EC2의 랜카드, ENI : Public IP는 어디에 붙어 있나ENI, the Network Card of EC2: Where Does the Public IP Live?
ENI, Private IP, Public IP, 그리고 EIPENI, private IP, public IP, and EIP
“EC2에 IP를 붙인다”고 흔히 말하지만, 조금만 파고들면 이 문장은 정확하지 않습니다. IP를 들고 있는 건 EC2가 아니라 ENI이고, EC2는 그 ENI가 꽂혀 있는 상자일 뿐입니다.
이 구분을 대충 넘어가면 나중에 꼭 걸립니다. 인스턴스를 껐다 켰더니 주소가 바뀌어 있고, 서버 안에서 ifconfig를 쳤는데 Public IP가 안 보이고, EIP를 붙였는데 왜 요금이 나오는지 모르겠고. 전부 “IP가 어디에 붙어 있는가” 하나로 설명됩니다.
이번 글은 그 이야기입니다. 예전에 그려둔 다이어그램의 스토리를 구간별로 잘라 각 문단에 붙였습니다. 그림의 재생 버튼을 누르면 그 문단이 그대로 재생됩니다. 한 번 돌고 멈추니, 다시 보고 싶으면 다시 누르시면 됩니다.
ENI는 EC2에 꽂는 랜카드다
ENI(Elastic Network Interface)는 VPC 안의 가상 랜카드입니다. 물리 서버에 랜카드를 꽂아야 네트워크에 붙듯, EC2도 ENI가 있어야 통신합니다. 인스턴스를 만들면 eth0에 해당하는 기본 ENI가 자동으로 하나 붙습니다.
여기서 놓치기 쉬운 게 하나 있습니다. ENI는 서브넷에 소속되고, 서브넷은 가용영역(AZ)에 소속됩니다. 그러니까 ENI도 특정 AZ에 묶여 있습니다. 다른 AZ의 인스턴스로 옮겨 붙일 수 없다는 뜻입니다.
Private IP는 ENI가 들고 있다
ENI 하나에는 기본 프라이빗 IPv4 주소(primary private IP)가 반드시 하나 있습니다. 이 주소는 ENI가 살아 있는 동안 바뀌지 않습니다. 인스턴스를 껐다 켜도, 몇 달을 굴려도 그대로입니다.
여기에 보조 프라이빗 IP(secondary private IP)를 더 붙일 수 있습니다. 몇 개까지 붙는지는 인스턴스 타입이 정합니다. 큰 타입일수록 ENI도 더 많이, ENI당 IP도 더 많이 붙습니다.
그럼 Public IP는 어디에 있나
여기가 핵심입니다. Public IP는 ENI의 기본 프라이빗 IP에 1:1로 매핑되는 방식으로 붙습니다. ENI가 Public IP를 “가지는” 게 아니라, 인터넷 게이트웨이(IGW)가 오갈 때 주소를 바꿔치기해 줍니다.
그래서 인스턴스 안에서 ip addr을 쳐도 Public IP는 보이지 않습니다. OS가 아는 주소는 프라이빗 IP뿐입니다. 처음 보면 당황스럽지만, 알고 나면 당연합니다 — 변환은 바깥에서 일어나니까요.
그리고 이 Public IP는 인스턴스를 시작할 때 AWS 주소 풀에서 무작위로 하나 꺼내 오는 것입니다. 내 것이 아니라 잠깐 빌려 쓰는 주소입니다.
껐다 켜면 주소가 바뀐다
빌려 쓰는 주소이니 반납할 일이 생깁니다. 인스턴스를 중지(stop)하면 Public IP는 풀로 돌아가고, 다시 시작(start)하면 새 주소를 받습니다.
- 재부팅(reboot) — 주소 유지. 인스턴스가 계속 살아 있으므로 반납하지 않습니다.
- 중지 후 시작(stop → start) — 주소 변경. 이때 사고가 납니다.
DNS 레코드를 그 IP로 박아뒀거나, 방화벽에 그 IP를 허용해 뒀거나, 상대 회사에 IP를 알려줬다면 — 인스턴스를 한 번 껐다 켜는 순간 전부 어긋납니다.
그래서 EIP
EIP(Elastic IP)는 계정에 할당해서 들고 있는 고정 Public IPv4 주소입니다. 풀에서 잠깐 빌리는 게 아니라 내가 소유하고 있다가, 원하는 ENI에 붙이는 것입니다.
