This simulator draws a small cloud network and lets you test four traffic patterns against it. A connection succeeds only if a route reaches the destination and the policy permits it; switch either off and the lab shows the hop where the packet stops.
• A 3D topology with an internet client, an internet gateway and NAT egress, a public subnet holding a web server, a private subnet holding a database, and a route and security-group gate. • A Traffic test selector — Internet to public HTTPS, Web to private database, Private to internet via NAT, or Internet to private database — plus checkboxes for Internet gateway and public IPv4 mapping, Required route present, NAT gateway available and Required security-group rule allows flow. • Readouts for connection attempts, successful modeled connections, blocked attempts, current hop index, whether the current path is allowed, and an illustrative successful round trip. • Experiments for local database access, a missing NAT and unsolicited inbound traffic.
An allowed connection requires a reachable route and the required policy. Public HTTPS from the internet needs the internet gateway and public address mapping; a private instance reaching out additionally needs a NAT gateway; web-to-database traffic uses local routing and works without an internet gateway. A permissive security-group rule cannot create a missing route, and NAT is not an inbound port forwarder, so unsolicited inbound traffic to the private database is unreachable in this topology. Return traffic is handled statefully, as in a security group.
The topology is an AWS-style IPv4 layout with stateful security-group return traffic. It does not include network ACLs, DNS, IPv6, peering, endpoint services, ephemeral port exhaustion or a packet-level TCP implementation. It is a reasoning tool for the route-plus-policy idea, not a configuration guide for a specific provider.
No. Reachability and policy are separate checks. In the lab, enabling the security-group rule while the required route is missing still blocks the connection at the routing hop.
No. In this topology NAT only supports private-initiated egress and its return traffic. Testing internet to private database stays blocked even with NAT available.
Traffic between subnets in the same network uses local routing, independent of the internet gateway. The Web to private database test succeeds with the gateway switched off, provided the security-group rule allows it.
It marks the position along the path where the connection currently is, or where it stopped. When a check fails, the blocked attempt counter increases and the highlight stays at the hop that refused the traffic.