🏫 The School›🚪 NAT›⚖️ धडा 03 — NAT gateway विरुद्ध NAT instance
🖼️ See the drawing + lab 🏠 Course home 🌿 Branch on GitHub ✏️ View source
🖼️ आकृती आणि labThe drawing + lab पूर्ण पानावर उघडा ↗Open full page ↗

⚖️ धडा 03 — NAT gateway विरुद्ध NAT instance

📍 तुम्ही इथे आहात: 8 पैकी धडा 03 · मागे: lesson-02-how-pat-works · पुढे: lesson-04-per-az-routing


📦 या ब्रँचमध्ये काय आहे

धडे 01–02, आणि दोन प्रकारची फाटके: managed NAT gateway आणि NAT instance (तुम्ही configure करता ते EC2). nat/demo.py मधील kinds() दोन्ही शेजारी-शेजारी छापते.

🧒 5 वर्षांच्या मुलाला समजावल्यासारखे

शाळा एखादी फाटक कंपनी 🏢 नेमू शकते. कंपनी रखवालदार पाठवते, आजारी पडलेल्या रखवालदाराच्या जागी काही मिनिटांत दुसरा आणते, गर्दी वाढली की जास्त रांगा उघडते, आणि प्रत्येक तासाचे व फाटकातून जाणाऱ्या प्रत्येक पिशवीचे bill पाठवते.

किंवा शाळा स्वतःच्या काळजीवाहकालाच 🧹 रखवालदार म्हणून वापरू शकते. तो स्वस्त आहे. कंपनी करणार नाही अशी जास्तीची कामेही तो करू शकतो: शाळेच्या स्वतःच्या यादीनुसार पिशव्या तपासणे, किंवा एखाद्या पाहुण्याला बाजूच्या दारातून आत सोडणे. पण तो आजारी पडला तर फाटकावर कोणीच नसते. आणि तो एका माणसाला जमेल तितक्याच वेगाने काम करतो.

कंपनी म्हणजे NAT gateway. काळजीवाहक म्हणजे NAT instance.

🗺️ आकृती

flowchart LR
    subgraph gw["🏢 NAT gateway (managed)"]
      g1["5 Gbps → 100 Gbps<br/>redundant in its AZ<br/>no security groups"]
    end
    subgraph inst["🧹 NAT instance (EC2)"]
      i1["size of the instance<br/>you patch and fail it over<br/>security groups ✅"]
    end
    desks["🪑 private desks"] -->|"1 option A"| gw
    desks -->|"2 option B"| inst
    gw -->|"$/hour + $/GB"| net["🌐 internet"]
    inst -->|"instance $/hour"| net

🗺️ काढलेली आकृती + एक lab: https://school-edh.pages.dev/nat/lesson-diagrams.html#l03

❓ काय

🤔 का

2015 पूर्वी NAT instance हा एकमेव पर्याय होता, आणि NAT instance थांबले म्हणजे प्रत्येक private server चे internet जात असे. Managed gateway ने ते काम काढून टाकले. आज gateway हाच default आहे; instance फक्त छोट्या labs मध्ये टिकून आहे, जिथे त्याच्या धोक्यापेक्षा त्याचा कमी खर्च जास्त महत्त्वाचा असतो, आणि gateway करू शकत नाही अशा युक्त्या लागणाऱ्या मोजक्या रचनांमध्ये.

🔧 कसे (या repo मध्ये)

nat/demo.py मधील kinds() तुलनेचे table छापते. nat/gateway.py मधील monthly_cost() हे hourly आणि per_gb arguments घेते, त्यामुळे तुम्ही NAT instance ची किंमत त्याच्या instance किमतीने आणि per_gb=0 ने काढू शकता. NatGateway.up मुळे तुम्ही फाटक थांबवून प्रत्येक फेरी fail होताना पाहू शकता.

🧪 करून पाहा

python3 nat/demo.py kinds
python3 - <<'EOF'
import sys; sys.path.insert(0, "nat"); from gateway import NatGateway, monthly_cost
PYPI = ("151.101.0.223", 443, "tcp")
for gb in (100, 1000, 5000):
    gw = monthly_cost(1, gb)
    inst = monthly_cost(1, gb, hourly=0.0104, per_gb=0)   # example t3.micro price, no per-GB NAT fee
    print(f"{gb:>5} GB  gateway ${gw:>7,.2f}  ·  instance ${inst:>6,.2f}")
g = NatGateway("nat-instance", ["13.232.10.40"])
g.up = False                                           # the one EC2 stops
print("instance down → send:", g.send(("10.20.48.25", 50001), PYPI))
EOF

0.0104 ही t3.micro (Linux, us-east-1) ची उदाहरण on-demand किंमत आहे. hourly=0.0832 (एक उदाहरण m5.large) वापरून पाहा: instance ची ओळ $ 60.74 होते — 100 GB ला gateway पेक्षा जास्त, 1,000 GB ला कमी.

