Gives every resource in a subnet a managed way out to the internet through one or more fixed public IP addresses, while accepting no unsolicited inbound connections. Azure Container Apps can use it only when the environment is a workload profiles one.
Also called NAT.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Azure NAT Gateway in context, with comparison tables and the common traps.
Terms in this definition
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- Azure Container Apps
Container hosting built on KEDA where Azure runs the underlying cluster for you; apps scale automatically and can be zone-redundant.
- Azure Machine Learning environment
Versioned asset that pairs a Docker image with a pip or conda specification, so every job or deployment using it gets identical dependencies. You point to it by name plus a version number, or by name with @latest.
- Workload
Also called an experience: a Fabric toolset aimed at one job role, e.g. Data Factory, Data Engineering, Data Warehouse, Real-Time Intelligence or Power BI. Each keeps its data in OneLake.
Related terms
- Access restrictions
Allow and deny rules for inbound App Service traffic, matched on IP range, service tag or subnet. They can, for instance, restrict an app to a corporate NAT's public addresses.
- Active Standby
An NSX gateway HA mode where one Edge node handles traffic while a second waits to take over. Stateful services such as NAT, VPN, load balancing and the stateful firewall depend on it, and VCF Automation 9.0 expects its Tier-0 to be set up this way.
- DNAT
Destination NAT. Inbound packets get a new target address, letting an outside IP map to a workload inside. On NSX this requires an active-standby gateway.
- Frontend IP configuration
The public or private IP address on a load balancer that clients connect to. Inbound NAT rules and load-balancing rules point at it.
- IP configuration
NIC setting that carries a private IP, dynamic or static, and optionally a public one. NAT rules and backend pools on a load balancer refer to it.
- LAN
A local area network covering a single site. By default, Delivery Optimization downloads share content between peers that sit behind the same NAT.
- NSX
Software that handles networking and security across VCF, covering firewalling, load balancing, NAT, VPCs, overlay segments and Tier-0/1 gateways.
- NSX Edge cluster
Pool of Edge nodes that runs centralised gateway services, for example VPN, NAT, load balancing and north-south routing. VCF adds it to a workload domain after that domain has been built.