awsvpc networking have ENIs. Load balancers, RDS databases, NAT gateways, and interface VPC endpoints also create network interfaces behind the scenes.
What an ENI contains
An ENI can include:- A primary private IPv4 address
- Additional private IPv4 addresses
- IPv6 addresses when enabled
- A MAC address
- One or more security groups
- An optional public IPv4 association through an Elastic IP or automatic assignment
- A description and attachment state
A route table belongs to the subnet, not directly to the ENI. Packets leaving the interface follow the route table associated with its subnet.
What happens when a packet arrives
Consider a request sent to an ECS task with its own ENI:- Routing delivers the packet to the subnet that owns the destination IP.
- The ENI’s security groups evaluate whether the flow is allowed.
- The virtual network delivers the packet to the task’s network namespace.
- The application must be listening on the destination port.
- Return traffic leaves through the same ENI and follows the subnet route table.
Why ECS tasks consume subnet addresses
Withawsvpc networking, each task receives networking that looks like a small machine in the VPC. That isolation is useful, but it consumes at least one private IP address per task.
During a rolling deployment, ECS may start replacement tasks before stopping the old tasks. Auto scaling, previews, failed task retries, load balancers, and VPC endpoints also consume addresses. A subnet that looks large enough for steady state can run out of addresses during deployment.
When no address is available, the scheduler cannot attach a new ENI. The application image and CPU capacity may be fine, yet the task still fails to start.
ENI lifecycle
Some ENIs live and die with their resource. An ECS task ENI is attached when the task starts and removed after the task stops. Other interfaces have longer lives, such as those created for load balancers or interface VPC endpoints. AWS-managed ENIs often show a description that identifies the owning service. You may be unable to detach or delete one directly because the service controls its lifecycle. Delete or update the parent resource instead. An EC2 ENI can sometimes move between compatible instances in the same Availability Zone. This can preserve a private IP during failover, but it is not the normal lifecycle for managed ECS or load-balancer interfaces.ENIs and observability
VPC Flow Logs record accepted and rejected traffic for network interfaces, subnets, or VPCs. They help answer questions such as:- Did traffic reach the interface?
- Was the flow accepted or rejected?
- Which source and destination addresses were involved?
- Which ports and protocols were used?
A practical troubleshooting order
When a resource cannot connect, check the path in layers:- Confirm the resource has an ENI and expected private IP.
- Confirm the source and destination CIDR ranges do not overlap incorrectly.
- Check subnet routes in both directions.
- Check security groups on both sides.
- Check network ACLs.
- Check that the application is listening on the expected address and port.
- Inspect Flow Logs for accepted or rejected traffic.
Frequently asked questions
What is an ENI in AWS?
What is an ENI in AWS?
An AWS elastic network interface is a virtual network card inside a VPC. It carries private and optional public addresses, a MAC address, security groups, and attachment state. EC2, ECS, load balancers, RDS, NAT gateways, and VPC endpoints all use ENIs.
Why does each ECS Fargate task need an ENI?
Why does each ECS Fargate task need an ENI?
ECS tasks using
awsvpc networking receive their own network namespace and VPC identity. Each task gets an ENI and private IP, which enables task-level security groups but consumes subnet address capacity during steady state, scaling, retries, and rolling deployments.Can an ENI cause an ECS task to fail to start?
Can an ENI cause an ECS task to fail to start?
An ECS task can fail before its container starts when the subnet has no available private addresses, an ENI quota is reached, or permissions prevent attachment. Check subnet capacity, ECS service events, interface quotas, security groups, and VPC Flow Logs.