> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configure NAT Instance and Stream Web Logs to CloudWatch Using CloudWatch Agent

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Lab Details

1. In this lab, you will set up an AWS NAT instance within a Virtual Private Cloud (VPC) to provide secure outbound internet access for instances in private subnets. Additionally, you will install and configure the CloudWatch Agent on a private instance to stream live web server logs to AWS CloudWatch, allowing you to monitor web activity in real time.

2. Duration: 1 hour.

3. AWS Region: **US East (N. Virginia) us-east-1**

### Introduction

#### What is NAT Instance ?

1. A **Network Address Translation (NAT) instance** is an EC2 instance configured to allow instances in a **private subnet** within an AWS Virtual Private Cloud (VPC) to access the internet. However, the private instances remain secure, as they do not have direct inbound internet access.
2. In a typical AWS setup, public subnets have direct internet access through an Internet Gateway, while private subnets do not. The NAT instance bridges this gap by providing internet access to the private subnet instances for activities like software updates or accessing external APIs, while still keeping them hidden from direct inbound internet traffic.
3. By disabling the source/destination check on the NAT instance and enabling IP forwarding, the NAT instance can forward traffic between the private instances and the internet, making it a secure and scalable solution for scenarios where internet access is needed for private instances without exposing them to direct external access.

#### What is Nginx?

Nginx is a powerful, open-source web server and reverse proxy renowned for its ability to handle high volumes of concurrent connections efficiently. It is commonly used for:

* Delivering both static and dynamic web content
* Distributing client requests across multiple backend servers as a load balancer
* Routing traffic as a reverse proxy to improve performance, scalability, and security

#### Lab Feature :

This lab focuses on configuring a NAT instance within an AWS Virtual Private Cloud (VPC) environment and setting up monitoring by using the CloudWatch Agent to stream live web server logs to AWS CloudWatch.

#### Benefits:

**1.Understanding NAT Instances:**

* Learn how to configure NAT (Network Address Translation) for private EC2 instances to enable outbound internet access without exposing them to the internet directly.

**2. AWS VPC and Subnet Setup:**

* Understand how to create a VPC with public and private subnets, as well as configuring internet gateways and route tables for proper routing.

**3. EC2 Instances Deployment:**

* Gain hands-on experience deploying EC2 instances in both public and private subnets, configuring security groups, and setting up key pairs for secure access.

**4. NAT Instance Configuration:**

* Convert an EC2 instance into a NAT instance by disabling source/destination checks and configuring IP forwarding, enabling private instances to access the internet.

**5. Cloud Watch Agent Installation and Setup:**

* Learn how to install the CloudWatch Agent on a private instance, configure it, and view web server logs in AWS CloudWatch.

### Architecture Diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/001.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=43d5b7aea4d12e807c2820962e95f1c4" alt="" width="2660" height="778" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/001.png" />

### Task Details :

1. Sign in to the AWS Management Console.
2. VPC and Subnet Setup
3. Launch EC2 instances within this VPC
4. Enable NAT Configuration for EC2 Instance
5. install Nginx (Webpage) in the Private Instance
6. Install and Configure CloudWatch Agent

#### Launching Lab Environment:

1. To launch the lab environment, click on the Start Lab button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the Lab is started, you will be provided with IAM username, Password, Access Key, and Secret Access Key.

> Note : You can only start one lab at any given time

## Lab guide

### Lab Steps

#### Task 1 : Sign in to AWS Management Console

1. Click On the **Open Console** Button, And You Will Get Redirected To AWS Console In A New Browser Tab.
2. On The AWS Sign-In Page,
3. Leave The **Account ID** As Default. Never Edit/Remove The 12 Digit Account ID Present In the AWS Console. Otherwise, You Cannot Proceed with the Lab.
4. Now Copy Your **User Name** And **Password** In the Lab Console to the **IAM Username and Password** In AWS Console and Click On the **Sign in** Button.
5. Once Signed in to the AWS Management Console, Make the Default AWS Region As **US East (N. Virginia) Us-East-1**.

#### Task 2 : VPC and Subnet Setup

1. In the AWS Management Console, you can find the **VPC service** by clicking on the “Services” dropdown at the top and type VPC in the search bar. Then, select the VPC service from the search results.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/002.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=35dc51d7706d3c0a2f95022c23eaecbd" alt="" width="445" height="483" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/002.png" />

2. Once you're in the VPC service, you'll see the option to create a new VPC on the side menu or by clicking on the **create VPC button** and VPC only.

3. Create a new VPC: Name:  **Nat\_vpc**

4. Specify an IPv4 CIDR block for your VPC **(10.0.0.0/16)** in the IPv4 CIDR block field.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/003.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=778fd4cf5e95321240f7ef4d4a3afb9e" alt="" width="939" height="550" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/003.png" />

5. Click on the Create VPC button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/004.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=a88666ccd70940138235a0cb7a9f1c60" alt="" width="939" height="245" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/004.png" />

> **Note :** Kindly Ignore the error message if anything popped up!

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/005.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=daaf1e7d7cda18f19bac02cda6415a75" alt="" width="1214" height="238" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/005.png" />

6. Within your newly created VPC, you'll need to create two subnets: one public and one private.

7. To create a subnet, go to the subnets section in the VPC service and click on the **Create Subnet** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/006.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=bed6762b611a937e54e80a68648d7ab0" alt="" width="1464" height="328" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/006.png" />

8. Click the VPC which we created before i.e., **Nat\_vpc**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/007.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=e431ec89d40e6676ecd97f5428b90bba" alt="" width="967" height="307" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/007.png" />

9. Specify the VPC you just created, the CIDR block for the subnet

* Subnet Name: **PublicSubnet**
* Choose Availability zone **“us-east-1a”**
* IPv4 subnet CIDR block: **10.0.1.0/24**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/008.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=8a9e247135f9f5090323e729b08d4cfa" alt="" width="939" height="566" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/008.png" />

10.scroll down click add  **“Add new Subnet”**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/009.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=7dc87997dd3f430f6a5e4b503aa05b4c" alt="" width="721" height="250" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/009.png" />

11. Now we are going to create the same steps,

* Subnet name: **PrivateSubnet**
* Choose Availability zone **“us-east-1a”**
* subnet CIDR block: **10.0.2.0/24**
* Click  **Create Subnet .**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/010.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=c98f42b8c6c588686b8b6e511bd802a7" alt="" width="939" height="614" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/010.png" />

12. Configure the route tables and internet gateway for the public subnet

13. For the public subnet to have internet access, you'll need to configure the route table and attach an internet gateway.

14. Go to the Route Tables section in the VPC service and create a new route table for the public subnet.

* Route Table Name:  **“Nat\_public\_rt”**
* Select vpc  : **“Nat\_vpc”**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/011.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=d6a1aa192319b23655bcf2b948a634e5" alt="" width="1455" height="553" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/011.png" />

15. Click **Subnet associations** then  **“Edit subnet associations”**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/012.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=bfae2d9d832a8eabf39de1999fc0be9a" alt="" width="1210" height="492" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/012.png" />

16. Select **PublicSubnet**  then click  **Save associations .**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/013.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=d813271d4a2dc83eb8538d65d33c7def" alt="" width="1454" height="444" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/013.png" />

17. Next, go to the Internet Gateways section and create a new internet gateway.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/014.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=aa0082926ba74d83f2e6b65edc17d307" alt="" width="362" height="345" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/014.png" />

* Internet Gateway Name: **My-Internet-Gateway**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/015.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=fc4faeb0dc82070f8189a3fd3a2f6518" alt="" width="939" height="518" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/015.png" />

18. Once Internet gateway is created attach it the VPC that you have created.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/016.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=a17d9e3b26ff3dc067ed1d576f746183" alt="" width="939" height="300" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/016.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/017.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=96a109c2ac28b6b762fc53f5feb33594" alt="" width="939" height="254" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/017.png" />

19. In the **”Nat\_public\_rt“** route table, click on Edit routes, then add your internet gateway. The destination should  be (0.0.0.0/0), and the target should be the internet gateway.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/018.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=8f2ac159e4c0a2dafbc02e506e31d501" alt="" width="1456" height="410" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/018.png" />

