AWS Solutions Architect Handbook SAA-C03, from zero Bipin Singh
Networking

VPC fundamentals

3 min readChapter 11 of 48By Bipin Singh

An Amazon Virtual Private Cloud (VPC) is your own logically isolated network in an AWS Region. Almost every architecture question involves a VPC, so these fundamentals must be second nature.

The building blocks

Component What it does
VPC Your private network in a Region, defined by an IPv4 CIDR block (e.g. 10.0.0.0/16); can add secondary CIDRs and IPv6
Subnet A range of IPs inside the VPC, in one AZ
Route table Rules deciding where traffic from a subnet goes
Internet gateway (IGW) Lets resources with public IPs reach the internet and be reached from it; one per VPC, highly available
NAT gateway Lets private resources make outbound internet connections, while blocking inbound connections
Elastic IP A static public IPv4 address you own until released
Elastic network interface (ENI) A virtual network card with IPs and security groups

CIDR in one minute

A CIDR block like 10.0.0.0/16 means "the first 16 bits are fixed": 2^(32−16) = 65,536 addresses. A /24 has 256 addresses.

Public vs private subnets

A subnet isn't "public" by a setting — it's public because its route table sends 0.0.0.0/0 to an internet gateway.

Subnet Route to 0.0.0.0/0 Typical contents
Public Internet gateway Load balancers, NAT gateways, bastion hosts
Private NAT gateway (or none) Application servers, containers
Isolated None Databases
VPC 10.0.0.0/16 (Region)Internet GWAvailability Zone AAvailability Zone BPublic subnet 10.0.1.0/24Public subnet 10.0.2.0/24ALB nodeALB nodeNAT GWNAT GWPrivate subnet (app) 10.0.11.0/24Private subnet (app) 10.0.12.0/24EC2 / ECSEC2 / ECSIsolated subnet (data) 10.0.21.0/24Isolated subnet (data) 10.0.22.0/24RDS primaryRDS standby
A standard highly available VPC: every tier spans two AZs; public subnets route to the internet gateway, app subnets route outbound through the NAT gateway in their own AZ, data subnets have no internet route.

NAT gateway vs NAT instance

NAT gateway NAT instance
Managed Yes, by AWS No — an EC2 instance you run
Availability Highly available within one AZ Single instance unless you build failover
Bandwidth Scales automatically Limited by instance type
Security groups Not supported (use NACLs) Supported
Setup Simple Disable source/destination check; manage patches
Cost Hourly + per-GB processing Instance cost (can be cheaper for tiny workloads)
Key idea

For high availability, create one NAT gateway per AZ and point each private subnet to the NAT gateway in its own AZ. A single shared NAT gateway is cheaper but is a single point of failure and adds cross-AZ data charges.

Route tables

IPv6

Other VPC features

Exam patterns

Bipin Singh
Written by Bipin Singh

Senior Full-Stack Engineer · AI & AWS. I design and run production systems on AWS — serverless, data and AI.

Work with me