How can scaled EC2 instances reach an on-prem service with a stable source IP?
A company is migrating an application to the AWS Cloud. The company has successfully provisioned and tested connectivity between AWS Direct Connect and the company's on-premises data center. The application runs on Amazon EC2 instances across multiple Availability Zones. The instances are in an Auto Scaling group. The application communicates through HTTPS to a third-party vendor's data service that is hosted at the company’s data center. The data service implements a static ACL through explicit allow listing of client IP addresses. A network engineer must design a network solution so that the migrated application can continue to access the vendor’s data service as the application scales. Which solution will meet these requirements with the LEAST amount of ongoing change to the vendor's allow list?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests egress routing to on-premises networks with Direct Connect; the trap is that you don't reconfigure the application to target the NAT gateway—you update the subnet route table so the on-prem destination is routed through the NAT gateway.
When Auto Scaling EC2 instances need to reach an on-prem data service over AWS Direct Connect, a private NAT gateway provides a stable source IP that can be allowed once in the vendor's ACL. The community overwhelmingly agrees that Option A is correct because managed NAT gateways scale automatically and minimize ongoing allow-list changes.
A common mistake is choosing Option B, thinking an ENI can be associated with an Auto Scaling group, but an ENI can be attached to only one instance at a time. As the ASG scales, new instances will have different source IPs, causing continuous updates to the vendor's allow list.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A private NAT gateway provides a fixed private source IP per Availability Zone for outbound traffic to an on-premises data center. The application instances keep using the same data service endpoint, while the VPC route table directs data-service-bound traffic to the NAT gateway, so the vendor only needs to whitelist the NAT gateway's IPs once. As one commenter noted, NAT gateways provide a static IP that can be allowed once in the allow list. Another commenter correctly pointed out that you should modify the route tables, not the application configuration.
Why the Other Options Are Wrong
Option B is invalid because an elastic network interface cannot be shared by an Auto Scaling group; each instance gets its own ENI and source IP, so the allow list would need constant updates as instances scale or recycle. Option C describes a NAT instance, which can work but adds the operational burden of managing EC2 instances and high availability, so it is not the least-maintenance solution. Option D is an inbound load balancer, not an egress proxy; using an ALB would require changing the application's endpoint and would not cleanly solve the source-IP allow-list requirement.
Community Comment Notes
The top comment (3 likes) supports A and clarifies that the application itself should not be changed—the subnet route tables should route to the NAT gateway. Another comment (2 likes) highlights that NAT gateways give a static IP for one-time allow-list configuration. A dissenting comment suggested ALB, but that demonstrates a misunderstanding of ALB's role: ALB is for inbound traffic distribution, not for providing a stable egress source IP to an external on-prem service.
Official Reference
Exam Strategy
For questions that ask for the least ongoing allow-list change in a scaling environment, look for a managed NAT gateway or a fixed-IP egress device positioned in the path. Remember that the routing table does the heavy lifting—the application continues targeting the same service—so you can update the vendor ACL once and keep it stable as the Auto Scaling group expands or contracts.
Related Analysis
Practice All ANS-C01 Questions
Access 137 questions with complete answers and detailed explanations.
View Full ANS-C01 Practice Test →