✅ तपासा — तुम्हाला काय दिसायला हवे

kinds table छापते, त्यात security groups cannot attach yes आणि cost $0.045/h + $0.045/GB the instance price, no per-GB fee असते. तुमचा snippet हे छापतो:

  100 GB  gateway $  37.35  ·  instance $  7.59
 1000 GB  gateway $  77.85  ·  instance $  7.59
 5000 GB  gateway $ 257.85  ·  instance $  7.59
instance down → send: None

कागदावर instance खूपच स्वस्त दिसते. शेवटची ओळ म्हणजे त्यासाठी मोजावी लागणारी किंमत: एक EC2 थांबले आणि तुम्ही ते दुरुस्त करेपर्यंत send() प्रत्येक बाकासाठी None परत देते. (t3.micro ची network bandwidth सुद्धा मर्यादित असते, महिन्याला 5,000 GB ती तपासून पाहू शकतात.)

🏁 तुम्ही आत्ताच काय सिद्ध केले

Managed gateway जास्त महाग आहे आणि कमी "हुशार" काम करतो, पण तो त्याच्या AZ मध्ये स्वतःहून scale होतो आणि स्वतःच बरा होतो; NAT instance ते थांबेपर्यंतच स्वस्त असते.

⚠️ नेहमीच्या चुका

🏭 प्रत्यक्ष वापरात

खऱ्या account वर — NAT instance बांधणे (lab साठी), आणि Terraform मध्ये gateway:

aws ec2 modify-instance-attribute --instance-id i-0nat --no-source-dest-check
# on the instance (Amazon Linux, interface name may differ):
sudo sysctl -w net.ipv4.ip_forward=1
sudo iptables -t nat -A POSTROUTING -o ens5 -s 10.20.0.0/16 -j MASQUERADE
aws ec2 create-route --route-table-id rtb-private-a --destination-cidr-block 0.0.0.0/0 --instance-id i-0nat
resource "aws_eip" "nat_a" {
  domain = "vpc"
}

resource "aws_nat_gateway" "a" {
  allocation_id     = aws_eip.nat_a.id
  subnet_id         = aws_subnet.public_a.id
  connectivity_type = "public"
  tags              = { Name = "nat-a" }
}

🏭 प्रत्यक्ष वापरात हे का महत्त्वाचे: "पहाटे 3 वाजता NAT restart कोण करणार?" हाच खरा प्रश्न आहे. Gateway असेल तर AWS करते. Instance असेल तर तुम्ही — म्हणून production जवळजवळ नेहमी gateway वापरते.

⏭️ पुढे

NAT gateway एका AZ च्या आत स्वतःच बरा होतो. पण संपूर्ण AZ चाच प्रकाश गेला तर? प्रत्येक AZ ला एक फाटक — आणि त्यांच्याकडे निर्देश करणाऱ्या route tables.

git checkout lesson-04-per-az-routing

⚖️ Lesson 03 — NAT gateway vs NAT instance

📍 You are here: Lesson 03 of 8 · Previous: lesson-02-how-pat-works · Next: lesson-04-per-az-routing


📦 What's in this branch

Lessons 01–02, plus the two kinds of gate: the managed NAT gateway and the NAT instance (an EC2 you configure). kinds() in nat/demo.py prints them side by side.

🧒 Explain like I'm 5

The school can hire a gate company 🏢. The company sends guards, replaces a guard who falls ill in minutes, opens more lanes when the crowd grows, and sends a bill for every hour and for every bag that passes.

Or the school can use its own caretaker 🧹 as the guard. He is cheap. He can also do extra jobs the company will not do: check bags against the school's own list, or let one visitor through a side door. But if he is ill, nobody guards the gate. And he only works as fast as one person can.

The company is the NAT gateway. The caretaker is the NAT instance.

