے جوڑیں۔Private subnet ke liye alag route table banayein aur 0.0.0.0/0 ko NAT Gateway ki taraf lagayein. Phir LabPrivateA is se jorein.Create a separate route table for the private subnet with 0.0.0.0/0 pointing at the NAT Gateway. Then associate LabPrivateA with it.

aws ec2 create-route-table --vpc-id vpc-0123456789abcdef0 --tag-specifications 'ResourceType=route-table,Tags=[{Key=Name,Value=LabPrivateRT}]'
aws ec2 create-route --route-table-id rtb-0987654321fedcba0 --destination-cidr-block 0.0.0.0/0 --nat-gateway-id nat-0123456789abcdef0
aws ec2 associate-route-table --route-table-id rtb-0987654321fedcba0 --subnet-id subnet-ccccprivatea

🖱️ VPC > Route Tables > Create route table > نام LabPrivateRT > Create۔ Routes > Edit routes > Add route: 0.0.0.0/0، Target: NAT Gateway LabNAT > Save۔ Subnet associations > LabPrivateA منتخب کریں۔VPC > Route Tables > Create route table > Name LabPrivateRT > Create. Routes > Edit routes > Add route: 0.0.0.0/0, Target: NAT Gateway LabNAT > Save. Subnet associations > LabPrivateA select karein.VPC > Route Tables > Create route table > Name LabPrivateRT > Create. Routes > Edit routes > Add route: 0.0.0.0/0, Target: NAT Gateway LabNAT > Save. Subnet associations > select LabPrivateA.

Step 6

ہر روٹ ٹیبل کے Routes ٹیب میں چیک کریں: LabPublicRT میں 0.0.0.0/0 → igw-xxx اور LabPrivateRT میں 0.0.0.0/0 → nat-xxx نظر آنا چاہیے۔Har route table ke Routes tab mein check karein: LabPublicRT mein 0.0.0.0/0 → igw-xxx aur LabPrivateRT mein 0.0.0.0/0 → nat-xxx nazar aana chahiye.Check the Routes tab of each route table: LabPublicRT must show 0.0.0.0/0 → igw-xxx and LabPrivateRT must show 0.0.0.0/0 → nat-xxx.

🖱️ VPC > Route Tables > ہر ٹیبل منتخب کریں > Routes ٹیبVPC > Route Tables > har table select karein > Routes tabVPC > Route Tables > select each table > Routes tab

تصدیقVerifyVerify

LabPublicRT میں انٹرنیٹ گیٹ وے کا روٹ اور LabPrivateRT میں NAT گیٹ وے کا روٹ Active حالت میں ہو۔ NAT گیٹ وے کی حالت Available ہو۔LabPublicRT mein Internet Gateway ka route aur LabPrivateRT mein NAT Gateway ka route Active state mein ho. NAT Gateway ki state Available ho.LabPublicRT shows the IGW route and LabPrivateRT shows the NAT Gateway route, both Active. The NAT Gateway state is Available.

aws ec2 describe-route-tables --filters Name=tag:Name,Values=LabPublicRT,LabPrivateRT --query 'RouteTables[*].[Tags[?Key==`Name`].Value|[0],Routes[*].[DestinationCidrBlock,State]]' --output table
aws ec2 describe-nat-gateways --filter Name=tag:Name,Values=LabNAT --query 'NatGateways[*].[NatGatewayId,State]' --output table

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ NAT گیٹ وے Pending حالت میں پھنسا رہتا ہے۔NAT Gateway Pending state mein phansa rehta hai.The NAT Gateway stays stuck in Pending state.

✅ چیک کریں کہ Elastic IP مختص ہوئی ہے اور سب نیٹ پبلک ہے (اس کا روٹ IGW کی طرف ہو)۔ NAT گیٹ وے کو خود انٹرنیٹ رسائی چاہیے۔Check karein ke Elastic IP allocate hui hai aur subnet public hai (is ka route IGW ki taraf ho). NAT Gateway ko khud internet access chahiye.Check that an Elastic IP was allocated and the subnet is public (its route points to the IGW). The NAT Gateway itself needs internet access.

⚠️ پرائیویٹ سب نیٹ کا EC2 انسٹنس انٹرنیٹ تک نہیں پہنچتا۔Private subnet ka EC2 instance internet tak nahi pahunchta.An EC2 instance in the private subnet cannot reach the internet.

✅ پرائیویٹ روٹ ٹیبل چیک کریں: 0.0.0.0/0 NAT گیٹ وے کی طرف ہونا چاہیے، IGW کی طرف نہیں۔ اور سیکیورٹی گروپ میں آؤٹ باؤنڈ اجازت ہونی چاہیے۔Private route table check karein: 0.0.0.0/0 NAT Gateway ki taraf hona chahiye, IGW ki taraf nahi. Aur security group mein outbound ijazat honi chahiye.Check the private route table: 0.0.0.0/0 must point to the NAT Gateway, not the IGW. Also confirm the security group allows outbound traffic.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ انٹرنیٹ گیٹ وے اور NAT گیٹ وے میں کیا فرق ہے؟Internet Gateway aur NAT Gateway mein kya farq hai?What is the difference between an Internet Gateway and a NAT Gateway?

IGW پوری VPC کے لیے دو طرفہ انٹرنیٹ رسائی دیتا ہے (پبلک سب نیٹس کے لیے)۔ NAT گیٹ وے صرف آؤٹ باؤنڈ رسائی دیتا ہے — پرائیویٹ وسائل باہر جا سکتے ہیں مگر انٹرنیٹ سے کوئی براہِ راست اندر نہیں آ سکتا۔IGW poori VPC ke liye do tarfa internet access deta hai (public subnets ke liye). NAT Gateway sirf outbound access deta hai — private resources bahar ja sakte hain magar internet se koi direct andar nahi aa sakta.An IGW gives two-way internet access for the whole VPC (for public subnets). A NAT Gateway gives outbound-only access — private resources can go out, but nothing from the internet can come in directly.

❓ سب نیٹ پبلک کب کہلاتا ہے؟Subnet public kab kehlata hai?When is a subnet considered public?

جب اس کے روٹ ٹیبل میں 0.0.0.0/0 کا روٹ انٹرنیٹ گیٹ وے کی طرف ہو۔ 'پبلک' ہونا سب نیٹ کی خاصیت نہیں، اس کے روٹ ٹیبل کی ہے۔Jab is ke route table mein 0.0.0.0/0 ka route Internet Gateway ki taraf ho. 'Public' hona subnet ki khasiyat nahi, is ke route table ki hai.When its route table has a 0.0.0.0/0 route pointing to an Internet Gateway. Being 'public' is a property of the route table, not the subnet.