Yandex Cloud
  • Services
  • Solutions
  • Why Yandex Cloud
  • Blog
  • Pricing
  • Documentation
  • Contact us
Get started
Language / Region
Yandex project
© 2023 Yandex.Cloud LLC
Yandex Virtual Private Cloud
  • Getting started
  • Step-by-step instructions
    • All instructions
    • Cloud network
      • Creating a cloud network
      • Deleting a cloud network
      • Updating a cloud network
      • Moving a cloud network between folders
    • Subnet
      • Creating a subnet
      • Deleting a subnet
      • Updating a subnet
      • Moving a subnet between folders
      • Viewing a list of used addresses
    • IP address
      • Reserving a static public IP address
      • Making a dynamic public IP address static
      • Making a static public IP address dynamic
      • Moving an address between folders
      • Deleting a static public IP address
    • Static routing
      • Creating static routes
      • Enabling NAT to the internet
      • Creating and setting up a NAT gateway
      • Moving a route table between folders
      • Moving a NAT gateway between folders
    • Security groups
      • Create a security group
      • Changing the name and description
      • Adding a new rule
      • Delete a rule
      • Moving a security group between folders
      • Delete a security group
    • Enable a software-accelerated network
    • DDoS protection
      • Enable protection from DDoS attacks
    • Chart of network connections
  • Practical guidelines
    • All tutorials
    • Architecture and protection of a basic internet service
    • Routing through a NAT instance
    • Creating an IPSec VPN tunnel
    • Installing a Cisco CSR 1000v virtual router
    • Installing a Mikrotik CHR virtual router
    • Connecting to a cloud network using OpenVPN
    • Creating and configuring a UserGate gateway in proxy server mode
    • Configuring networks for Yandex Data Proc
  • Concepts
    • Relationships between service resources
    • Cloud networks and subnets
    • Cloud resource addresses
    • Static routes
    • Security groups
    • Gateways
    • Monitoring network connections
    • Public IP address ranges
    • MTU and MSS
    • DHCP settings
    • Software-accelerated network
    • Quotas and limits
  • DDoS Protection
  • Recommendations
    • Using public IP addresses
  • Access management
  • Pricing policy
    • Current pricing policy
    • Archive
      • Before January 1, 2019
  • API reference
    • Authentication in the API
    • REST
      • Overview
      • Address
        • Overview
        • create
        • delete
        • get
        • getByValue
        • list
        • listOperations
        • move
        • update
      • Gateway
        • Overview
        • create
        • delete
        • get
        • list
        • listOperations
        • move
        • update
      • Network
        • Overview
        • create
        • delete
        • get
        • list
        • listOperations
        • listRouteTables
        • listSecurityGroups
        • listSubnets
        • move
        • update
      • RouteTable
        • Overview
        • create
        • delete
        • get
        • list
        • listOperations
        • move
        • update
      • SecurityGroup
        • Overview
        • create
        • delete
        • get
        • list
        • listOperations
        • move
        • update
        • updateRule
        • updateRules
      • Subnet
        • Overview
        • addCidrBlocks
        • create
        • delete
        • get
        • list
        • listOperations
        • move
        • removeCidrBlocks
        • update
      • Operation
        • Overview
        • get
    • gRPC
      • Overview
      • AddressService
      • GatewayService
      • NetworkService
      • RouteTableService
      • SecurityGroupService
      • SubnetService
      • OperationService
  • Questions and answers
  1. Concepts
  2. Gateways

Gateways

Written by
Yandex Cloud
  • NAT gateway

NAT gateway

A NAT gateway lets you grant internet access permissions to cloud resources without assigning them public IP addresses. Instead, they will access the internet via the NAT gateway that will be assigned an IP address from a separate range of public IPs. A gateway is a regional resource that is present in all availability zones. You can manage gateways using the management console, CLI, Terraform, or API.

To route traffic through a gateway, specify it as the next hop in a route table. Currently, you can only use a NAT gateway for a route with the 0.0.0.0/0 destination prefix: any traffic to be routed outside the network will pass through this gateway.

If a VM's network interface is assigned a public IP and the subnet that this interface is connected to has a route table with a gateway set up, the VM will access the internet from that public IP and not through the gateway. Currently, you can't use reserved public IP addresses for gateways.

Warning

Please note that a NAT gateway will replace the Egress NAT function for subnets. If you disable NAT to the internet in a subnet, you can't enable it again and have to use a NAT gateway instead.

Was the article helpful?

Language / Region
Yandex project
© 2023 Yandex.Cloud LLC