An operations team runs IPv6-enabled EC2 instances in private subnets that must download packages from internet repositories over IPv6. The security policy requires that no connection can be initiated from the internet to these instances. What should the team configure?
Choose one.
VPC IPv6 addresses are globally unique and publicly routable, so IPv6 has no NAT. The egress-only internet gateway is the IPv6 construct for outbound-only access: instances can initiate connections out, and all inbound-initiated traffic is blocked.
Routing ::/0 to an egress-only internet gateway gives the instances outbound IPv6 access while its stateful behavior blocks anything the internet initiates. A NAT gateway is wrong because it handles IPv4 only; a standard internet gateway is wrong because it exposes the publicly routable IPv6 addresses to inbound connections; and a gateway endpoint only reaches S3 and DynamoDB, not internet repositories.
- Create an egress-only internet gateway and attach it to the VPC.
- In the private subnets' route tables, add a route sending ::/0 to the egress-only internet gateway.
- Verify security groups and NACLs permit the outbound traffic and (for NACLs) the ephemeral-port return traffic.
- Confirm instances can reach the repositories while inbound IPv6 connection attempts fail.
Exam tip: "IPv6, outbound only" always maps to an egress-only internet gateway — there is no IPv6 NAT.
VPC Networking and Private Connectivity for SOA-C03 — the lesson that teaches this.