View a markdown version of this page

Dual Stack Internal Application and Network Load Balancers - Dual Stack and IPv6-only Amazon Amazon VPC Reference Architectures

Dual Stack Internal Application and Network Load Balancers

Publication date: June 23, 2022 (Diagram history)

This architecture shows how to enable IPv4 and IPv6 private connectivity to your application using internal Application and Network Load Balancers with dual stack support.

Dual Stack Internal Application and Network Load Balancers architecture

Architecture diagram showing dual stack internal application and network load balancers.

The following numbered items describe the key components in this architecture:

  1. Configure your Amazon VPC NLB or Application Load Balancer (ALB) subnets as dual stack, to accommodate for the internal Elastic Load Balancing (ELB) instances.

  2. Depending on the private connectivity method you have in place for your Amazon VPC (such as Amazon VPC peering, AWS Transit Gateway, Virtual Private Gateway, VPN, or AWS Direct Connect), the ALB/NLB private subnets must be configured with the appropriate routes, for both IPv4 and IPv6 stacks.

  3. Target groups for both ALBs and NLBs can contain either only IPv6 targets or only IPv4 targets. You cannot register an IPv4 target with an IPv6 target group.

  4. Clients reaching out to the private ELB endpoints can be both IPv4 and IPv6 and can have connectivity over any private connectivity method supported by the Amazon Amazon VPC, such as Amazon VPC peering, AWS Transit Gateway, Virtual Private Gateway, VPN, or AWS Direct Connect.

  5. For internal ALBs and NLBs, the attribute flag ipv6.deny-all-igw-traffic blocks internet gateway (IGW) access to the load balancer, preventing unintended access to your internal load balancer through an internet gateway. It is set to false for internet-facing load balancers and true for internal load balancers.

Further reading

For additional information, see the following resources:

Diagram history

To be notified about updates to this reference architecture diagram, subscribe to the RSS feed.

ChangeDescriptionDate

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Initial publication

Reference architecture diagram first published.

June 23, 2022

Note

To subscribe to RSS updates, you must have an RSS plugin enabled for the browser you are using.