Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

15.1 What is a VPC? Default VPC vs custom VPC

Friends, think of a VPC as a housing society. The society's boundary wall is the VPC – who lives inside, in which wing, where the gate is – the society decides everything. But note: this is only to help you understand. Technically, a VPC is your own network inside an AWS Region, isolated from other customers, and you choose its IP range (CIDR).

A VPC (Virtual Private Cloud) is your own logically isolated virtual network inside one AWS Region. Every EC2 instance, RDS database or load balancer you launch gets its private IP address from a VPC. A VPC covers all the Availability Zones (AZs) of its Region, while each of its subnets lives in exactly one AZ.

A custom VPC with three subnets and an internet gateway Inside the region ap-south-1 sits the VPC 10.0.0.0/16. It contains three subnets in one Availability Zone: web-public-1a 10.0.1.0/24, app-private-1a 10.0.2.0/24 and db-private-1a 10.0.3.0/24. A request from the internet enters through the internet gateway attached to the VPC and reaches only the public subnet. Internet Region ap-south-1 (Mumbai) society-vpc 10.0.0.0/16 AZ ap-south-1a IGW web-public-1a10.0.1.0/24 · route 0.0.0.0/0 → IGW Nginx reached app-private-1a10.0.2.0/24 · no route from the internet db-private-1a10.0.3.0/24 · no route from the internet HTTP

The VPC 10.0.0.0/16 lives in one Region. Inside it, each subnet lives in one Availability Zone. A request from the internet enters through the internet gateway and can reach only the public subnet, because only its route table points to the IGW.

Housing society AWS What it really does
The society and its boundary wall VPC An isolated private IP range (CIDR block) in one Region
Wings A, B and C Subnets Smaller IP ranges carved out of the VPC range, each in one AZ
Main gate to the road Internet gateway Connects the VPC to the internet
Direction board near the gate Route table Decides where packets for each destination go next
Security guard at a wing entrance Network ACL Stateless allow and deny rules at the subnet boundary
Lock on each flat's door Security group Stateful allow rules on each instance's network interface

The default VPC

Every AWS account gets a default VPC in each Region, ready to use. That is why your first instance in Chapter 5 got a public IP and opened in the browser straight away. It comes with:

  • the CIDR block 172.31.0.0/16,
  • one default subnet in every AZ of the Region, each a /20 (4,096 addresses),
  • an internet gateway already attached, and a main route table with 0.0.0.0/0 → internet gateway,
  • auto-assign public IPv4 turned on in the default subnets,
  • a default security group and a default network ACL that allows all traffic.

A custom VPC

A custom VPC is one you create. You choose its CIDR block, design the subnets and decide which of them may reach the internet. Nothing in it is public until you add an internet gateway and a route to it.

Default VPC Custom VPC
Created by AWS, automatically You
IPv4 CIDR 172.31.0.0/16 You choose, from /16 to /28
Subnets One public /20 per AZ Whatever you design (public and private)
Internet gateway Already attached You create and attach it
Public IP on new instances On in default subnets Off, unless you enable it per subnet
Good for Quick tests and learning EC2 Real projects with private web, app and database tiers

Ravindra Bagale's Tip

Many students delete the default VPC as "cleanup", and then no subnet shows up when they launch a new instance. Don't touch the default VPC. If you delete it by mistake, you can recreate it from Your VPCs → Actions → Create default VPC. Keep this in mind!

Lab

Chala, open VPC → Your VPCs and find the VPC marked Default VPC: Yes. Write down its CIDR. Then open Subnets, filter by that VPC and count the subnets: the number should match the number of AZs in the Region. Finally open Route tables and find the route 0.0.0.0/0 → igw-....