Lesson 089 · AWS Learning Path

AWS 089: Compare NAT, gateway endpoint, and interface endpoint traffic and cost

· Published · 14 min read

Trial resources feed usage and budget meters that trigger early cost alerts

The real problem

A team recognizes the name Compare NAT, gateway endpoint, and interface endpoint traffic and cost but has not connected the feature to a real requirement, identity boundary, network or data path, failure mode, price dimension, and cleanup owner. A plausible configuration could still fail the workload.

Final outcome

The learner will produce a requirement-led artifact for Compare NAT, gateway endpoint, and interface endpoint traffic and cost, inspect the matching AWS control plane in the Management Console, run a matching CloudShell or AWS CLI query, interpret the output, diagnose one failure, defend one architecture choice, and prove cleanup or approved retained state.

The practical outcome is not a command transcript. It must show what was expected, what happened, what the result proves, what it does not prove, and which evidence would change the decision.

Learning objectives

By the end of this lesson, the learner can:

  • explain nat cost path;
  • explain gateway endpoint path;
  • explain interface endpoint path;
  • explain private dns;
  • explain policy layers;
  • connect control-plane state to the real data, network, identity, or application behavior;
  • identify cost and cleanup ownership before any optional mutation;
  • troubleshoot from evidence without opening broad access or adding broad permissions.

Relationship model

Requirement
   |
   v
Identity and policy -> AWS configuration -> network or data path -> workload behavior
        |                    |                      |                    |
        +--------------------+----------------------+--------------------+
                                      |
                                      v
                         monitoring, cost, recovery, cleanup

Use this model to separate an AWS object that exists from a result that actually works. Every arrow is a verification boundary.

Prerequisites, permissions, Region, and safety

  • Learning baseline: This sequence assumes practical Linux knowledge but no prior cloud-computing or AWS knowledge. Cloud, networking, security, data, automation, and architecture concepts must come from completed earlier lessons. If a prerequisite checkpoint is incomplete, return to its linked lesson before continuing.
  • Confirm a non-root caller with aws sts get-caller-identity and keep the account number private.
  • Use ap-south-1 unless this lesson explicitly names a second Region.
  • Confirm the intended profile and Region with aws configure list before interpreting an empty result.
  • The live track requires only the named create, describe, tag, test, and delete actions for the lab resources. If the personal-account identity lacks them, use the instructor evidence track. Do not attach AdministratorAccess as a shortcut.
  • This lesson has an optional paid live track. Record current prices, obtain owner approval, set a hard timer, tag every resource, and finish same-session cleanup. The supplied-evidence track is a complete no-create alternative.
  • Never publish account IDs, public addresses, ARNs containing private account data, session IDs, presigned URLs, object data, credentials, or KMS material.
  • Do not use root, world-open SSH or RDP, disabled TLS verification, unowned resources, or irreversible retention controls in a training exercise.

Core model

ConceptWhat the learner must understand
NAT cost pathA public NAT gateway has hourly and data-processing charges. Traffic can also incur cross-AZ and service data-transfer charges when subnets use a NAT gateway in another Availability Zone.
Gateway endpoint pathGateway endpoints support Amazon S3 and DynamoDB, add service prefix-list routes to selected route tables, and have no hourly endpoint charge. Service request and data charges still apply.
Interface endpoint pathAn interface endpoint creates private ENIs in selected subnets. Endpoint-hour and data-processing charges apply, and multi-AZ resilience normally creates an endpoint ENI in each active AZ.
Private DNSWith private DNS enabled, the normal regional service hostname resolves to endpoint private addresses inside associated VPCs when DNS prerequisites are satisfied.
Policy layersA route or private DNS answer does not authorize an API call. Endpoint policy, identity policy, resource policy, KMS policy, and service-specific controls can all affect the result.
Cost comparisonThe cheapest architecture depends on destinations, bytes, AZ placement, availability, operations, and required private access. A single per-GB comparison is incomplete.

How it works

Compare the same workload flow three ways: internet-bound IPv4 through NAT, S3 through a route-table gateway endpoint, and a supported AWS API through interface-endpoint DNS and ENIs. Draw both forward and return paths and attach each charge dimension to the component that causes it.

Read the result in layers:

  1. Scope: account, Region, VPC, bucket, AZ, endpoint, principal, object version, or resource ARN.
  2. Control plane: the requested configuration exists and reached an expected state.
  3. Behavior: the request, connection, health check, replication, restore, or application result meets the requirement.
  4. Operations: monitoring, failure owner, cost, retention, rollback, and cleanup are known.

