A subnet mask is like an IP address, but for only internal usage within a network. Routers use subnet masks to route data packets to the right place. Subnet masks are not indicated within data packets traversing the Internet — those packets only indicate the destination IP address, which a router will match with a subnet.

The internet gateway logically provides the one-to-one NAT on behalf of your instance, so that when traffic leaves your VPC subnet and goes to the internet, the reply address field is set to the public IPv4 address or Elastic IP address of your instance, and not its private IP address.

Internet — ISP Router — Subnet 1 — Router 2 — Subnet 2. As you can see, for devices at subnet 2 to access the Internet, it must pass through subnet 1. Therefore, subnet 1 has to allow traffic from subnet 2 and cannot be a separate private network. In order to have several private networks, your options are: Oct 07, 2016 · Make sure that the private subnet's route table has a default route pointing to the NAT gateway. Note: Ensure that you're not using the same route table for both the private and the public subnet; this will not route traffic to the Internet. Check that you have allowed the required protocols and ports for outbound traffic to the Internet. Subnet mask is a mask used to determine what subnet an IP address belongs to. An IP address has two components, the network address and the host address.

