How can scaled EC2 instances reach an on-prem service with a stable source IP?

A company is migrating an application to the AWS Cloud. The company has successfully provisioned and tested connectivity between AWS Direct Connect and the company's on-premises data center. The application runs on Amazon EC2 instances across multiple Availability Zones. The instances are in an Auto Scaling group. The application communicates through HTTPS to a third-party vendor's data service that is hosted at the company’s data center. The data service implements a static ACL through explicit allow listing of client IP addresses. A network engineer must design a network solution so that the migrated application can continue to access the vendor’s data service as the application scales. Which solution will meet these requirements with the LEAST amount of ongoing change to the vendor's allow list?

  1. Configure a private NAT gateway in the subnets for each Availability Zone that the application runs in. Configure the application to target the NAT gateways instead of the data service directly. Update the data service's allow list to include the IP addresses of the NAT gateways. Source Reference Answer
  2. Configure an elastic network interface in the subnets for each Availability Zone that the application runs in. Associate the elastic network interfaces with the Auto Scaling group for the application. Update the data service's allow list to include the IP addresses of the elastic network interfaces.
  3. Configure an elastic network interface in the subnets for each Availability Zone that the application runs in. Launch an EC2 instance into each subnet. Attach the respective elastic network interfaces to the new EC2 instances. In the application subnet route tables, configure the new EC2 instances as the next destination for the data service. Update the data service’s allow list to include the IP addresses of the elastic network interfaces.
  4. Configure an Application Load Balancer (ALB) in the subnets for each Availability Zone that the application runs in. Configure an ALB-associated target group that contains a target that uses the IP address for the data service. Configure the application to target the ALB instead of the data service directly. Update the data service's allow list to include the IP addresses of the ALBs.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests egress routing to on-premises networks with Direct Connect; the trap is that you don't reconfigure the application to target the NAT gateway—you update the subnet route table so the on-prem destination is routed through the NAT gateway.

When Auto Scaling EC2 instances need to reach an on-prem data service over AWS Direct Connect, a private NAT gateway provides a stable source IP that can be allowed once in the vendor's ACL. The community overwhelmingly agrees that Option A is correct because managed NAT gateways scale automatically and minimize ongoing allow-list changes.

A common mistake is choosing Option B, thinking an ENI can be associated with an Auto Scaling group, but an ENI can be attached to only one instance at a time. As the ASG scales, new instances will have different source IPs, causing continuous updates to the vendor's allow list.

Community Discussion (6 comments)

c1193d4 👍 3 Selected: A
A ... but I'm not ok with "Configure the application to target the NAT gateways instead of the data service directly." => the subnet route tables should be modified ... NOT the application itself.
woorkim 👍 1 Selected: A
By using a private NAT gateway, the solution ensures that the vendor's data service always sees the same IP address, minimizing the need for ongoing updates to the allow list while allowing the application to scale.
cas_tori 👍 1 Selected: A
this is A
[Removed] 👍 2 Selected: A
NAT gateway provide static ip that can be allowed once in allow list
siheom 👍 2 Selected: A
VOTE A
yama_chan 👍 1
The correct answer is D. Considering the simplicity of managing the allow list and the automation of load balancing, option D, using an Application Load Balancer (ALB), is the optimal solution. However, if managing the allow list is not an issue or if direct communication is required due to specific requirements, option B, using an Elastic Network Interface (ENI), is also a strong choice.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A private NAT gateway provides a fixed private source IP per Availability Zone for outbound traffic to an on-premises data center. The application instances keep using the same data service endpoint, while the VPC route table directs data-service-bound traffic to the NAT gateway, so the vendor only needs to whitelist the NAT gateway's IPs once. As one commenter noted, NAT gateways provide a static IP that can be allowed once in the allow list. Another commenter correctly pointed out that you should modify the route tables, not the application configuration.

Why the Other Options Are Wrong

Option B is invalid because an elastic network interface cannot be shared by an Auto Scaling group; each instance gets its own ENI and source IP, so the allow list would need constant updates as instances scale or recycle. Option C describes a NAT instance, which can work but adds the operational burden of managing EC2 instances and high availability, so it is not the least-maintenance solution. Option D is an inbound load balancer, not an egress proxy; using an ALB would require changing the application's endpoint and would not cleanly solve the source-IP allow-list requirement.

Community Comment Notes

The top comment (3 likes) supports A and clarifies that the application itself should not be changed—the subnet route tables should route to the NAT gateway. Another comment (2 likes) highlights that NAT gateways give a static IP for one-time allow-list configuration. A dissenting comment suggested ALB, but that demonstrates a misunderstanding of ALB's role: ALB is for inbound traffic distribution, not for providing a stable egress source IP to an external on-prem service.

Official Reference

Exam Strategy

For questions that ask for the least ongoing allow-list change in a scaling environment, look for a managed NAT gateway or a fixed-IP egress device positioned in the path. Remember that the routing table does the heavy lifting—the application continues targeting the same service—so you can update the vendor ACL once and keep it stable as the Auto Scaling group expands or contracts.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide