结论, 如果lb是internet-facing,也就是面向public,那么在subnet的route-table里面必须有igw网关,而不是nat网关. https://docs.aws.amazon.com/elasticloadbalancing/latest/userguide/what-is-load-balancing.html?icmpid=docs_elbv2_console#elb-featureshttps://itellity.wordpress.com/2014/09/11/creating-an-elb-load-balancer-with-private-subnet-instances-in-a-vpc/