Azure does not have a component called an Internet Gateway, but it has services that do the same job

If you are moving from AWS or another cloud platform, you might be looking for Azure's equivalent of an Internet Gateway. Azure does not use that term or that exact architecture. Instead, Azure handles internet traffic through a combination of public IP addresses, Network Address Translation (NAT), and Azure's edge routing. The way you connect a virtual machine or application to the internet in Azure is different from AWS, but the end result is the same: your resources can send traffic out to the internet and receive traffic back.

The confusion usually comes from AWS terminology. In AWS, an Internet Gateway is a required component that you explicitly attach to a VPC to enable internet communication. In Azure, internet connectivity is built into the platform itself — you do not need to create and attach a separate gateway object. Instead, you assign a public IP address to the resource that needs to reach the internet, and Azure handles the routing automatically.

Key Takeaways

  • Azure does not have an Internet Gateway component; instead, it uses public IP addresses assigned directly to virtual machines or load balancers to enable internet access.
  • If you need outbound-only internet access without a public IP, you can use Azure NAT Gateway, which is Azure's closest equivalent to some Internet Gateway functions.
  • Azure's edge routing and public IP assignment happen automatically once you configure the IP, unlike AWS where you must explicitly attach an Internet Gateway to a VPC.
  • For inbound traffic from the internet, you typically use a public IP on a Network Interface Card (NIC) or an Azure Load Balancer, not a separate gateway object.

How Azure handles outbound internet traffic without a gateway

When a virtual machine in Azure needs to send traffic to the internet, it does not require a separate Internet Gateway object. If the VM has a public IP address assigned to its network interface, Azure automatically routes outbound traffic through that public IP. The routing is handled by Azure's backbone network, not by a gateway you create and manage.

If your VM does not have a public IP but still needs to reach the internet, Azure uses Source Network Address Translation (SNAT) through the default outbound path. This means Azure translates the VM's private IP to a temporary public IP for the duration of the connection. This happens automatically, but it has limits — Azure provides a limited number of SNAT ports per VM, and if you exceed them, outbound connections will fail.

This is where Azure NAT Gateway comes in. If you need reliable outbound internet access without assigning a public IP to every resource, you create an Azure NAT Gateway and attach it to a subnet. All VMs in that subnet use the NAT Gateway's public IP for outbound traffic, giving you a single, predictable source IP and more SNAT ports than the default path provides.

Azure NAT Gateway: the closest equivalent to an Internet Gateway

If you are looking for something that resembles an Internet Gateway in function, Azure NAT Gateway is the closest match — but only for outbound traffic. A NAT Gateway is a managed service that you create, assign a public IP to, and attach to one or more subnets. All traffic leaving those subnets uses the NAT Gateway's public IP as the source.

NAT Gateway is useful when you have many VMs that need outbound internet access but you do not want to assign a public IP to each one. It is also useful when you need a stable, known source IP for outbound connections — for example, if a third-party service allows traffic only from specific IP addresses. You create the NAT Gateway in the Azure portal or via command line, assign it a public IP address, and link it to your subnet. From that point on, outbound traffic from VMs in that subnet flows through the NAT Gateway.

However, NAT Gateway only handles outbound traffic. It does not accept inbound traffic from the internet the way an AWS Internet Gateway does. For inbound traffic, you use a public IP on the VM's network interface or an Azure Load Balancer.

Handling inbound internet traffic in Azure

To allow inbound traffic from the internet to reach a VM or application in Azure, you assign a public IP address to the network interface card (NIC) of the VM, or you place the VM behind an Azure Load Balancer that has a public IP. The public IP is the address that external users or systems connect to; Azure routes that traffic to the private IP of your resource.

If you have a single VM that needs to be reachable from the internet, the simplest approach is to assign a public IP directly to its NIC. You do this in the Azure portal by creating a public IP resource and associating it with the VM's network interface. Once assigned, the VM is reachable at that public IP address.

