Networking
VPC fundamentals
An Amazon Virtual Private Cloud (VPC) is your own logically isolated network in an AWS Region. Almost every architecture question involves a VPC, so these fundamentals must be second nature.
The building blocks
| Component | What it does |
|---|---|
| VPC | Your private network in a Region, defined by an IPv4 CIDR block (e.g. 10.0.0.0/16); can add secondary CIDRs and IPv6 |
| Subnet | A range of IPs inside the VPC, in one AZ |
| Route table | Rules deciding where traffic from a subnet goes |
| Internet gateway (IGW) | Lets resources with public IPs reach the internet and be reached from it; one per VPC, highly available |
| NAT gateway | Lets private resources make outbound internet connections, while blocking inbound connections |
| Elastic IP | A static public IPv4 address you own until released |
| Elastic network interface (ENI) | A virtual network card with IPs and security groups |
CIDR in one minute
A CIDR block like 10.0.0.0/16 means "the first 16 bits are fixed": 2^(32−16) = 65,536 addresses. A /24 has 256 addresses.
- VPC CIDR sizes range from /16 (largest) to /28 (smallest).
- Use private ranges (
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16) and plan to avoid overlap with on-premises networks and other VPCs you may connect later. - AWS reserves 5 IP addresses in every subnet (first four and last one). A
/24subnet therefore has 251 usable addresses.
Public vs private subnets
A subnet isn't "public" by a setting — it's public because its route table sends 0.0.0.0/0 to an internet gateway.
| Subnet | Route to 0.0.0.0/0 |
Typical contents |
|---|---|---|
| Public | Internet gateway | Load balancers, NAT gateways, bastion hosts |
| Private | NAT gateway (or none) | Application servers, containers |
| Isolated | None | Databases |
NAT gateway vs NAT instance
| NAT gateway | NAT instance | |
|---|---|---|
| Managed | Yes, by AWS | No — an EC2 instance you run |
| Availability | Highly available within one AZ | Single instance unless you build failover |
| Bandwidth | Scales automatically | Limited by instance type |
| Security groups | Not supported (use NACLs) | Supported |
| Setup | Simple | Disable source/destination check; manage patches |
| Cost | Hourly + per-GB processing | Instance cost (can be cheaper for tiny workloads) |
Key idea
For high availability, create one NAT gateway per AZ and point each private subnet to the NAT gateway in its own AZ. A single shared NAT gateway is cheaper but is a single point of failure and adds cross-AZ data charges.
Route tables
- Each subnet is associated with exactly one route table (the main route table by default).
- The local route (VPC CIDR → local) always exists — all subnets in a VPC can reach each other unless blocked by NACLs or security groups.
- The most specific route wins (longest prefix match).
IPv6
- VPCs can be dual-stack (IPv4 + IPv6). IPv6 addresses are globally unique and public by nature.
- For outbound-only IPv6 from private subnets, use an egress-only internet gateway (the IPv6 equivalent of a NAT gateway).
Other VPC features
- VPC Flow Logs — capture IP traffic metadata (accepted/rejected) at VPC, subnet or ENI level to CloudWatch Logs or S3. Used for troubleshooting and security analysis.
- DHCP option sets, DNS hostnames and DNS resolution — control internal naming.
- Default VPC — every Region has one with public subnets in each AZ, for quick starts. Production workloads normally use custom VPCs.
- Shared VPCs — share subnets with other accounts in your organization through RAM.
Exam patterns
- "Private instances need to download patches from the internet" → NAT gateway in a public subnet + route in the private route table.
- "NAT must survive an AZ failure" → NAT gateway in each AZ.
- "An instance in a public subnet can't reach the internet" → check: IGW attached, route to IGW, public IP/Elastic IP, security group and NACL rules.
- "Need more IP addresses in an existing VPC" → add a secondary CIDR block.