A VPC NAT gateway is compliant if created in a virtual private cloud (VPC) within the specified parameter range.
Scenarios
Restrict VPC NAT gateway creation to specified VPCs to prevent invalid resources and reduce management and operational costs.
Risk level
Default risk level: Medium.
You can change the risk level as needed.
Detection logic
-
A VPC NAT gateway is compliant if its VPC is within the specified parameter range.
-
A VPC NAT gateway is non-compliant if its VPC is outside the specified parameter range and requires Remediation.
-
This rule does not apply to Internet NAT gateways, which are marked Not Applicable.
Rule details
|
Parameter |
Description |
|
Rule name |
VPC NAT gateway is created in a specified VPC |
|
Rule identifier |
intranet-nat-gateway-in-specified-vpc |
|
Tags |
NAT, NatGateway |
|
Automatic remediation |
Not supported |
|
Rule trigger mechanism |
Configuration change |
|
Supported resource type |
NAT Gateway |
|
Rule input parameter |
Note
Separate multiple VPC IDs with commas (,). |
Remediation
Create a VPC NAT gateway in a specified VPC. Create and manage VPC NAT gateway instances.