Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

15.2 How to create a custom VPC and choose its CIDR block

Now let's build our own society. First question: how big is the society? That is, how many IP addresses will we need – this is the CIDR. So the very first job – choose the IP range. Make this decision once and think it through, because the primary CIDR of a VPC cannot be changed later.

A CIDR block such as 10.0.0.0/16 describes a range of IP addresses. An IPv4 address has 32 bits. The number after the slash tells how many of those bits are fixed (the network part). The remaining bits are free for hosts:

  • /16 → 16 bits fixed, 32 − 16 = 16 bits free → 2^16 = 65,536 addresses.
  • 10.0.0.0/16 therefore runs from 10.0.0.0 to 10.0.255.255.
  • Count it like on the board: 10.0.0.255 + 1 = 10.0.1.0, and so on up to 10.0.255.255.
CIDR Free host bits Total addresses Typical use
/16 16 65,536 A whole VPC (the largest AWS allows)
/20 12 4,096 Default subnets in the default VPC
/24 8 256 A normal custom subnet
/26 6 64 A small subnet
/28 4 16 The smallest VPC or subnet AWS allows

Formula: addresses = 2^(32 − prefix). A bigger number after the slash means a smaller network.

Which ranges should I use?

Use the private ranges from RFC 1918, which are never routed on the internet:

Private range CIDR Addresses
10.0.0.0 – 10.255.255.255 10.0.0.0/8 16.7 million
172.16.0.0 – 172.31.255.255 172.16.0.0/12 1 million
192.168.0.0 – 192.168.255.255 192.168.0.0/16 65,536

AWS accepts an IPv4 VPC CIDR with a netmask between /16 and /28. So 10.0.0.0/8 is too big for one VPC; you take a /16 out of it, such as 10.0.0.0/16. Avoid 172.31.0.0/16 (the default VPC already uses it) and 192.168.x.x (most home Wi-Fi routers use it, which clashes when you later connect over VPN). You cannot change the primary CIDR of a VPC later; you can only add secondary CIDR blocks (5 IPv4 blocks per VPC by default).

Create the VPC in the console

  1. Open VPC → Your VPCs → Create VPC.
  2. Resources to create: choose VPC only. (VPC and more builds subnets, route tables, an internet gateway and optional NAT gateways in one go. It is great later; in this chapter we build each piece by hand to understand it.)
  3. Name tag: society-vpc.
  4. IPv4 CIDR block: IPv4 CIDR manual input → 10.0.0.0/16.
  5. IPv6 CIDR block: No IPv6 CIDR block. Tenancy: Default.
  6. Click Create VPC.
  7. Select the new VPC → Actions → Edit VPC settings → tick Enable DNS hostnames → Save. (In a VPC created with VPC only, DNS hostnames start switched off; with it on, instances with a public IP also get a public DNS name.)

The same with the AWS CLI:

aws ec2 create-vpc --cidr-block 10.0.0.0/16 \
  --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=society-vpc}]'
aws ec2 modify-vpc-attribute --vpc-id vpc-0123456789abcdef0 --enable-dns-hostnames '{"Value":true}'

A new VPC automatically gets a main route table (with only the local route), a default network ACL (allows all) and a default security group. It has no subnets and no internet gateway yet.

Ravindra Bagale's Tip

Many students give the VPC a /24 or /28 because "it's a small lab" – and then there is no room for three or four subnets. Give the VPC a /16 and the subnets a /24. The primary CIDR cannot be changed later, so plan it on paper first. Remember the order.

Lab

Chala, create society-vpc with 10.0.0.0/16 using VPC only, and turn on DNS hostnames. Then open the VPC's details and write down its main route table ID and default network ACL ID. Both were created for you automatically.