---
type: resource-type
title: NatGateway
description: aws resource type AWS::EC2::NatGateway
name: NatGateway
lexicon: aws
resource_type: AWS::EC2::NatGateway
---
`AWS::EC2::NatGateway`, a resource type of the aws lexicon.

## Properties

- `AllocationId` (`string`, optional): [Public NAT gateway only] The allocation ID of the Elastic IP address that's associated with the NAT gateway. This property is required for a public NAT gateway and cannot be specified with a private NAT gateway.
- `AutoProvisionZones` (`string`, optional)
- `AutoScalingIps` (`string`, optional)
- `AvailabilityMode` (`string`, optional): Indicates whether this is a zonal (single-AZ) or regional (multi-AZ) NAT gateway. A zonal NAT gateway is a NAT Gateway that provides redundancy and scalability within a single availability zone. A regional NAT gateway is a single NAT Gateway that works across multiple availability zones (AZs) in your VPC, providing redundancy, scalability and availability across all the AZs in a Region. For more information, see [Regional NAT gateways for automatic multi-AZ expansion](https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateways-regional.html) in the *Amazon VPC User Guide*.
- `AvailabilityZoneAddresses` (`NatGateway_AvailabilityZoneAddress[]`, optional): For regional NAT gateways only: Specifies which Availability Zones you want the NAT gateway to support and the Elastic IP addresses (EIPs) to use in each AZ. The regional NAT gateway uses these EIPs to handle outbound NAT traffic from their respective AZs. If not specified, the NAT gateway will automatically expand to new AZs and associate EIPs upon detection of an elastic network interface. If you specify this parameter, auto-expansion is disabled and you must manually manage AZ coverage. A regional NAT gateway is a single NAT Gateway that works across multiple availability zones (AZs) in your VPC, providing redundancy, scalability and availability across all the AZs in a Region. For more information, see [Regional NAT gateways for automatic multi-AZ expansion](https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateways-regional.html) in the *Amazon VPC User Guide*.
- `ConnectivityType` (`string`, optional): Indicates whether the NAT gateway supports public or private connectivity. The default is public connectivity.
- `EniId` (`string`, optional)
- `MaxDrainDurationSeconds` (`number`, optional): The maximum amount of time to wait (in seconds) before forcibly releasing the IP addresses if connections are still in progress. Default value is 350 seconds.
- `NatGatewayId` (`string`, optional)
- `PrivateIpAddress` (`string`, optional): The private IPv4 address to assign to the NAT gateway. If you don't provide an address, a private IPv4 address will be automatically assigned.
- `RouteTableId` (`string`, optional)
- `SecondaryAllocationIds` (`string[]`, optional): Secondary EIP allocation IDs. For more information, see [Create a NAT gateway](https://docs.aws.amazon.com/vpc/latest/userguide/nat-gateway-working-with.html) in the *Amazon VPC User Guide*.
- `SecondaryPrivateIpAddressCount` (`number`, optional): [Private NAT gateway only] The number of secondary private IPv4 addresses you want to assign to the NAT gateway. For more information about secondary addresses, see [Create a NAT gateway](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-creating) in the *Amazon Virtual Private Cloud User Guide*. ``SecondaryPrivateIpAddressCount`` and ``SecondaryPrivateIpAddresses`` cannot be set at the same time.
- `SecondaryPrivateIpAddresses` (`string[]`, optional): Secondary private IPv4 addresses. For more information about secondary addresses, see [Create a NAT gateway](https://docs.aws.amazon.com/vpc/latest/userguide/vpc-nat-gateway.html#nat-gateway-creating) in the *Amazon Virtual Private Cloud User Guide*. ``SecondaryPrivateIpAddressCount`` and ``SecondaryPrivateIpAddresses`` cannot be set at the same time.
- `SubnetId` (`string`, optional): The ID of the subnet in which the NAT gateway is located.
- `Tags` (`NatGateway_Tag[]`, optional): The tags for the NAT gateway.
- `VpcId` (`string`, optional): The ID of the VPC in which the NAT gateway is located.

## Attributes

- `AutoProvisionZones`
- `AutoScalingIps`
- `EniId`
- `NatGatewayId`
- `RouteTableId`