Control-plane success is necessary but not sufficient. A resource can be available while policy, routing, DNS, health, data, or application behavior remains wrong.

Architecture decision table

RequirementPreferred directionWhy
High-volume same-Region S3 from private subnetsS3 gateway endpointIt removes NAT processing for the supported route and permits endpoint-policy controls.
Private access to a supported API with no internet pathInterface endpoints per required AZPrivate ENIs and DNS keep the API path inside the VPC design.
Many changing public internet destinationsNAT gatewayEndpoints do not replace general IPv4 internet egress.
Training account without paid-lab approvalRequired T0 evidence trackUse supplied route, DNS, metric, and price evidence without creating hourly resources.

Professional questions normally contain several valid services. State the requirement that selects one option, why the nearest alternative fails it, and what changed requirement would reverse the choice.

AWS Management Console guided practice

Before opening a service page, write the expected account, Region, starting state, and evidence. Do not choose Create, Save, Purchase, Lock, or Delete unless the lesson explicitly authorizes the live track.

  1. Open VPC NAT gateways, Endpoints, Route tables, and Network interfaces in ap-south-1; inventory the exact components before approving the optional build.
  2. For the T0 track, load the supplied nw-p05-netlab route, DNS, and price evidence. For T2, create only the approved temporary NAT and endpoint resources and start a 30-minute timer.
  3. Trace one public destination, one S3 request, and one interface-endpoint service name; record the route target, DNS answer, policy boundary, AZ path, and charge dimensions.

For each step, capture the field name and value in text. A screenshot may support the record but does not replace the explanation. Console labels can evolve, so use the service search and current documentation if a navigation label differs.

CloudShell and AWS CLI practice

CloudShell is the default browser-based command environment taught in AWS 028. AWS 029 and AWS 030 cover local CLI installation and authentication. This lesson therefore does not assume that an unconfigured local shell is ready.

Start every session with:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account portion of the ARN before sharing. Then perform the topic query:

List NAT gateways, endpoints, endpoint ENIs, and routes, then annotate which component each planned flow uses.

aws ec2 describe-nat-gateways --query 'NatGateways[].{Id:NatGatewayId,State:State,Subnet:SubnetId}' --output table
aws ec2 describe-vpc-endpoints --query 'VpcEndpoints[].{Id:VpcEndpointId,Type:VpcEndpointType,Service:ServiceName,State:State,PrivateDNS:PrivateDnsEnabled}' --output table
aws ec2 describe-route-tables --query 'RouteTables[].Routes[].{Destination:DestinationCidrBlock,PrefixList:DestinationPrefixListId,NAT:NatGatewayId,Endpoint:GatewayId}' --output table

Expected interpretation:

A gateway endpoint is visible as a prefix-list route, while an interface endpoint is represented by ENIs and optionally private DNS. These control-plane results do not prove application authorization or measured traffic volume.

Replace every replace-with-... sample value before running its command, and use only an explicitly owned resource. Explain each option first. These queries are read-only; a successful response does not authorize a later create or delete operation.

Practical work

Complete the required p05-egress-cost-comparison.md from current pricing and supplied evidence. The optional T2 extension uses nw-p05-netlab-vpc (10.51.0.0/16), one public and one private subnet in one AZ, one public NAT gateway and Elastic IP, one S3 gateway endpoint, and one approved interface endpoint. Time-box it to 30 minutes, compare route and private-DNS state, then delete the interface endpoint, gateway endpoint, NAT gateway, Elastic IP, routes, subnets, internet gateway, and VPC. No optional build is required to pass.

Required T0 comparison track

The required track creates nothing. Use the supplied route-table, DNS, NAT metric, endpoint ENI, and current-price records. Complete this table for three flows:

FlowAddress or DNS resultRoute targetPolicy boundariesAZ pathCharge dimensions
private client to a public IPv4 servicepublic address0.0.0.0/0 to NATclient IAM is normally not involved in internet routingclient AZ to NAT AZNAT hours, NAT bytes, public IPv4, transfer
private client to regional S3S3 regional addressesS3 prefix list to gateway endpointidentity, endpoint, bucket, KMS when usedroute-table service pathS3 requests, storage and applicable transfer
private client to Systems Manager APIprivate endpoint ENI addressesVPC local route to endpoint ENIidentity, endpoint policy, service and KMS where usedclient AZ to endpoint AZendpoint ENI hours and processed bytes

Calculate the monthly direction for one and two active AZs. Record hours, GB in each direction, endpoint count, cross-AZ bytes, requests, and current Region price. Do not use a price copied from an old course note.

Optional T2 control-plane build

This extension proves the route and DNS controls. It does not claim measured application bytes because no client instance is required. Stop if the current estimated charge is not approved.

Use CloudShell:

export AWS_DEFAULT_REGION="ap-south-1"
NW_AZ="$(aws ec2 describe-availability-zones --filters Name=state,Values=available --query 'AvailabilityZones[0].ZoneName' --output text)"

NW_VPC_ID="$(aws ec2 create-vpc --cidr-block 10.51.0.0/16 --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=nw-p05-netlab-vpc},{Key=Project,Value=NitWings-P05-NetLab}]' --query Vpc.VpcId --output text)"
aws ec2 modify-vpc-attribute --vpc-id "$NW_VPC_ID" --enable-dns-support Value=true
aws ec2 modify-vpc-attribute --vpc-id "$NW_VPC_ID" --enable-dns-hostnames Value=true

NW_PUBLIC_SUBNET_ID="$(aws ec2 create-subnet --vpc-id "$NW_VPC_ID" --availability-zone "$NW_AZ" --cidr-block 10.51.10.0/24 --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=nw-p05-netlab-public},{Key=Project,Value=NitWings-P05-NetLab}]' --query Subnet.SubnetId --output text)"
NW_PRIVATE_SUBNET_ID="$(aws ec2 create-subnet --vpc-id "$NW_VPC_ID" --availability-zone "$NW_AZ" --cidr-block 10.51.110.0/24 --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=nw-p05-netlab-private},{Key=Project,Value=NitWings-P05-NetLab}]' --query Subnet.SubnetId --output text)"

NW_IGW_ID="$(aws ec2 create-internet-gateway --tag-specifications 'ResourceType=internet-gateway,Tags=[{Key=Name,Value=nw-p05-netlab-igw},{Key=Project,Value=NitWings-P05-NetLab}]' --query InternetGateway.InternetGatewayId --output text)"
aws ec2 attach-internet-gateway --vpc-id "$NW_VPC_ID" --internet-gateway-id "$NW_IGW_ID"

NW_PUBLIC_RT_ID="$(aws ec2 create-route-table --vpc-id "$NW_VPC_ID" --tag-specifications 'ResourceType=route-table,Tags=[{Key=Name,Value=nw-p05-netlab-public-rt},{Key=Project,Value=NitWings-P05-NetLab}]' --query RouteTable.RouteTableId --output text)"
NW_PRIVATE_RT_ID="$(aws ec2 create-route-table --vpc-id "$NW_VPC_ID" --tag-specifications 'ResourceType=route-table,Tags=[{Key=Name,Value=nw-p05-netlab-private-rt},{Key=Project,Value=NitWings-P05-NetLab}]' --query RouteTable.RouteTableId --output text)"
aws ec2 create-route --route-table-id "$NW_PUBLIC_RT_ID" --destination-cidr-block 0.0.0.0/0 --gateway-id "$NW_IGW_ID"
NW_PUBLIC_ASSOC_ID="$(aws ec2 associate-route-table --route-table-id "$NW_PUBLIC_RT_ID" --subnet-id "$NW_PUBLIC_SUBNET_ID" --query AssociationId --output text)"
NW_PRIVATE_ASSOC_ID="$(aws ec2 associate-route-table --route-table-id "$NW_PRIVATE_RT_ID" --subnet-id "$NW_PRIVATE_SUBNET_ID" --query AssociationId --output text)"

NW_ALLOCATION_ID="$(aws ec2 allocate-address --domain vpc --tag-specifications 'ResourceType=elastic-ip,Tags=[{Key=Name,Value=nw-p05-netlab-eip},{Key=Project,Value=NitWings-P05-NetLab}]' --query AllocationId --output text)"
NW_NAT_ID="$(aws ec2 create-nat-gateway --subnet-id "$NW_PUBLIC_SUBNET_ID" --allocation-id "$NW_ALLOCATION_ID" --tag-specifications 'ResourceType=natgateway,Tags=[{Key=Name,Value=nw-p05-netlab-nat},{Key=Project,Value=NitWings-P05-NetLab}]' --query NatGateway.NatGatewayId --output text)"
aws ec2 wait nat-gateway-available --nat-gateway-ids "$NW_NAT_ID"
aws ec2 create-route --route-table-id "$NW_PRIVATE_RT_ID" --destination-cidr-block 0.0.0.0/0 --nat-gateway-id "$NW_NAT_ID"

