Gives a subnet managed, outbound-only SNAT through static public IPs and is Microsoft's preferred explicit outbound option. Unsolicited inbound connections are never accepted.
Also called Azure NAT Gateway.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains NAT gateway in context, with comparison tables and the common traps.
Terms in this definition
- Subnet
A segment of a VNet's address space from which resources receive private IPs. Azure holds back five addresses per subnet (the first four and the last), leaving 251 usable in a /24 and three in a /29, the smallest IPv4 subnet.
- SNAT
Translating the source address of a flow. Azure Firewall does this automatically to its public IP for outbound internet traffic, and NAT gateway supplies SNAT ports for outbound connections.
Related terms
- Container Apps workload profiles
The default Container Apps environment type, offering Consumption and Dedicated profiles on a subnet of at least /27; unlike the legacy Consumption-only type (/23), it supports UDRs, private endpoints and NAT Gateway egress.
- ILPIP
An instance-level public IP is attached straight to a VM's NIC on a 1:1 basis with no SNAT. If the subnet has a NAT gateway, new outbound flows use that instead, though inbound traffic still arrives via the ILPIP.
- Private subnet
Subnet in which default outbound access is off. Internet access for its VMs must come from a public IP, a NAT gateway or Standard Load Balancer outbound rules.
- Public IP address prefix
A block of contiguous Standard static public IPs held in reserve, by default as large as /28, from which a NAT gateway or load balancer outbound rule can draw extra addresses.
- Secured virtual hub
What you get once Azure Firewall Manager places Azure Firewall, or a SECaaS partner, inside a Virtual WAN hub. Putting a NAT gateway, WAF or Front Door in front is not enough to count.
- SNAT port exhaustion
Failures of outbound connections that occur once a source has no SNAT ports left for new flows to one destination. With NAT gateway, adding public IPs or a prefix resolves it.
- StandardV2 NAT gateway
A zone-redundant SKU of NAT gateway offering flow logs, IPv6 and greater throughput. It needs StandardV2 public IPs or prefixes, and a Standard gateway cannot be upgraded to it.
- Workload profile
Defines the compute that Container Apps run on, either Consumption or one of the Dedicated sizes. The workload profiles environment, now the default, also allows UDRs, private endpoints and NAT Gateway egress.