Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
15.1 What is a VPC? Default VPC vs custom VPC
Friends, think of a VPC as a housing society. The society's boundary wall is the VPC – who lives inside, in which wing, where the gate is – the society decides everything. But note: this is only to help you understand. Technically, a VPC is your own network inside an AWS Region, isolated from other customers, and you choose its IP range (CIDR).
मित्रांनो, VPC ला एक housing society समजा. Society ची boundary wall म्हणजे VPC – आत कोण राहणार, कोणत्या wing मध्ये, gate कुठे – सगळं society ठरवते. पण लक्ष द्या: हे फक्त समजण्यासाठी आहे. Technically VPC म्हणजे AWS Region मधलं तुमचं स्वतःचं, बाकी customers पासून वेगळं (isolated) network, आणि त्याची IP range (CIDR) तुम्ही निवडता.
दोस्तों, VPC को एक housing society समझो. Society की boundary wall यानी VPC – अंदर कौन रहेगा, किस wing में, gate कहाँ – सब society तय करती है. पर ध्यान दो: यह सिर्फ समझने के लिए है. Technically VPC यानी AWS Region में आपका अपना, बाकी customers से अलग (isolated) network, और उसकी IP range (CIDR) आप चुनते हो.
A VPC (Virtual Private Cloud) is your own logically isolated virtual network inside one AWS Region. Every EC2 instance, RDS database or load balancer you launch gets its private IP address from a VPC. A VPC covers all the Availability Zones (AZs) of its Region, while each of its subnets lives in exactly one AZ.
The VPC 10.0.0.0/16 lives in one Region. Inside it, each subnet lives in one Availability Zone. A request from the internet enters through the internet gateway and can reach only the public subnet, because only its route table points to the IGW.
VPC 10.0.0.0/16 एका Region मध्ये असतो. त्याच्या आत प्रत्येक subnet एका Availability Zone मध्ये असतो. Internet वरून आलेली request internet gateway मधून आत येते आणि फक्त public subnet पर्यंत पोहोचते, कारण फक्त त्याचं route table IGW कडे जातं.
VPC 10.0.0.0/16 एक Region में रहता है. उसके अंदर हर subnet एक Availability Zone में रहता है. Internet से आई request internet gateway से अंदर आती है और सिर्फ public subnet तक पहुँचती है, क्योंकि सिर्फ उसी का route table IGW की ओर जाता है.
| Housing society | AWS | What it really does |
|---|---|---|
| The society and its boundary wall | VPC | An isolated private IP range (CIDR block) in one Region |
| Wings A, B and C | Subnets | Smaller IP ranges carved out of the VPC range, each in one AZ |
| Main gate to the road | Internet gateway | Connects the VPC to the internet |
| Direction board near the gate | Route table | Decides where packets for each destination go next |
| Security guard at a wing entrance | Network ACL | Stateless allow and deny rules at the subnet boundary |
| Lock on each flat's door | Security group | Stateful allow rules on each instance's network interface |
The default VPC
Every AWS account gets a default VPC in each Region, ready to use. That is why your first instance in Chapter 5 got a public IP and opened in the browser straight away. It comes with:
- the CIDR block
172.31.0.0/16, - one default subnet in every AZ of the Region, each a
/20(4,096 addresses), - an internet gateway already attached, and a main route table with
0.0.0.0/0→ internet gateway, - auto-assign public IPv4 turned on in the default subnets,
- a default security group and a default network ACL that allows all traffic.
A custom VPC
A custom VPC is one you create. You choose its CIDR block, design the subnets and decide which of them may reach the internet. Nothing in it is public until you add an internet gateway and a route to it.
| Default VPC | Custom VPC | |
|---|---|---|
| Created by | AWS, automatically | You |
| IPv4 CIDR | 172.31.0.0/16 |
You choose, from /16 to /28 |
| Subnets | One public /20 per AZ |
Whatever you design (public and private) |
| Internet gateway | Already attached | You create and attach it |
| Public IP on new instances | On in default subnets | Off, unless you enable it per subnet |
| Good for | Quick tests and learning EC2 | Real projects with private web, app and database tiers |
Ravindra Bagale's Tip
Many students delete the default VPC as "cleanup", and then no subnet shows up when they launch a new instance. Don't touch the default VPC. If you delete it by mistake, you can recreate it from Your VPCs → Actions → Create default VPC. Keep this in mind!
Ravindra Bagale's Tip – मराठी
बरेच students "cleanup" म्हणून default VPC delete करतात, आणि मग नवीन instance launch करताना subnet च सापडत नाही. Default VPC ला हात लावू नका. चुकून delete झाला तर Your VPCs → Actions → Create default VPC ने परत बनवता येतो. ध्यान रखो!
Ravindra Bagale's Tip – हिंदी
बहुत से students "cleanup" के नाम पर default VPC delete कर देते हैं, और फिर नया instance launch करते समय subnet ही नहीं मिलता. Default VPC को हाथ मत लगाओ. गलती से delete हो जाए तो Your VPCs → Actions → Create default VPC से वापस बना सकते हो. ध्यान रखो!
Lab
Chala, open VPC → Your VPCs and find the VPC marked Default VPC: Yes. Write down its CIDR. Then open Subnets, filter by that VPC and count the subnets: the number should match the number of AZs in the Region. Finally open Route tables and find the route 0.0.0.0/0 → igw-....
Step-by-step guide