Help Center/ Config/ User Guide/ Resource Compliance/ Built-In Policies/ NAT Gateway/ Private NAT Gateways Are in Specified VPCs
Updated on 2025-08-25 GMT+08:00

Private NAT Gateways Are in Specified VPCs

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

private-nat-gateway-authorized-vpc-only

Identifier

Private NAT Gateways Are in Specified VPCs

Description

If a private NAT gateway is not in a specified VPC, this gateway is non-compliant.

Tag

nat

Trigger Type

Configuration change

Filter Type

nat.privateNatGateways

Rule Parameters

authorizedVpcIds: VPC IDs. If there are no VPCs specified, all values are allowed. This is an array type parameter. You can include up to 10 VPCs.

Application Scenarios

A VPC is a logically isolated area where you can define virtual networks. You can define security groups, VPNs, IP address segments, and bandwidth for a VPC. This facilitates internal network configuration and management and allows you to change your network in a secure and convenient manner. For details, see the Virtual Private Cloud User Guide.

Solution

When buying a private NAT gateway, select a specified VPC.

Rule Logic

  • If the VPC of a private NAT gateway is not one of the specified VPCs, the private NAT gateway is non-compliant.
  • If the VPC of a private NAT gateway belongs is one of the specified VPCs, the private NAT gateway is compliant.