EC2의 랜카드, ENI : Public IP는 어디에 붙어 있나ENI, the Network Card of EC2: Where Does the Public IP Live?

ENI, Private IP, Public IP, 그리고 EIPENI, private IP, public IP, and EIP

written by tiaz0128

“EC2에 IP를 붙인다”고 흔히 말하지만, 조금만 파고들면 이 문장은 정확하지 않습니다. IP를 들고 있는 건 EC2가 아니라 ENI이고, EC2는 그 ENI가 꽂혀 있는 상자일 뿐입니다.

이 구분을 대충 넘어가면 나중에 꼭 걸립니다. 인스턴스를 껐다 켰더니 주소가 바뀌어 있고, 서버 안에서 ifconfig를 쳤는데 Public IP가 안 보이고, EIP를 붙였는데 왜 요금이 나오는지 모르겠고. 전부 “IP가 어디에 붙어 있는가” 하나로 설명됩니다.

이번 글은 그 이야기입니다. 예전에 그려둔 다이어그램의 스토리를 구간별로 잘라 각 문단에 붙였습니다. 그림의 재생 버튼을 누르면 그 문단이 그대로 재생됩니다. 한 번 돌고 멈추니, 다시 보고 싶으면 다시 누르시면 됩니다.

'VPC, 서브넷, CIDR, 라우트 테이블의 기본 개념'에 대해 더 자세히 알고 싶으시다면, "AWS 네트워크 기본" 글을 확인 해주세요!

ENI는 EC2에 꽂는 랜카드다

ENI(Elastic Network Interface)는 VPC 안의 가상 랜카드입니다. 물리 서버에 랜카드를 꽂아야 네트워크에 붙듯, EC2도 ENI가 있어야 통신합니다. 인스턴스를 만들면 eth0에 해당하는 기본 ENI가 자동으로 하나 붙습니다.

여기서 놓치기 쉬운 게 하나 있습니다. ENI는 서브넷에 소속되고, 서브넷은 가용영역(AZ)에 소속됩니다. 그러니까 ENI도 특정 AZ에 묶여 있습니다. 다른 AZ의 인스턴스로 옮겨 붙일 수 없다는 뜻입니다.

> ENI — EC2의 가상 랜카드, 그리고 AZ 소속

Private IP는 ENI가 들고 있다

ENI 하나에는 기본 프라이빗 IPv4 주소(primary private IP)가 반드시 하나 있습니다. 이 주소는 ENI가 살아 있는 동안 바뀌지 않습니다. 인스턴스를 껐다 켜도, 몇 달을 굴려도 그대로입니다.

여기에 보조 프라이빗 IP(secondary private IP)를 더 붙일 수 있습니다. 몇 개까지 붙는지는 인스턴스 타입이 정합니다. 큰 타입일수록 ENI도 더 많이, ENI당 IP도 더 많이 붙습니다.

> ENI의 기본 Private IP와 보조 Private IP

그럼 Public IP는 어디에 있나

여기가 핵심입니다. Public IP는 ENI의 기본 프라이빗 IP에 1:1로 매핑되는 방식으로 붙습니다. ENI가 Public IP를 “가지는” 게 아니라, 인터넷 게이트웨이(IGW)가 오갈 때 주소를 바꿔치기해 줍니다.

그래서 인스턴스 안에서 ip addr을 쳐도 Public IP는 보이지 않습니다. OS가 아는 주소는 프라이빗 IP뿐입니다. 처음 보면 당황스럽지만, 알고 나면 당연합니다 — 변환은 바깥에서 일어나니까요.

그리고 이 Public IP는 인스턴스를 시작할 때 AWS 주소 풀에서 무작위로 하나 꺼내 오는 것입니다. 내 것이 아니라 잠깐 빌려 쓰는 주소입니다.

서버 안에서 자기 Public IP를 알아야 한다면 인스턴스 메타데이터(IMDSv2)로 조회할 수 있습니다. 네트워크 인터페이스에는 없지만, 메타데이터 서비스는 알고 있습니다.
> Public IP는 기본 Private IP에 매핑되고, 부팅할 때 풀에서 할당된다

껐다 켜면 주소가 바뀐다

빌려 쓰는 주소이니 반납할 일이 생깁니다. 인스턴스를 중지(stop)하면 Public IP는 풀로 돌아가고, 다시 시작(start)하면 새 주소를 받습니다.

  • 재부팅(reboot) — 주소 유지. 인스턴스가 계속 살아 있으므로 반납하지 않습니다.
  • 중지 후 시작(stop → start) — 주소 변경. 이때 사고가 납니다.

DNS 레코드를 그 IP로 박아뒀거나, 방화벽에 그 IP를 허용해 뒀거나, 상대 회사에 IP를 알려줬다면 — 인스턴스를 한 번 껐다 켜는 순간 전부 어긋납니다.

> 중지 후 시작하면 Public IP가 바뀐다

그래서 EIP

EIP(Elastic IP)는 계정에 할당해서 들고 있는 고정 Public IPv4 주소입니다. 풀에서 잠깐 빌리는 게 아니라 내가 소유하고 있다가, 원하는 ENI에 붙이는 것입니다.

ENI에 EIP를 붙이면 그 ENI의 Public IP는 EIP로 고정됩니다. 인스턴스를 껐다 켜도, 심지어 ENI를 떼어서 다른 인스턴스에 옮겨 꽂아도 주소가 따라갑니다. 장애 조치(failover) 구성에서 이 성질을 자주 씁니다. 죽은 인스턴스에서 ENI를 떼어 예비 인스턴스에 붙이면, 프라이빗 IP와 EIP가 통째로 넘어갑니다.