If you have multiple VMs or need load balancing, you use an Azure Load Balancer. The load balancer has a public IP, and you configure it to forward traffic to the private IPs of your backend VMs. This is more scalable and allows you to distribute traffic across multiple instances. The load balancer itself acts as the internet-facing entry point, similar to how an AWS Internet Gateway routes traffic into a VPC.

Network Security Groups control what traffic actually reaches your resources

Whether you use a public IP or a NAT Gateway, you still need to control which traffic is allowed in and out. This is where Network Security Groups (NSGs) come in. An NSG is a set of firewall rules that you attach to a subnet or a network interface. It defines which inbound and outbound traffic is permitted.

By default, Azure denies all inbound traffic and allows all outbound traffic. If you assign a public IP to a VM but do not create an NSG rule allowing inbound traffic on a specific port, that traffic will be blocked. For example, if you want to allow HTTP traffic on port 80, you create an inbound rule in the NSG that permits traffic on that port from the source you specify (often 0.0.0.0/0 for any source, or a specific IP range).

NSGs are where you actually enforce security, not at the gateway level. The public IP or NAT Gateway just provides the routing; the NSG decides what is allowed through.

Comparing Azure public IP assignment to AWS Internet Gateway

The key difference between Azure and AWS is that AWS requires you to explicitly create and attach an Internet Gateway to a VPC before any resource in that VPC can reach the internet. In Azure, you do not create a gateway object at all. Instead, you assign a public IP address to the resource that needs internet access, and that is sufficient for outbound traffic. For inbound traffic, the public IP or load balancer serves the same purpose as an Internet Gateway.

In AWS, the Internet Gateway is a VPC-level component that handles all internet traffic for the entire VPC. In Azure, public IPs are assigned at the resource level (to a VM's NIC or to a load balancer), and each resource or service manages its own internet connectivity. This is a more granular, resource-focused approach rather than a network-level approach.

If you are migrating from AWS and need a single, subnet-level component that handles outbound traffic for multiple resources, Azure NAT Gateway is the closest equivalent. But for inbound traffic, you use public IPs or load balancers, not a gateway.

When you might think you need an Internet Gateway in Azure

Developers new to Azure often look for an Internet Gateway because they are familiar with AWS. The most common scenarios are: you want VMs to reach the internet, you want external users to reach your application, or you want a stable source IP for outbound traffic. In each case, Azure has a solution, but it does not involve creating a gateway.

If you want outbound access, assign a public IP or use a NAT Gateway. If you want inbound access, assign a public IP to the VM or use a load balancer. If you want to control what traffic is allowed, create NSG rules. None of these steps require an Internet Gateway because Azure does not have one.

Frequently Asked Questions

Do I need to create an Internet Gateway to use Azure?

No. Azure does not have an Internet Gateway component. Internet connectivity is built into the platform. You enable it by assigning a public IP address to a resource or by using a NAT Gateway for outbound traffic. You do not need to create or attach a separate gateway object.

What is the Azure equivalent of an AWS Internet Gateway?

There is no single equivalent. For outbound traffic, Azure NAT Gateway is the closest match. For inbound traffic, a public IP address or Azure Load Balancer serves the same purpose. Azure handles internet routing automatically once these resources are in place.

Can I use Azure NAT Gateway for inbound traffic from the internet?

No. Azure NAT Gateway only handles outbound traffic. For inbound traffic, you must use a public IP address on the VM's network interface or an Azure Load Balancer with a public IP.

Do I need a public IP for every VM that needs internet access?

Not necessarily. VMs can use the default outbound path (SNAT) without a public IP, but this has port limits. For reliable outbound access without public IPs on each VM, use an Azure NAT Gateway attached to the subnet.

How do I prevent unwanted inbound traffic if I assign a public IP?

Create Network Security Group rules that explicitly allow only the traffic you want. By default, Azure blocks all inbound traffic, so you must add rules to permit specific ports and sources. NSGs are where you enforce security, not at the IP or gateway level.