At this point the NAT timer is running. Create the no-hourly-charge S3 gateway endpoint and one paid SSM interface endpoint:

NW_S3_ENDPOINT_ID="$(aws ec2 create-vpc-endpoint --vpc-id "$NW_VPC_ID" --vpc-endpoint-type Gateway --service-name com.amazonaws.ap-south-1.s3 --route-table-ids "$NW_PRIVATE_RT_ID" --tag-specifications 'ResourceType=vpc-endpoint,Tags=[{Key=Name,Value=nw-p05-netlab-s3-gw},{Key=Project,Value=NitWings-P05-NetLab}]' --query VpcEndpoint.VpcEndpointId --output text)"

NW_ENDPOINT_SG_ID="$(aws ec2 create-security-group --group-name nw-p05-netlab-endpoint-sg --description 'Temporary HTTPS endpoint lab' --vpc-id "$NW_VPC_ID" --tag-specifications 'ResourceType=security-group,Tags=[{Key=Name,Value=nw-p05-netlab-endpoint-sg},{Key=Project,Value=NitWings-P05-NetLab}]' --query GroupId --output text)"
aws ec2 authorize-security-group-ingress --group-id "$NW_ENDPOINT_SG_ID" --ip-permissions 'IpProtocol=tcp,FromPort=443,ToPort=443,IpRanges=[{CidrIp=10.51.0.0/16,Description=Temporary-lab-clients}]'

NW_INTERFACE_ENDPOINT_ID="$(aws ec2 create-vpc-endpoint --vpc-id "$NW_VPC_ID" --vpc-endpoint-type Interface --service-name com.amazonaws.ap-south-1.ssm --subnet-ids "$NW_PRIVATE_SUBNET_ID" --security-group-ids "$NW_ENDPOINT_SG_ID" --private-dns-enabled --tag-specifications 'ResourceType=vpc-endpoint,Tags=[{Key=Name,Value=nw-p05-netlab-ssm-if},{Key=Project,Value=NitWings-P05-NetLab}]' --query VpcEndpoint.VpcEndpointId --output text)"
aws ec2 wait vpc-endpoint-available --vpc-endpoint-ids "$NW_INTERFACE_ENDPOINT_ID"

Inspect the S3 prefix-list route and interface endpoint DNS entries. Record that these prove configured paths, not API authorization or data volume.

Optional lab cleanup

Delete paid resources first and wait before deleting their network:

aws ec2 delete-vpc-endpoints --vpc-endpoint-ids "$NW_INTERFACE_ENDPOINT_ID" "$NW_S3_ENDPOINT_ID"
for NW_ATTEMPT in $(seq 1 30); do
  NW_ENDPOINT_COUNT="$(aws ec2 describe-vpc-endpoints --vpc-endpoint-ids "$NW_INTERFACE_ENDPOINT_ID" "$NW_S3_ENDPOINT_ID" --query 'length(VpcEndpoints)' --output text 2>/dev/null || printf '0')"
  if [ "$NW_ENDPOINT_COUNT" = "0" ]; then break; fi
  sleep 10
done
aws ec2 delete-nat-gateway --nat-gateway-id "$NW_NAT_ID"
aws ec2 wait nat-gateway-deleted --nat-gateway-ids "$NW_NAT_ID"
aws ec2 release-address --allocation-id "$NW_ALLOCATION_ID"

aws ec2 delete-security-group --group-id "$NW_ENDPOINT_SG_ID"
aws ec2 disassociate-route-table --association-id "$NW_PRIVATE_ASSOC_ID"
aws ec2 disassociate-route-table --association-id "$NW_PUBLIC_ASSOC_ID"
aws ec2 delete-route-table --route-table-id "$NW_PRIVATE_RT_ID"
aws ec2 delete-route-table --route-table-id "$NW_PUBLIC_RT_ID"
aws ec2 detach-internet-gateway --internet-gateway-id "$NW_IGW_ID" --vpc-id "$NW_VPC_ID"
aws ec2 delete-internet-gateway --internet-gateway-id "$NW_IGW_ID"
aws ec2 delete-subnet --subnet-id "$NW_PRIVATE_SUBNET_ID"
aws ec2 delete-subnet --subnet-id "$NW_PUBLIC_SUBNET_ID"
aws ec2 delete-vpc --vpc-id "$NW_VPC_ID"

Re-run the exact tag and service inventory. A successful delete request without absent-state verification does not pass.

The evidence package must contain:

  • the problem and final requirement in the learner's own words;
  • caller type and Region with private identifiers redacted;
  • exact planned values, ownership, and cost class;
  • one Console observation and matching CLI or API evidence;
  • one behavior result or supplied data-plane record;
  • one denied, failed, or counterexample result and evidence-led diagnosis;
  • one architecture choice plus the rejected alternative;
  • cleanup proof or explicit retained-state owner, expiry, and next lesson.

Verification standard

Use expected state before observed state. Record timestamps in UTC and preserve the original failure before changing anything. A passing submission answers all four questions:

  1. What exact requirement was tested?
  2. Which evidence proves the AWS configuration?
  3. Which evidence proves the workload behavior?
  4. What remains unproven or requires later monitoring?

If AWS returns no rows, verify account, Region, permission, filters, pagination, resource type, and deletion state before concluding that nothing exists.

Common failures and troubleshooting

SymptomEvidence firstLikely boundarySmallest safe response
object appears missingcaller, Region, filters, pagination, tagsscope or read permissionalign scope before creating a duplicate
state remains pending or unavailableservice state, events, dependencies, quotasdependency or capacitycorrect the named dependency and wait with a bound
AccessDeniedprincipal, action, resource, explicit-deny contextidentity, resource, endpoint, organization, or KMS policychange only the proven policy layer
configuration exists but behavior failsroute, DNS, security, listener, health, logs, object versiondata path or applicationtest the next boundary and change one control
bill is higher than expectedhours, bytes, requests, AZs, addresses, retentioncost model or retained resourcestop optional work and reconcile the ledger
cleanup is blockeddependency inventory and owning servicedeletion order or immutable stateremove owned dependants in reviewed reverse order

Do not troubleshoot by attaching administrator access, opening administration ports to the internet, disabling encryption, retrying uncontrolled creation, deleting unknown resources, or weakening retention.

Cost, cleanup, and retained state

No AWS resource is created. Close CloudShell and remove or redact downloaded evidence.

Cleanup evidence requires terminal state and an after-inventory. Search related ENIs, public IPv4 addresses, EBS volumes and snapshots, load balancers, target groups, Auto Scaling instances, endpoints, logs, S3 versions and delete markers, backup recovery points, and global IAM roles when they apply. Billing data can lag, so schedule a later review.

Architecture and certification decisions

  • Certification coverage: SAA-C03; SOA-C03; SAP-C02; DOP-C02.
  • Exam mapping: SAA D1-D3.
  • Explain service scope, failure boundary, consistency, recovery, security, operations, and price rather than matching a keyword.
  • Treat availability and durability, encryption and authorization, routing and filtering, health and lifecycle, backup and replication, and discount and capacity as separate concepts.
  • Do not reproduce protected certification questions.

Knowledge check

  1. Does an S3 gateway endpoint provide general internet access?

Expected direction: No. It routes only the supported service prefix list.

  1. Does an interface endpoint remove service authorization checks?

Expected direction: No. Network reachability and authorization remain separate.

  1. Why can one central NAT add cost and risk?

Expected direction: Other-AZ traffic can cross AZs and depends on the NAT gateway AZ.

  1. What must a cost comparison include?

Expected direction: Hours, bytes, AZ placement, endpoint count, transfers, request costs, operations, and availability.

Completion gate and assessment

AreaPointsPassing evidence
Requirement and model15Correct scope, terminology, and final outcome
Console evidence15Current path and interpreted fields
CLI or API evidence15Scoped command, expected result, and limitations
Behavior or decision exercise20Reproducible result or defensible architecture reasoning
Troubleshooting15Original symptom, hypothesis, one change, retest, rollback
Security and cost10Least privilege, data protection, current price dimensions
Cleanup and handoff10Terminal-state proof or approved retained-state record

Pass at 80 out of 100 with no critical safety failure. A missing practical artifact, unexplained output, unsafe access, destructive action outside the owned scope, unplanned billed resource, or false cleanup claim requires remediation and a changed retest.

Official sources

Advertisement