All Products
Search
Document Center

NAT Gateway:ModifyNatGatewayAttribute

Last Updated:Aug 27, 2026

Modifies the name and description of a NAT gateway.

Operation description

Description

This operation queries an Internet NAT gateway or a virtual private cloud (VPC) NAT gateway. In this topic, NAT gateway refers to both types.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

No authorization for this operation. If you encounter issues with this operation, contact technical support.

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

Yes

The region ID of the NAT gateway.

Call the DescribeRegions operation to query the most recent region list.

cn-hangzhou

NatGatewayId

string

Yes

The ID of the NAT gateway.

ngw-2ze0dcn4mq31qx2jc****

Name

string

No

The name of the NAT gateway.

The name must be 1 to 128 characters in length and cannot start with http:// or https://.

nat123

Description

string

No

The description of the NAT gateway.

The description must be 1 to 128 characters in length, and cannot start with http:// or https://.

Description

IcmpReplyEnabled

boolean

No

Specifies whether to enable the Internet Control Message Protocol (ICMP) non-retrieval feature. Valid values:

  • false (default)

  • true

true

EipBindMode

string

No

The EIP association mode for the NAT gateway. Valid value: empty or NAT (NAT mode).

Note
  • You can only change MULTI_BINDED to NAT. You cannot change NAT to MULTI_BINDED. For more information about the MULTI_BINDED mode, see CreateNatGateway.

  • When you change the association mode, your network may be interrupted for seconds. The duration increases with the number of EIPs. You can change the association mode for at most 5 EIPs at the same time. We recommend changing the association mode during off-peak hours.

  • After the association mode is changed to NAT, the Internet NAT gateway is compatible with an IPv4 gateway. If an EIP is associated with a NAT gateway in NAT mode, the EIP occupies a private IP address of the vSwitch to which the NAT gateway belongs. Ensure the vSwitch has sufficient private IP addresses for EIPs to be associated with the NAT gateway.

NAT

EnableSessionLog

boolean

No

Specifies whether to enable session logging. Valid values:

  • true: Session logging is enabled.

  • false: Session logging is disabled.

true

LogDelivery

object

No

The session log configuration.

LogDeliveryType

string

No

The session log delivery type. Valid value: sls (Alibaba Cloud Log Service).

sls

LogDestination

string

No

The session log delivery destination. Format: acs:log:${regionName}:${projectOwnerAliUid}:project/${projectName}/logstore/${logstoreName}

acs:log:cn-hangzhou:0000:project/nat_session_log_project/logstore/session_log_test

Response elements

Element

Type

Description

Example

object

The request ID.

RequestId

string

The request ID.

AB5F62CF-2B60-4458-A756-42C9DFE108D1

Examples

Success response

JSON format

{
  "RequestId": "AB5F62CF-2B60-4458-A756-42C9DFE108D1"
}

Error codes

HTTP status code

Error code

Error message

Description

400 UnsupportedFeature.PrivateLinkMode The feature of %s is not supported. The feature of reverse access is not supported.
400 IncorrectStatus.NATGW NATGW status is invalid. The NAT gateway is in an invalid state.
400 ExclusiveParam.%sAnd%s The param of %s and %s are mutually exclusive. You cannot specify %s and %s at the same time.
400 IncorrectStatus.NatGateway The status of natgateway is incorrect. The status of the NAT gateway is invalid.
400 DependencyViolation.PrivateLinkMode The specified resource of %s depends on %s, so the operation cannot be completed. The %s resource depends on %s.
400 UnsupportedFeature.IcmpReplyEnabled The feature of IcmpReplyEnabled is not supported. The value of IcmpReplyEnabled cannot be modified.
400 InvalidParams.NotNull The parameter must not be null, name or description or icmpReplyEnabled The name, description, and ICMP proxy cannot be empty at the same time.
400 InvalidParameter.Name.Malformed The specified Name is not valid.
400 InvalidParameter.Description.Malformed The specified Description is not valid.
400 UnsupportedFeature.IndirectConvertForVpcNat The VPC NAT gateway is not support to change EIP bond type. The error message returned because the value of the EipBindMode parameter cannot be modified for a VPC NAT gateway.
400 UnsupportedFeature.NormalNatModifyEipBindMode The normal NAT gateway is not support to change EIP bond type. The value of EipBindMode cannot be modified for a standard NAT gateway.
400 OperationDenied.EipBondTypeIsAlreadyNAT The EIP bond type is already NAT type. EipBindMode is already set to NAT.
400 UnsupportedFeature.IndirectConvertForFwNat The security protection enabled NAT gateway is not support change EIP bond type. The value of EipBindMode cannot be modified for an Internet NAT gateway for which the security protection feature is enabled.
400 QuotaExceeded.EipNumForModifyEipBondType The quota of %s is exceeded, binded: %s, quota: %s. The number of allowed EIPs reaches the upper limit when you modify the EIP association type.
400 ResourceNotEnough.SwitchAvailableIps The available private Ip number is not enough in your subnet. The number of private IP addresses in the subnet is insufficient.
400 UnsupportedFeature.VpcNatSecurityProtectionEnabled The VPC NAT gateway is not supported to enable security protection. You cannot enable security protection for the VPC NAT gateway.
400 OperationDenied.NatGatewayStatusInvalid The NAT gateway status is invalid. The status of the NAT gateway does not support the operation.
400 OperationDenied.EipStatusInvalid The NAT gateway has EIP in invalid status. The EIP associated with the NAT gateway is in an invalid state.
400 OperationDenied.SnatEntryStatusInvalid The NAT gateway has SNAT entry in invalid status. The SNAT entry associated with the NAT gateway is in an invalid state.
400 OperationDenied.DnatEntryStatusInvalid The NAT gateway has DNAT entry in invalid status. The DNAT entry associated with the NAT gateway is in an invalid state.
400 UnsupportedFeature.MutilBindedTypeNatEnableFw The NAT with Mutil-Binded Eip bind type is not support enable firewall. You cannot enable firewall for the NAT gateway because EIPs are associated with the NAT gateway in Multi-Binded mode.
400 Forbidden.FinancialLocked The instance is locked due to outstanding payments. The instance has overdue payments.
400 OperationFailed.PrivateLinkMode The NAT gateway is not support to change PrivateLinkMode. The NAT gateway is not support to change PrivateLinkMode.
400 IllegalParam.SessionLogDeliveryDestination The specified Delivery Destination is illegal. The specified Delivery Destination(SessionLogDeliveryDestination) is illegal.
400 OperationFailed.LogDeliveryIsUnAuthorized Operation failed because the user is not authorized to deliver NAT session log. The operation failed because you did not grant the NAT session log delivery permission
400 IllegalParam.SessionLogDeliveryType The specified Delivery Type is illegal. The specified delivery type parameter SessionLogDeliveryType is illegal.
400 UnsupportedFeature.EnableSessionLog The feature of EnableSessionLog is not supported. This instance does not support opening NAT Gateway session logs.
500 OperationFailed.ConfigSessionLog Failed to configure session log due to a temporary failure of the server. Failed to configure session log due to an internal service error.
403 Forbidden.ModifyEipBondType Authentication is failed for modify EIP bond type. The value of EipBindMode cannot be modified.
404 InvalidRegionId.NotFound The specified RegionId does not exist in our records.
404 InvalidNatGatewayId.NotFound The specified NatGatewayId does not exist in our records.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.