All Products
Search
Document Center

NAT Gateway:Diagnose an Internet NAT Gateway instance

Last Updated:Apr 01, 2026

When your Internet NAT gateway has connectivity or configuration issues, run an instance diagnostic to identify the root cause. The diagnostic checks 13 items across connectivity, configurations, capacity diagnostics, and cost diagnostics — and surfaces actionable suggestions for any detected exceptions.

Only Internet NAT gateways support instance diagnostics. VPC NAT gateways are not supported.

Prerequisites

Before you begin, make sure you have:

The first time you run a diagnostic, the system automatically creates the AliyunServiceRoleForNis service-linked role. For more information, see Service-linked roles.

Check the baseline configuration

Before running the diagnostic tool, verify that your NAT gateway meets the minimum working configuration:

  • An elastic IP address (EIP) is associated with the gateway

  • A route pointing to the Internet NAT gateway exists in your Virtual Private Cloud (VPC)

  • The gateway is in a healthy state (not expired or suspended)

If any of these conditions are not met, resolve them first. The diagnostic tool will also flag them, but correcting them upfront reduces diagnostic time.

Run a diagnostic

  1. Log on to the NAT Gateway console.

  2. On the Internet NAT Gateway page, find the gateway you want to diagnose and click Diagnose in the Diagnose column.

  3. In the Instance Diagnostics panel, review the progress, summary, and details of the diagnostic.

    • If an exception is detected, the affected diagnostic item appears in the panel. Click the item to view its details and suggested actions.

    • To see all supported diagnostic items — not just items with exceptions — go to the Diagnostic Item Details section and select Show All Diagnostic Items. Expand any item to view its details.

  4. (Optional) Click Go to the NIS console to view diagnostic records to open the NIS console and review the full history of diagnostic tasks.

Diagnostic items

The following table lists all 13 diagnostic items supported for Internet NAT gateways.

CategoryDiagnostic itemWhat it checks
Connectivity diagnosticsPacket Dropped Due to Capacity LimitWhether packets are dropped due to capacity limits
Connectivity diagnosticsSNAT Source Port AllocationWhether the SNAT source port is allocated
ConfigurationsRoute MissingWhether routes pointing to the Internet NAT gateway exist in the VPC
ConfigurationsInstance StatusWhether the Internet NAT gateway is in a healthy state
ConfigurationsNAT ConfigurationsWhether SNAT entries and DNAT entries are configured
ConfigurationsEIP StatusWhether an EIP is associated with the gateway
ConfigurationsDNAT and Security Group ConfigurationWhether the security group rules match the DNAT configuration
ConfigurationsDNAT ConflictsWhether DNAT entries conflict with backend EIPs
ConfigurationsIPv4 Gateway CompatibilityWhether the IPv4 gateway is compatible with the NAT configuration
Capacity DiagnosticsRate of NAT Gateway Traffic ProcessingWhether the traffic processing rate is within normal range
Capacity DiagnosticsUsage of Concurrent Connections of NAT GatewayWhether concurrent connection usage is within normal range
Cost DiagnosticsAlerts for ExpirationWhether the gateway expires within the next 15 days
Cost DiagnosticsAlerts for Overdue PaymentsWhether the gateway has overdue payments