-do a tcpdump on the instance and see if you get any traffic hits to the ip interface that is attached to the floating ip. 1) if you see traffic coming inside then your SNAT is working, you might want to allow egress traffic on instance security group. 2) if you dont see traffic coming inside then you need to allow ingress rules on the instance security group 3) if you feel this is all good, then try setting "port_security_enabled" false for private and external network port and see if it works.