20. Again create a route table for “PrivateSubnet”

* Route Table Name:  **“private\_rt”**
* Select vpc  : **“Nat\_vpc”**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/019.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=b92cff1420c194a0e91742a0ed3b46bc" alt="" width="1452" height="565" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/019.png" />

21. Click **Subnet associations** then  **“Edit subnet associations”**

22. Select **PrivateSubnet**  then click **Save associations.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/020.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=c1969a41632d214bd86be3de8e6ef83a" alt="" width="1451" height="435" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/020.png" />

#### Task 3 : Launch EC2 instance within this VPC

1. Navigate to EC2 by clicking on the Services menu in the top, then click on EC2 in the Compute section.

2. In the EC2 service, you'll see a left-hand side menu. Click on the Instances option, and then click on the Launch Instances button to start the process of creating a new EC2 instance.

3. Name: Enter **NAT\_instance**

* Choose **“Amazon Linux 2023 AMI”**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/021.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=830c0ecc7e606fc6fb05d053592f3e64" alt="" width="970" height="220" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/021.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/022.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=db48f743ac221b7ea807f8427882e3e3" alt="" width="921" height="537" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/022.png" />

4. For Instance Type: Select **t2.micro**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/023.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=2e53be14deaa267ea2a1d0b237f4e195" alt="" width="939" height="327" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/023.png" />

5. You'll need to create a key pair to securely connect to your EC2 instances. Select the Create a new key pair option.

6. For Key pair(login): Select Create a new key pair Button

* Key pair name: **WhizKey**
* Key pair type: **RSA**
* Private key file format: **.pem**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/024.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=0b466dbb459d1757b52dc9d768ce06f3" alt="" width="939" height="962" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/024.png" />

7. Make sure to select the **Nat\_vpc** and **public subnet** we created earlier\*\*.\*\*

8. In Network Settings Click on Edit Button:

* Auto-assign public IP: **Enable**
* Select **Create security group**
* Security group name: **“NaT\_ins\_sg”**
* Description: **“Security Group to allow traffic to EC2 “**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/025.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=76d47f583997ddd175d4a9366bab6363" alt="" width="908" height="563" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/025.png" />

9. We will now add the security group rules. SSH will already be present there.

* Click to add rules:

  * For **HTTP**: Set the Source type  to **0.0.0.0 (Anywhere)**
  * For **HTTPS**: Set the Source to  **10.0.0.0/16**
  * For **All ICMP-IPv4**: Set the Source to **10.0.0.0/16**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/cFGhMl2S4kekNdRt/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/026.png?fit=max&auto=format&n=cFGhMl2S4kekNdRt&q=85&s=2f4490a3f5a2dfe19c1bec34d20de3c8" alt="" width="811" height="713" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/026.png" />

10. Click Launch Instance.

11. Repeat the steps to launch another instance, ensuring it's in the same VPC but in the **private subnet.**

12. To create the second EC2 instance, repeat the same **steps 2-7** and make sure to select the key pair which we created before.

13. Name: Enter  **“Private\_ins”**

14. Select the Same VPC and choose **private subnet**.

15. Auto assign Public IP - **Disable**

16. Create a new security group for this instance as **private\_ins\_sg,** allowing inbound traffic from the first instance's security group.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/027.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=cc0452bf08eee378f824318256565a48" alt="" width="887" height="563" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/027.png" />

17. In the **Inbound Security Group Rules, leave** the **default** settings as they are and  **add new rule** For **HTTP**: Set the Source to **10.0.0.0/16**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/028.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=bac5b967825b7984c581db0922fe8403" alt="" width="939" height="612" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/028.png" />

18. Click **Launch Instance**.

#### Task 4 : Enable NAT Configuration for EC2 Instance

In this task, we will convert a normal EC2 instance into a NAT instance.

