How to Configure NLB and EKS for Source IP Visibility?

A company is building an internet-facing application that is hosted on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. The company is using the Amazon VPC Container Network Interface (CNI) plugin for Kubernetes for pod networking connectivity. The company needs to expose its application to the internet by using a Network Load Balancer (NLB). The pods that host the application must have visibility of the source IP address that is contained in the original packet that the NLB receives. How should the network engineer configure the NLB and Amazon EKS settings to achieve these goals?

  1. Specify the ip target type for the NLB. Set the externalTrafficPolicy attribute to Local in the Kubernetes service specification. Source Reference Answer
  2. Specify the instance target type for the NLSet the externalTrafficPolicy attribute to Cluster in the Kubernetes service specification.
  3. Specify the instance target type for the NLB. Set the externalTrafficPolicy attribute to Local in the Kubernetes service specification.
  4. Specify the ip target type for the NLB. Set the externalTrafficPolicy attribute to Cluster in the Kubernetes service specification.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the relationship between NLB target types and Kubernetes service externalTrafficPolicy; the common trap is overlooking that IP target type is needed for direct pod targeting while Local preserves source IP.

To preserve the original source IP when exposing an EKS application via an NLB, use the IP target type and set externalTrafficPolicy to Local. Community consensus confirms this is the required configuration for internet-facing NLBs.

Choosing an instance target type (options B or C) because instance-level routing is a more familiar pattern, but it doesn't guarantee source IP preservation to pods; the IP target type is the correct starting point for pod-level visibility.

Community Discussion (3 comments)

zanhsieh 👍 1 Selected: A
https://docs.aws.amazon.com/eks/latest/best-practices/load-balancing.html#:~:text=service.beta.kubernetes.io/aws%2Dload%2Dbalancer%2Dnlb%2Dtarget%2Dtype%3A%20ip https://docs.aws.amazon.com/eks/latest/best-practices/sgpp.html#:~:text=Kubernetes%20services%20support-,externalTrafficPolicy,-%3Dlocal%20to%20support
woorkim 👍 1 Selected: A
To expose an internet-facing application with source IP visibility, use the ip target type for the NLB and set the Kubernetes service's externalTrafficPolicy to Local. This configuration ensures that the original source IP address is preserved and visible to the pods.
ArunRav 👍 3 Selected: A
ip target type make sure that NLB send the traffic to pod ips. externalTrafficPolicy to local will help the pod ips to be shown. Combining both of these options will help to meet the requirements.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Answer A is correct because it combines two essential elements. The IP target type registers pod IPs directly with the NLB, ensuring traffic is delivered straight to the pods without extra node-level forwarding. Setting externalTrafficPolicy to Local preserves the client source IP for packets reaching the pod, satisfying the visibility requirement. Community commenter [1] notes that these two options together meet the requirement.

Why the Other Options Are Wrong

Option B uses instance target type with Cluster policy, which distributes traffic across all nodes and can result in source IP being masked due to SNAT. Option C uses instance target type with Local policy; while Local preserves source IP, the instance target type still routes via the node, which is not the optimal configuration for the CNI plugin and does not match the recommended IP target type. Option D uses IP target type with Cluster policy, which may lose source IP because kube-proxy rewrites packets. Therefore, only A satisfies both conditions.

Community Comment Notes

Comment [1] receives the highest likes and concisely explains the rationale: 'ip target type make sure that NLB send the traffic to pod ips. externalTrafficPolicy to local will help the pod ips to be shown.' Comment [2] provides official AWS documentation links, reinforcing the best practice. Comment [3] reiterates the same answer with a clear summary. The community strongly supports A.

Official Reference

Exam Strategy

In the exam, when asked about preserving source IP in EKS, immediately think about pairing IP target type with externalTrafficPolicy: Local. This combination is the AWS best practice for NLB with the CNI plugin.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide