Home icon

Routing UDP to on-premises Network Load Balancer targets

Networking & Content Delivery Blog



This article explains why UDP traffic to on-premises Network Load Balancer targets fails and provides a solution using EC2 proxy instances with kernel NAT.

  • Network Load Balancer preserves client IP but cannot rewrite return packets from out-of-VPC targets, breaking UDP sessions
  • VPC Flow Logs and health checks appear normal while the return path silently fails for UDP protocols
  • Deploy one EC2 proxy instance per Availability Zone running nftables to perform source NAT
  • Proxy rewrites source IP to its own VPC private IP, ensuring replies return through the load balancer
  • Configure security groups, network ACLs, and health checks to validate end-to-end connectivity
  • Concurrency limits apply per proxy; transit gateway attachments require subnets in each proxy AZ

Kernel NAT proxies enable UDP services on-premises to work behind AWS Global Accelerator and Network Load Balancers by fixing the asymmetric return path.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Sep 2
2026
Reduce Traffic Interruptions with Gateway Load Balancer TCP Reset
Sep 22
2026
Adding custom domains to AWS Lambda MicroVMs with Application Load Balancer
Nov 19
2025
Network Load Balancers now support Weighted Target Groups
Sep 8
2026
How AWS unified its routing control plane to improve network availability and performance

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.