EC2 server to VPC private instance via VPC NAT instance

  1. iptables -t nat -A PREROUTING -s -d -i eth0 -p tcp -m tcp --sport 1024:65535 --dport 3306 -j DNAT --to-destination
    1. is your external server's public IP address
    2. is your VPC NAT instance's IP address in the public subnet
    3. is the VPC IP address of your server in a private subnet
    4. 3306 is the port your service is listening on