> EIP — 계정이 소유하는 고정 Public IP
2024년 2월부터 사용 중인 EIP를 포함해 모든 퍼블릭 IPv4 주소에 시간당 요금이 붙습니다. 예전에는 '붙여두면 무료, 놀리면 과금'이었지만 지금은 붙여둬도 과금됩니다. 안 쓰는 EIP는 반드시 릴리스하세요.

정리

한 줄로 줄이면 “IP는 EC2가 아니라 ENI에 붙는다”입니다.

  어디에 붙나 껐다 켜면 OS에서 보이나
기본 Private IP ENI에 1개 (필수) 유지 보임
보조 Private IP ENI에 여러 개 유지 보임
자동 할당 Public IP 기본 Private IP에 매핑 바뀜 안 보임
EIP 기본 Private IP에 매핑 유지 안 보임

그리고 ENI는 AZ에 묶여 있다는 것, 이것만 같이 기억하면 됩니다.

짧게 요약한 영상도 있습니다.

> AWS 네트워크 기초 ENI와 EIP

'이 다이어그램을 그린 도구와 만든 이유'에 대해 더 자세히 알고 싶으시다면, "howtodraw.cloud를 만든 이유" 글을 확인 해주세요!

감사합니다!

We often say “attach an IP to EC2”, but dig a little and that sentence isn’t accurate. What holds the IP isn’t EC2 but the ENI; EC2 is just the box the ENI is plugged into.

Gloss over this distinction and it will bite you later. You stop and start an instance and its address has changed; you run ifconfig on the server and the public IP isn’t there; you attach an EIP and can’t figure out why you’re being billed. All of it is explained by one thing: “where the IP is attached”.

That’s what this post is about. I cut the story of a diagram I drew earlier into segments and attached each one to its paragraph. Press the play button on a picture and that paragraph plays out. It plays once and stops, so press it again if you want to see it again.

Want to know more about 'Basic concepts of VPCs, subnets, CIDR and route tables'? Check out "AWS Networking Basics"!

An ENI Is the Network Card You Plug into EC2

An ENI (Elastic Network Interface) is a virtual network card inside a VPC. Just as a physical server needs a network card to join a network, EC2 needs an ENI to communicate. When you create an instance, a primary ENI, corresponding to eth0, is attached automatically.

There’s one thing that’s easy to miss here. An ENI belongs to a subnet, and a subnet belongs to an Availability Zone (AZ). So an ENI is tied to a specific AZ too. That means you can’t move it over to an instance in a different AZ.

> ENI — EC2's virtual network card, and which AZ it belongs to

The ENI Holds the Private IP

Every ENI has exactly one primary private IPv4 address (primary private IP). This address doesn’t change for as long as the ENI exists. Stop and start the instance, run it for months, and it stays the same.

On top of that, you can attach more secondary private IPs. How many depends on the instance type. Larger types support more ENIs and more IPs per ENI.

> The ENI's primary private IP and secondary private IPs

So Where Is the Public IP?

This is the crux. A public IP is attached by being mapped 1:1 to the ENI’s primary private IP. The ENI doesn’t “own” the public IP; the internet gateway (IGW) swaps the address as traffic passes in and out.

That’s why running ip addr inside the instance doesn’t show the public IP. The only address the OS knows about is the private IP. It’s confusing the first time you see it, but obvious once you know — the translation happens outside.

And this public IP is picked at random from the AWS address pool when the instance starts. It isn’t yours; it’s an address you borrow for a while.

If you need to know your own public IP from inside the server, you can look it up through instance metadata (IMDSv2). It isn't on the network interface, but the metadata service knows it.
> The public IP is mapped to the primary private IP and assigned from the pool at boot

Stop and Start, and the Address Changes

A borrowed address eventually has to be returned. When you stop an instance, its public IP goes back to the pool, and when you start it again, it gets a new address.

  • Reboot — the address stays. The instance is alive the whole time, so nothing is returned.
  • Stop, then start (stop → start) — the address changes. This is where accidents happen.

If you’d hard-coded that IP in a DNS record, allowed it in a firewall, or given it to a partner company — the moment you stop and start the instance once, all of it breaks.

> Stop and start, and the public IP changes

Hence the EIP

An EIP (Elastic IP) is a fixed public IPv4 address allocated to and held by your account. Instead of borrowing one from the pool for a while, you own it and attach it to whichever ENI you want.

Attach an EIP to an ENI and that ENI’s public IP is fixed to the EIP. Stop and start the instance, or even detach the ENI and plug it into another instance, and the address follows it. This property is often used in failover setups: detach the ENI from the dead instance, attach it to a standby, and the private IP and EIP move over as a whole.

> EIP — a fixed public IP owned by your account
Since February 2024, every public IPv4 address, including EIPs in use, is billed by the hour. It used to be 'free while attached, billed while idle', but now you pay even while it's attached. Always release EIPs you don't use.

Summary

In one line: “IPs attach to the ENI, not to EC2.”

  Attached to After stop/start Visible in the OS?
Primary private IP One per ENI (required) Kept Yes
Secondary private IP Several per ENI Kept Yes
Auto-assigned public IP Mapped to the primary private IP Changes No
EIP Mapped to the primary private IP Kept No

Just remember one more thing along with it: an ENI is tied to an AZ.

There’s also a short video summary.

> AWS networking basics: ENI and EIP

Want to know more about 'The tool I drew this diagram with, and why I built it'? Check out "Why I Built howtodraw.cloud"!

Thank you!

AWS Network ENI EC2 EIP

tiaz0128

Eat Sleep Coding.

Never Never GiveUp.

Security  |  BackEnd  |  Multi Cloud