1 Answers
The public subnet needs to permit the traffic in via NACL to allow the traffic to reach the NATGW. Since Security Groups don’t apply to NATGWs they don’t come into play. In general, the NATGW will source nat/proxy the traffic it receives before going to the internet which makes it the destination for the return traffic from the internet. Functionally it will pass its external elastic IP to the internet gateway. The Internet gateway uses the elastic IP as the one to one NAT onto the internet. This nat/proxy pattern allows the return traffic to get back to the correct instances that make up the NATGW and eventually the EC2 instance. Let me know if this isn’t clear or what you were asking.