ENI에 EIP를 붙이면 그 ENI의 Public IP는 EIP로 고정됩니다. 인스턴스를 껐다 켜도, 심지어 ENI를 떼어서 다른 인스턴스에 옮겨 꽂아도 주소가 따라갑니다. 장애 조치(failover) 구성에서 이 성질을 자주 씁니다. 죽은 인스턴스에서 ENI를 떼어 예비 인스턴스에 붙이면, 프라이빗 IP와 EIP가 통째로 넘어갑니다.
정리
한 줄로 줄이면 “IP는 EC2가 아니라 ENI에 붙는다”입니다.
| 어디에 붙나 | 껐다 켜면 | OS에서 보이나 | |
|---|---|---|---|
| 기본 Private IP | ENI에 1개 (필수) | 유지 | 보임 |
| 보조 Private IP | ENI에 여러 개 | 유지 | 보임 |
| 자동 할당 Public IP | 기본 Private IP에 매핑 | 바뀜 | 안 보임 |
| EIP | 기본 Private IP에 매핑 | 유지 | 안 보임 |
그리고 ENI는 AZ에 묶여 있다는 것, 이것만 같이 기억하면 됩니다.
짧게 요약한 영상도 있습니다.
> AWS 네트워크 기초 ENI와 EIP
감사합니다!
We often say “attach an IP to EC2”, but dig a little and that sentence isn’t accurate. What holds the IP isn’t EC2 but the ENI; EC2 is just the box the ENI is plugged into.
Gloss over this distinction and it will bite you later. You stop and start an instance and its address has changed; you run ifconfig on the server and the public IP isn’t there; you attach an EIP and can’t figure out why you’re being billed. All of it is explained by one thing: “where the IP is attached”.
That’s what this post is about. I cut the story of a diagram I drew earlier into segments and attached each one to its paragraph. Press the play button on a picture and that paragraph plays out. It plays once and stops, so press it again if you want to see it again.
An ENI Is the Network Card You Plug into EC2
An ENI (Elastic Network Interface) is a virtual network card inside a VPC. Just as a physical server needs a network card to join a network, EC2 needs an ENI to communicate. When you create an instance, a primary ENI, corresponding to eth0, is attached automatically.
There’s one thing that’s easy to miss here. An ENI belongs to a subnet, and a subnet belongs to an Availability Zone (AZ). So an ENI is tied to a specific AZ too. That means you can’t move it over to an instance in a different AZ.
The ENI Holds the Private IP
Every ENI has exactly one primary private IPv4 address (primary private IP). This address doesn’t change for as long as the ENI exists. Stop and start the instance, run it for months, and it stays the same.
On top of that, you can attach more secondary private IPs. How many depends on the instance type. Larger types support more ENIs and more IPs per ENI.
So Where Is the Public IP?
This is the crux. A public IP is attached by being mapped 1:1 to the ENI’s primary private IP. The ENI doesn’t “own” the public IP; the internet gateway (IGW) swaps the address as traffic passes in and out.
That’s why running ip addr inside the instance doesn’t show the public IP. The only address the OS knows about is the private IP. It’s confusing the first time you see it, but obvious once you know — the translation happens outside.
And this public IP is picked at random from the AWS address pool when the instance starts. It isn’t yours; it’s an address you borrow for a while.
Stop and Start, and the Address Changes
A borrowed address eventually has to be returned. When you stop an instance, its public IP goes back to the pool, and when you start it again, it gets a new address.
- Reboot — the address stays. The instance is alive the whole time, so nothing is returned.
- Stop, then start (stop → start) — the address changes. This is where accidents happen.
If you’d hard-coded that IP in a DNS record, allowed it in a firewall, or given it to a partner company — the moment you stop and start the instance once, all of it breaks.
Hence the EIP
An EIP (Elastic IP) is a fixed public IPv4 address allocated to and held by your account. Instead of borrowing one from the pool for a while, you own it and attach it to whichever ENI you want.
Attach an EIP to an ENI and that ENI’s public IP is fixed to the EIP. Stop and start the instance, or even detach the ENI and plug it into another instance, and the address follows it. This property is often used in failover setups: detach the ENI from the dead instance, attach it to a standby, and the private IP and EIP move over as a whole.
Summary
In one line: “IPs attach to the ENI, not to EC2.”
| Attached to | After stop/start | Visible in the OS? | |
|---|---|---|---|
| Primary private IP | One per ENI (required) | Kept | Yes |
| Secondary private IP | Several per ENI | Kept | Yes |
| Auto-assigned public IP | Mapped to the primary private IP | Changes | No |
| EIP | Mapped to the primary private IP | Kept | No |
Just remember one more thing along with it: an ENI is tied to an AZ.
There’s also a short video summary.
> AWS networking basics: ENI and EIP
Thank you!