Scenarios

<p>This article describes the common application scenarios of the NAT gateway.</p> <p><strong><span style="font-size:18px">Access the Internet with Multiple Cloud Hosts in the VPC</span></strong></p> <p>There are conditions when some servers in the VPC need to access the Internet, including software upgrading and web page browsing. However, for security reasons, the IP addresses of these servers must not be exposed to the Internet; or, for cost-saving reasons, multiple servers need to share one public IP address. You can use the SNAT function of the NAT gateway to meet your demand.</p> <p><img src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20201707112316-1436bec796b4.png" style="height:525px; width:435px" /></p> <p><span style="font-size:18px"><strong>Build a Simple Website or App Service</strong></span></p> <p>With the function of DNAT of the NAT gateway, you can use one to two servers to provide web page service or app service to the Internet.</p> <p>&bull;&nbsp;When only a few fixed ports are used to provide services, you can use the DNAT port mapping function of the NAT gateway to maximize the use of a single public IP address.</p> <p><img src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20201707112351-135e6fac9011.png" style="height:531px; width:435px" /></p> <p>&bull;&nbsp;When unfixed number or a large number of ports are needed, you can use the DNAT IP mapping function of the NAT gateway, so that one ECS instance needs to occupy only one public IP address.</p> <p><img src="https://obs-cn-shanghai.yun.pingan.com/pcp-portal/20201707112433-1aab670d993a.png" style="height:526px; width:442px" /></p> <p><strong><span style="font-size:18px">Provide Security Protection to the VPC</span></strong></p> <p>With SNAT function of the NAT gateway, you can provide simple security protection to the VPC. After establishing a NAT gateway, you can control the access requests to Internet servers. It refers to hiding the ECS in the VPC behind the NAT gateway, so that the host would not be scanned or be easily attacked by hackers. Servers in the Internet cannot initiate access request to ECSs of the VPC actively. Only Internet servers receiving access requests sent by ECSs in the VPC are able to connect to ECSs, so as to provide security protection to ECSs in the VPC.</p>
Did the above content solve your problem? Yes No
Please complete information!

Call us

400-151-8800

Email us

cloud@pingan.com

Online customer service

Instant reply

Technical Support

cloud products