1. Select the NAT instance, go to the **Actions** menu, then choose **Networking** and click on **Change Source/Destionation Check. Enable** the Save option and Click on **Save** Opti.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/029.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=0c989b0ccfcc133a284ac66694af82fe" alt="" width="939" height="429" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/029.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/030.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=c1e846e6f7bd7722eaa4783cb588d3eb" alt="" width="837" height="533" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/030.png" />

2. Open your Local terminal and navigate to the location where your **.pem** file is stored.

```
chmod 400 "WhizKey.pem"
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/031.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=8f78eebca1a6ab8eccb402faab535e61" alt="" width="743" height="50" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/031.png" />

3. Then, Upload your **.pem** key from your local machine to the EC2 NAT instance using the following

Command:

```
scp -i WhizKey.pem  WhizKey.pem  ec2-user@<ec2-Nat-instance-public-ip>:/home/ec2-user/
```

* Replace the **\<ec2-Nat-instance-public-ip>** and the **Key pair name** accordingly.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/032.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=1a2935d12fd76596095b0ee37a670c9d" alt="" width="1458" height="234" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/032.png" />

4. Navigate to VPC and Go to **Route table** Section. Select **private\_rt.**

5. Select **Routes** Option and click **Edit Routes** Option.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/033.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=069c8af1ae9dc314a83e8faddfc934d3" alt="" width="1448" height="633" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/033.png" />

6. Click **Add route**

* Destination : **0.0.0.0/0**
* Target : **Instance - Choose Nat instance**
* Click “Save  changes “

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/034.gif?s=3ff746789a9d06c515c628b42b893fb1" alt="" width="1280" height="431" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/034.gif" />

7. Now, Navigate to EC2, Connect the **Nat\_instance**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/035.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=f97447d741336817b64376b3f4341ff2" alt="" width="939" height="404" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/035.png" />

8. Copy paste the command on NAT instance :

* Enable IP forwarding :

```
sudo dnf update -y
```

```
echo 'net.ipv4.ip_forward=1' | sudo tee /etc/sysctl.d/custom-ip-forwarding.conf
```

```
sudo sysctl -p /etc/sysctl.d/custom-ip-forwarding.conf
```

* Setting up ip-tables for NAT (correct interface!)

9. Check correct interface by the below command:

```
ip a
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/036.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=2938debcd2e8df5260991c2b45d462a4" alt="" width="1430" height="431" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/036.png" />

> **Note :**  Replace enX0 with your actual network interface (e.g., enX0, ens5,..). Run ip a to confirm your interface name before applying the below code.

```
sudo yum install iptables-services -y
sudo systemctl enable iptables
sudo systemctl start iptables
sudo iptables -t nat -A POSTROUTING -o enX0 -j MASQUERADE # Replace enX0 with your actual interface if different
sudo service iptables save
```

10. Ensure iptables **FORWARD** chain is **ACCEPT** :

```
sudo iptables -P FORWARD ACCEPT
sudo iptables -L FORWARD
# There should NOT be a REJECT rule—remove it if present!
sudo iptables -D FORWARD -j REJECT --reject-with icmp-host-prohibited
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/037.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=d394f39900f8ba88973c83af638a67b0" alt="" width="852" height="136" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/037.png" />

* Paste and run each command one at a time to see where it might hang or fail.

11. Again go to Instance Page and Select **Nat\_Instance.** Click on Connect and Open new tab.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/038.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=f51c8c82acecf529ae1da9871e1782f6" alt="" width="1216" height="215" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/038.png" />

12. Now we doing, Private instance via ssh command which is running inside NAT instance

**Command :** ssh -i "WhizKey.pem" ec2-user@\<Private\_ins-Private-IP-Address>

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/039.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=d9183121ab5e14576c3116afc10a922f" alt="" width="939" height="781" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/039.png" />

13. Check the internet connectivity  in the private\_instance

ping google.com or **ping 8.8.8.8**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/040.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=f5c542effbeacc4802b5effec6b8463e" alt="" width="939" height="845" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/040.png" />

#### Task 5 : Install Nginx (Webpage) in the Private Instance

1. On Private EC2 Instance,

* Install Nginx  ,Copy paste the command

