Network Address Translation Gateway - enables private subnet resources to access the internet for outbound traffic while blocking inbound connections. Available as AWS NAT Gateway, Azure NAT Gateway, GCP Cloud NAT, and OCI NAT Gateway. Like a secure mailroom that sends packages out but rejects unsolicited deliveries.
Database servers in private subnets use a NAT Gateway to download security patches and call external APIs while remaining protected from direct internet access.
Explore real-world architectures from our community that use NAT Gateway: