> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# NAT gateway - AWS VPC Challenge

> Hands-on lab · 30m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/nat-gateway-aws-vpc-challenge" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Prerequisites

1. Good knowledge of AWS services

   * Amazon VPC
   * Amazon EC2
2. Laptop/Desktop
3. Internet Browser
4. Internet connection
5. Windows Users :

   * Download putty and puttygen from this link : [**Download Link**](https://www.chiark.greenend.org.uk/~sgtatham/putty/releases/0.74.html)

### Challenge Instructions

1. **Region** : Make sure to use **us-east-1** region to create all the resources.
2. You will be provided with the requirements of the challenge. If you are new to AWS Cloud, we recommend you go through our hands-on Labs before taking this challenge.
3. Challenge Duration: **90 minutes**

### How to submit the challenge

1. After building the infrastructure, click on the **Validation** button, to validate if you have built the required infrastructure and completed the challenge successfully.
2. Validation status

   * **Success** - You have completed the challenge successfully.
   * **Failed** - You have failed to complete the challenge.
3. Once you have successfully validated the challenge, click on **End Challenge** button.

### Launching Challenge Environment

1. To launch the challenge environment, Click on the **Start Challenge** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the challenge is started, you will be provided with **IAM user name**, **Password**, **Access** **Key**, and **Secret** **Access** **Key**.

> **Note** : You can only start one challenge at any given time

## Lab guide

### Sign in to AWS Management Console

1. Click on the **Open Console** button, and you will get redirected to AWS Console in a new browser tab.
2. On the AWS sign-in page,

* Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
* Now copy your **User Name** and **Password** in the Lab Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.

5. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

### Cloud Challenge Details

In this lab challenge, your Amazon VPC and Amazon EC2 skills are put to the test. You'll be given a requirement and you have to reach it using your knowledge of Amazon VPC and other AWS services. The Lab Challenge helps you understand the real-time scenarios.

**A company ABC launches two EC2 Instances, one to deploy a web application in Public subnet and the other to host another application in Private subnet. As a part of the infrastructure, they need internet access to Private Instance but secured. Now your are a Security Engineer and your challenge is to build the entire Infrastructure from scratch so, that the dev team can host their application in both EC2 Instances.**

**Follow the below instructions to complete this challenge.**

1. Create an Amazon VPC named **MyVPC** with IPv4 CIDR: **10.0.0.0/16** and **No** IPv6 CIDR.
2. Create Public and Private Subnets in MyVPC with IPv4 CIDR **10.0.0.0/24** and **10.0.1.0/24** Respectively.
3. Enable auto-assign public IPv4 address to Public subnet.
4. Create an Internet gateway named **MyIGW** and attach it to **MyVPC**
5. Create a **Public Route table** in MyVPC and add **Internet Gateway** public route in it.
6. Associate the Public Subnet to the Public route Table.
7. Launch an **MyPublicEC2Server** **Instance** in **Public Subnet** with the following configuration:

   1. Select **Amazon Linux 2023 kernel-6.1** AMI
   2. Select t2.micro instance type
   3. Create 8GB gp2 EBS Volume.
   4. Select MyVPC and MYPublicSubnet and Enable Auto-assign Public IP
   5. Create a new security group MyEC2Server\_SG and add SSH port with source Anywhere.
   6. Create a new Key Pair for the Public EC2 Instance.
8. Launch an **MyPrivateEC2Server Instance** in **Private Subnet** with the following configuration:

   1. Select **Amazon Linux 2023 kernel-6.1** AMI
   2. Select t2.micro instance type
   3. Create 8GB gp2 EBS Volume.
   4. Select MyVPC and MYPrivateSubnet and Disable Auto-assign Public IP
   5. Select the Security Group created for first instance.
   6. Create a new Key Pair for the Private EC2 Instance.
9. SSH into **Public EC2 Instance** and test Internet Connectivity.
10. To Perform SSH operation

    * Windows Users use **Putty Software**.
    * Linux/Mac Users use **Terminal**.
11. First SSH into **Public EC2 Instance.**
12. Next SSH into **Private EC2 Instance** from **Public EC2 Instance**  and run the following Linux commands in **Private EC2 Instance**. (Since no internet access is provided for Private EC2 instances, you will not be able to run the bellow)

    ```
    yum -y update
    ```

    ```
    yum install httpd -y
    ```
13. Create a **MyNATGateway**  in **Public** Subnet of VPC **MyVPC** to provide Internet access to the private instance.
14. Update the **Main** Route table (which is different from one created by you) and Add **NAT Gateway** public Route.
15. Now again **SSH** into **Public EC2** Instance and then SSH into **Private EC2** instance from Public EC2 instance.
16. Run the below Linux commands in the **Private EC2 Instance**.

    ```
    yum -y update
    ```

    ```
    yum install httpd -y
    ```
17. If You are able to install httpd in Private Instance, You have completed this Challenge.

#### End Challenge

1. Sign out of the AWS Account
2. You have successfully completed the challenge.
3. Click on **End Challenge** button from IP Lab Portal Challenge console and wait till the process gets completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Create Amazon Custom VPC** — Check whether a Custom VPC is created or not.
* **Create Amazon Custom VPC Subnet** — Check whether a Subnet is created for the Custom VPC or not.
* **Create Amazon Custom VPC Public Route Table** — Check whether a Custom VPC Public Route Table is created and an Internet Gateway route is added or not.
* **Create Internet Gateway** — Check whether an Internet Gateway is created and attached to the Custom VPC or not.
* **Create NAT Gateway** — Check whether a NAT Gateway is created or not.
* **Launch an EC2 Instance** — Check whether an EC2 Instance is launched or not.
* **Validate EC2 Instance Type t2.micro** — Check whether the EC2 instance type is t2.micro.
* **Launch EC2 AMI type Amazon Linux** — Check whether the EC2 instance is launched using an Amazon AMI.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.