```
sudo dnf update -y
sudo dnf install nginx -y
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/041.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=fac2a36f8d5a93b2e42818135a9654e2" alt="" width="1464" height="665" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/041.png" />

2. Set up a Simple Web Page

```
echo "<h1>Hello from IP Lab Portal</h1>" | sudo tee /usr/share/nginx/html/index.html
```

This replaces the default NGINX homepage with a custom message

3. Enable and Start NGINX

```
sudo systemctl enable nginx
 sudo systemctl start nginx
 sudo systemctl status nginx
```

You should see output like active (running)

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/042.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=5bbabac7b2c247ba51403817e867986c" alt="" width="939" height="339" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/042.png" />

4. Now, Again Login NAT\_instance, Click Connect, Use EC2 Instance Connect (Browser-based SSH), You're now inside the **NAT instance** terminal.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/043.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=97b3a70e9791147302cc3fc8a892da75" alt="" width="1221" height="220" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/043.png" />

We will now create a configuration file that tells NGINX to **forward requests** it receives to the **private EC2 instance** where the actual web page is hosted.

5. The NAT instance will use NGINX to act as a **reverse proxy**, forwarding requests to the private instance.

* Install NGINX :

```
sudo dnf install nginx -y
sudo systemctl enable nginx
sudo systemctl start nginx
sudo systemctl status nginx
```

6. Configure NGINX as a Reverse Proxy

* Open a new NGINX configuration file

```
sudo nano /etc/nginx/conf.d/reverse-proxy.conf
```

7. Paste the following configuration

* Replace 10.0.1.10 with the private IP address of your private\_ins.

```
server {
    listen 80;
    location / {
        proxy_pass http://10.0.1.10;
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
    }
}
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/044.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=530c7cc43ba133930decac6575ef1578" alt="" width="939" height="577" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/044.png" />

8. Save and exit the file .

* Press “CTRL + X”   to save. Press “Y”
* Press **Enter** to confirm the file name.

9. Test the new configuration for syntax errors

```
sudo nginx -t
```

You should see:

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/045.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=8e9e8a27b6b0c718439237214452ee02" alt="" width="899" height="156" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/045.png" />

10. Reload NGINX to apply the changes

```
sudo systemctl restart nginx
```

11. Disable Firewalld and Flush IPTables Rules

* Run these commands on the **NAT instance** to stop firewalld and flush iptables

```
sudo systemctl stop firewalld
sudo iptables -F
sudo iptables -t nat -F
sudo iptables -P INPUT ACCEPT
sudo iptables -P FORWARD ACCEPT
sudo iptables -P OUTPUT ACCEPT
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/046.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=9a98a4d9f6e712217e39cfd1d1dea22f" alt="" width="648" height="152" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/046.png" />

* This will allow traffic on **port 80**, which is necessary for NGINX reverse proxy to work.

12. Any requests made to the **NAT instance's public IP** on port 80 will be **forwarded to the private instance's web server.**

Copy the NAT instance's public IP and open it in your web browser.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/047.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=67ab0753ec96fb126667c8a9c688622a" alt="" width="552" height="139" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/047.png" />

You should see the page served from the private EC2 instance, like:

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/048.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=7ce6a82c7a6688abf824343e4d4b4e26" alt="" width="939" height="252" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/048.png" />

13. Again run this commands, which Setup iptables NAT:

> **Note :** Replace **enX0** with your actual network interface (e.g., **enX0, ens5,..),** Run **ip a** to confirm your interface name before applying the below code.

```
sudo yum install iptables-services -y
sudo systemctl enable iptables
sudo systemctl start iptables
sudo iptables -t nat -A POSTROUTING -o enX0 -j MASQUERADE # Replace ens5 with your actual interface if different
sudo service iptables save
```

####

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/049.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=49efa0aae0f2e647371c90d3291c51f7" alt="" width="689" height="221" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/049.png" />

#### Task 6 : Install and Configure CloudWatch Agent

1. Go to the EC2 section in the AWS Management Console, open the Instances page, and select your **private\_ins** instance.

