Skip to main content
An elastic network interface, usually shortened to ENI, is a virtual network card inside an Amazon VPC. It is the point where an AWS resource receives IP addresses, applies security groups, and exchanges packets with the rest of the network. Updated October 9, 2026. EC2 instances have ENIs. ECS tasks using awsvpc networking have ENIs. Load balancers, RDS databases, NAT gateways, and interface VPC endpoints also create network interfaces behind the scenes.

What an ENI contains

An ENI can include:
  • A primary private IPv4 address
  • Additional private IPv4 addresses
  • IPv6 addresses when enabled
  • A MAC address
  • One or more security groups
  • An optional public IPv4 association through an Elastic IP or automatic assignment
  • A description and attachment state
The ENI belongs to one subnet and one Availability Zone. Its private addresses come from that subnet’s CIDR range.
A route table belongs to the subnet, not directly to the ENI. Packets leaving the interface follow the route table associated with its subnet.

What happens when a packet arrives

Consider a request sent to an ECS task with its own ENI:
  1. Routing delivers the packet to the subnet that owns the destination IP.
  2. The ENI’s security groups evaluate whether the flow is allowed.
  3. The virtual network delivers the packet to the task’s network namespace.
  4. The application must be listening on the destination port.
  5. Return traffic leaves through the same ENI and follows the subnet route table.
Security groups are stateful. If an allowed request starts a connection, return traffic for that connection is allowed automatically. Network ACLs operate at the subnet boundary and are stateless, so their inbound and outbound rules must both permit the traffic.

Why ECS tasks consume subnet addresses

With awsvpc networking, each task receives networking that looks like a small machine in the VPC. That isolation is useful, but it consumes at least one private IP address per task. During a rolling deployment, ECS may start replacement tasks before stopping the old tasks. Auto scaling, previews, failed task retries, load balancers, and VPC endpoints also consume addresses. A subnet that looks large enough for steady state can run out of addresses during deployment. When no address is available, the scheduler cannot attach a new ENI. The application image and CPU capacity may be fine, yet the task still fails to start.
Include deployment surge and managed-service interfaces when estimating subnet size. Do not calculate capacity from the normal task count alone.

ENI lifecycle

Some ENIs live and die with their resource. An ECS task ENI is attached when the task starts and removed after the task stops. Other interfaces have longer lives, such as those created for load balancers or interface VPC endpoints. AWS-managed ENIs often show a description that identifies the owning service. You may be unable to detach or delete one directly because the service controls its lifecycle. Delete or update the parent resource instead. An EC2 ENI can sometimes move between compatible instances in the same Availability Zone. This can preserve a private IP during failover, but it is not the normal lifecycle for managed ECS or load-balancer interfaces.

ENIs and observability

VPC Flow Logs record accepted and rejected traffic for network interfaces, subnets, or VPCs. They help answer questions such as:
  • Did traffic reach the interface?
  • Was the flow accepted or rejected?
  • Which source and destination addresses were involved?
  • Which ports and protocols were used?
Flow Logs do not inspect application payloads and cannot tell you whether the process returned an HTTP 500. Combine network evidence with load-balancer access logs and application logs.

A practical troubleshooting order

When a resource cannot connect, check the path in layers:
  1. Confirm the resource has an ENI and expected private IP.
  2. Confirm the source and destination CIDR ranges do not overlap incorrectly.
  3. Check subnet routes in both directions.
  4. Check security groups on both sides.
  5. Check network ACLs.
  6. Check that the application is listening on the expected address and port.
  7. Inspect Flow Logs for accepted or rejected traffic.
The useful mental model is simple: the ENI is where a cloud resource joins the VPC. If you understand its address, subnet, security groups, and owner, many apparently mysterious connectivity failures become ordinary routing or application problems.

Frequently asked questions

An AWS elastic network interface is a virtual network card inside a VPC. It carries private and optional public addresses, a MAC address, security groups, and attachment state. EC2, ECS, load balancers, RDS, NAT gateways, and VPC endpoints all use ENIs.
ECS tasks using awsvpc networking receive their own network namespace and VPC identity. Each task gets an ENI and private IP, which enables task-level security groups but consumes subnet address capacity during steady state, scaling, retries, and rolling deployments.
An ECS task can fail before its container starts when the subnet has no available private addresses, an ENI quota is reached, or permissions prevent attachment. Check subnet capacity, ECS service events, interface quotas, security groups, and VPC Flow Logs.

Sources and further reading

Last modified on October 8, 2026