🗺️ Diagram

flowchart LR
    subgraph gw["🏢 NAT gateway (managed)"]
      g1["5 Gbps → 100 Gbps<br/>redundant in its AZ<br/>no security groups"]
    end
    subgraph inst["🧹 NAT instance (EC2)"]
      i1["size of the instance<br/>you patch and fail it over<br/>security groups ✅"]
    end
    desks["🪑 private desks"] -->|"1 option A"| gw
    desks -->|"2 option B"| inst
    gw -->|"$/hour + $/GB"| net["🌐 internet"]
    inst -->|"instance $/hour"| net

🗺️ Drawn version + a lab: https://school-edh.pages.dev/nat/lesson-diagrams.html#l03

❓ What

🤔 Why

Before 2015, the NAT instance was the only choice, and a stopped NAT instance meant every private server lost the internet. The managed gateway removed that work. Today the gateway is the default; the instance survives in tiny labs, where its lower cost matters more than its risk, and in the few designs that need tricks a gateway cannot do.

🔧 How (in this repo)

kinds() in nat/demo.py prints the comparison table. monthly_cost() in nat/gateway.py takes hourly and per_gb arguments, so you can price a NAT instance with its instance price and per_gb=0. NatGateway.up lets you stop a gate and watch every trip fail.

🧪 Try it

python3 nat/demo.py kinds
python3 - <<'EOF'
import sys; sys.path.insert(0, "nat"); from gateway import NatGateway, monthly_cost
PYPI = ("151.101.0.223", 443, "tcp")
for gb in (100, 1000, 5000):
    gw = monthly_cost(1, gb)
    inst = monthly_cost(1, gb, hourly=0.0104, per_gb=0)   # example t3.micro price, no per-GB NAT fee
    print(f"{gb:>5} GB  gateway ${gw:>7,.2f}  ·  instance ${inst:>6,.2f}")
g = NatGateway("nat-instance", ["13.232.10.40"])
g.up = False                                           # the one EC2 stops
print("instance down → send:", g.send(("10.20.48.25", 50001), PYPI))
EOF

0.0104 is an example on-demand price for a t3.micro (Linux, us-east-1). Try hourly=0.0832 (an example m5.large): the instance line becomes $ 60.74 — more than the gateway at 100 GB, less at 1,000 GB.

✅ Verify — what you should see

kinds prints the table, including security groups cannot attach yes and cost $0.045/h + $0.045/GB the instance price, no per-GB fee. Your snippet prints:

  100 GB  gateway $  37.35  ·  instance $  7.59
 1000 GB  gateway $  77.85  ·  instance $  7.59
 5000 GB  gateway $ 257.85  ·  instance $  7.59
instance down → send: None

The instance looks far cheaper on paper. The last line is the price you pay for that: one EC2 stops and send() returns None for every desk until you fix it. (A t3.micro also has limited network bandwidth, which 5,000 GB a month may test.)

🏁 What you just proved

The managed gateway costs more and does less "clever" work, but it scales and heals by itself inside its AZ; the NAT instance is cheap until the moment it stops.

⚠️ Common mistakes

🏭 In production

On a real account — building a NAT instance (lab use), and the gateway in Terraform:

aws ec2 modify-instance-attribute --instance-id i-0nat --no-source-dest-check
# on the instance (Amazon Linux, interface name may differ):
sudo sysctl -w net.ipv4.ip_forward=1
sudo iptables -t nat -A POSTROUTING -o ens5 -s 10.20.0.0/16 -j MASQUERADE
aws ec2 create-route --route-table-id rtb-private-a --destination-cidr-block 0.0.0.0/0 --instance-id i-0nat
resource "aws_eip" "nat_a" {
  domain = "vpc"
}

resource "aws_nat_gateway" "a" {
  allocation_id     = aws_eip.nat_a.id
  subnet_id         = aws_subnet.public_a.id
  connectivity_type = "public"
  tags              = { Name = "nat-a" }
}

🏭 Why this matters in production: "who restarts the NAT at 3 a.m.?" is the real question. With a gateway, AWS does. With an instance, you do — so production almost always uses the gateway.

⏭️ Next

A NAT gateway heals itself inside one AZ. What if the whole AZ goes dark? One gate per AZ — and the route tables that point at them.

git checkout lesson-04-per-az-routing
← Previoushow pat worksNext →per az routing

This page is the lesson's README from the lesson-03-gateway-vs-instance branch, shown here so the whole School stays on one site. Code files open on GitHub at the same branch.