2. Then open the Actions menu, navigate to the Security settings, choose Modify IAM Role, select the **EC2\_CloudWatch\_Agent\_policy** from the list of available roles, and confirm the update to attach the role to your instance.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/050.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=bfec63cb9dd44b254d0c20da22bf1027" alt="" width="1221" height="267" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/050.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/051.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=0a756e8809d7d16b07a6435263ced907" alt="" width="1444" height="335" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/051.png" />

3. Now we going to Connect to your private EC2 instance again,

Go to EC2 Instance page, Select **Nat\_instance,** and click on **Connect.**

4. Now we doing, Private instance via ssh command which is running inside NAT instance

**Command :** ssh -i "WhizKey.pem" ec2-user@\<Private\_ins-Private-IP-Address>

5. Install CloudWatch Agent

```
sudo dnf install -y amazon-cloudwatch-agent
```

6. Create agent config file

```
sudo mkdir -p /opt/aws/amazon-cloudwatch-agent/etc/
sudo nano /opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.json
```

7. Paste this config (for monitoring NGINX logs)

```
{
  "logs": {
    "logs_collected": {
      "files": {
        "collect_list": [
          {
            "file_path": "/var/log/nginx/access.log",
            "log_group_name": "/nginx/access",
            "log_stream_name": "{instance_id}-access",
            "timezone": "UTC"
          },
          {
            "file_path": "/var/log/nginx/error.log",
            "log_group_name": "/nginx/error",
            "log_stream_name": "{instance_id}-error",
            "timezone": "UTC"
          }
        ]
      }
    }
  }
}
```

8. Save the file

* Press “CTRL + X”   to save. Press “Y”
* Press Enter to confirm the file name.

9. Start the agent with your config

```
sudo /opt/aws/amazon-cloudwatch-agent/bin/amazon-cloudwatch-agent-ctl \\
  -a fetch-config \\
  -m ec2 \\
  -c file:/opt/aws/amazon-cloudwatch-agent/etc/amazon-cloudwatch-agent.json \\
  -s
```

10. Confirm Logs in CloudWatch :

* Go to AWS Console, Search for CloudWatch, Select **Log Groups** in the left panel.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/052.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=8a18c80b58158bf9a4439ec67ba88ad9" alt="" width="939" height="491" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/052.png" />

11. Open the log groups in the CloudWatch console and view the log streams associated with your EC2 instance ID.

* Check whether logs from your EC2 instance are being successfully delivered and displayed in the selected log streams.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/053.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=4ecb5ee6d639d3da08aad216e72bc07e" alt="" width="1456" height="702" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/053.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/O-gZIFgd1R7O2zWY/images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/054.png?fit=max&auto=format&n=O-gZIFgd1R7O2zWY&q=85&s=f4ec073a4a82d14a479d9facdeb38a6f" alt="" width="1450" height="490" data-path="images/labs/configure-nat-instance-and-stream-web-logs-to-cloudwatch-using-cloudwatch-agent/054.png" />

> ##### Do You Know?
>
> While NAT Instances are great for cost-effective small-scale use cases, NAT Gateways are more scalable and highly available. With NAT Gateways, you don't need to manage instances, and AWS automatically scales them. However, NAT Instances are often cheaper in smaller environments and offer full control.

### Completion and Conclusion

1. You have successfully created an VPC
2. You have converted an EC2 instance into a NAT Instance
3. You have successfully pinged Google from the private instance via the NAT instance.
4. You have installed Nignx , Cloud Watch Agent on the private instance
5. You have connected Cloud Watch Agent to AWS CloudWatch,

### End Lab

1. Sign out of AWS Account.
2. You have successfully completed the lab.
3. Once you completed the steps, click on **End Lab** from your IP Lab Portal and wait till the process gets completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Create Amazon Custom VPC** — Check whether a Custom VPC is created or not.
* **Create Amazon Custom VPC Subnet** — Check whether a Subnet is created for the Custom VPC or not.
* **Launch an EC2 Instance** — Check whether an EC2 Instance is launched or not.
* **Check Log Group** — Check whether a CloudWatch log group exists.

## Related help

* [FAQs and Troubleshooting](/aws-saa/support/faqs-and-troubleshooting)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.