How to Configure NLB and EKS for Source IP Visibility?
A company is building an internet-facing application that is hosted on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster. The company is using the Amazon VPC Container Network Interface (CNI) plugin for Kubernetes for pod networking connectivity. The company needs to expose its application to the internet by using a Network Load Balancer (NLB). The pods that host the application must have visibility of the source IP address that is contained in the original packet that the NLB receives. How should the network engineer configure the NLB and Amazon EKS settings to achieve these goals?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the relationship between NLB target types and Kubernetes service externalTrafficPolicy; the common trap is overlooking that IP target type is needed for direct pod targeting while Local preserves source IP.
To preserve the original source IP when exposing an EKS application via an NLB, use the IP target type and set externalTrafficPolicy to Local. Community consensus confirms this is the required configuration for internet-facing NLBs.
Choosing an instance target type (options B or C) because instance-level routing is a more familiar pattern, but it doesn't guarantee source IP preservation to pods; the IP target type is the correct starting point for pod-level visibility.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Answer A is correct because it combines two essential elements. The IP target type registers pod IPs directly with the NLB, ensuring traffic is delivered straight to the pods without extra node-level forwarding. Setting externalTrafficPolicy to Local preserves the client source IP for packets reaching the pod, satisfying the visibility requirement. Community commenter [1] notes that these two options together meet the requirement.
Why the Other Options Are Wrong
Option B uses instance target type with Cluster policy, which distributes traffic across all nodes and can result in source IP being masked due to SNAT. Option C uses instance target type with Local policy; while Local preserves source IP, the instance target type still routes via the node, which is not the optimal configuration for the CNI plugin and does not match the recommended IP target type. Option D uses IP target type with Cluster policy, which may lose source IP because kube-proxy rewrites packets. Therefore, only A satisfies both conditions.
Community Comment Notes
Comment [1] receives the highest likes and concisely explains the rationale: 'ip target type make sure that NLB send the traffic to pod ips. externalTrafficPolicy to local will help the pod ips to be shown.' Comment [2] provides official AWS documentation links, reinforcing the best practice. Comment [3] reiterates the same answer with a clear summary. The community strongly supports A.
Official Reference
- https://docs.aws.amazon.com/eks/latest/best-practices/load-balancing.html#:~:text=service.beta.kubernetes.io/aws%2Dload%2Dbalancer%2Dnlb%2Dtarget%2Dtype%3A%20ip
- https://docs.aws.amazon.com/eks/latest/best-practices/sgpp.html#:~:text=Kubernetes%20services%20support-,externalTrafficPolicy,-%3Dlocal%20to%20support
Exam Strategy
In the exam, when asked about preserving source IP in EKS, immediately think about pairing IP target type with externalTrafficPolicy: Local. This combination is the AWS best practice for NLB with the CNI plugin.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →