Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
15.2 How to create a custom VPC and choose its CIDR block
Now let's build our own society. First question: how big is the society? That is, how many IP addresses will we need – this is the CIDR. So the very first job – choose the IP range. Make this decision once and think it through, because the primary CIDR of a VPC cannot be changed later.
आता आपली स्वतःची society बांधूया. पहिला प्रश्न: society किती मोठी? म्हणजे किती IP addresses लागतील – हाच CIDR. तर सगळ्यात पहिलं काम – IP range निवडणं. हा निर्णय एकदाच, विचार करून घ्या, कारण VPC चा primary CIDR नंतर बदलता येत नाही.
अब अपनी खुद की society बनाते हैं. पहला सवाल: society कितनी बड़ी? यानी कितने IP addresses लगेंगे – यही CIDR है. तो सबसे पहला काम – IP range चुनना. यह फैसला एक ही बार, सोच-समझकर लो, क्योंकि VPC का primary CIDR बाद में बदला नहीं जा सकता.
A CIDR block such as 10.0.0.0/16 describes a range of IP addresses. An IPv4 address has 32 bits. The number after the slash tells how many of those bits are fixed (the network part). The remaining bits are free for hosts:
/16→ 16 bits fixed, 32 − 16 = 16 bits free → 2^16 = 65,536 addresses.10.0.0.0/16therefore runs from10.0.0.0to10.0.255.255.- Count it like on the board:
10.0.0.255+ 1 =10.0.1.0, and so on up to10.0.255.255.
| CIDR | Free host bits | Total addresses | Typical use |
|---|---|---|---|
/16 |
16 | 65,536 | A whole VPC (the largest AWS allows) |
/20 |
12 | 4,096 | Default subnets in the default VPC |
/24 |
8 | 256 | A normal custom subnet |
/26 |
6 | 64 | A small subnet |
/28 |
4 | 16 | The smallest VPC or subnet AWS allows |
Formula: addresses = 2^(32 − prefix). A bigger number after the slash means a smaller network.
Which ranges should I use?
Use the private ranges from RFC 1918, which are never routed on the internet:
| Private range | CIDR | Addresses |
|---|---|---|
| 10.0.0.0 – 10.255.255.255 | 10.0.0.0/8 |
16.7 million |
| 172.16.0.0 – 172.31.255.255 | 172.16.0.0/12 |
1 million |
| 192.168.0.0 – 192.168.255.255 | 192.168.0.0/16 |
65,536 |
AWS accepts an IPv4 VPC CIDR with a netmask between /16 and /28. So 10.0.0.0/8 is too big for one VPC; you take a /16 out of it, such as 10.0.0.0/16. Avoid 172.31.0.0/16 (the default VPC already uses it) and 192.168.x.x (most home Wi-Fi routers use it, which clashes when you later connect over VPN). You cannot change the primary CIDR of a VPC later; you can only add secondary CIDR blocks (5 IPv4 blocks per VPC by default).
Create the VPC in the console
- Open VPC → Your VPCs → Create VPC.
- Resources to create: choose VPC only. (VPC and more builds subnets, route tables, an internet gateway and optional NAT gateways in one go. It is great later; in this chapter we build each piece by hand to understand it.)
- Name tag:
society-vpc. - IPv4 CIDR block: IPv4 CIDR manual input →
10.0.0.0/16. - IPv6 CIDR block: No IPv6 CIDR block. Tenancy: Default.
- Click Create VPC.
- Select the new VPC → Actions → Edit VPC settings → tick Enable DNS hostnames → Save. (In a VPC created with VPC only, DNS hostnames start switched off; with it on, instances with a public IP also get a public DNS name.)
The same with the AWS CLI:
aws ec2 create-vpc --cidr-block 10.0.0.0/16 \
--tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=society-vpc}]'
aws ec2 modify-vpc-attribute --vpc-id vpc-0123456789abcdef0 --enable-dns-hostnames '{"Value":true}'
A new VPC automatically gets a main route table (with only the local route), a default network ACL (allows all) and a default security group. It has no subnets and no internet gateway yet.
Ravindra Bagale's Tip
Many students give the VPC a /24 or /28 because "it's a small lab" – and then there is no room for three or four subnets. Give the VPC a /16 and the subnets a /24. The primary CIDR cannot be changed later, so plan it on paper first. Remember the order.
Ravindra Bagale's Tip – मराठी
बरेच students "छोटा lab आहे" म्हणून VPC ला /24 किंवा /28 देतात – मग तीन-चार subnets साठी जागा उरत नाही. VPC ला /16 द्या आणि subnets ला /24. Primary CIDR नंतर बदलता येत नाही, म्हणून plan आधी कागदावर करा. क्रम लक्षात ठेवा.
Ravindra Bagale's Tip – हिंदी
बहुत से students "छोटा lab है" सोचकर VPC को /24 या /28 दे देते हैं – फिर तीन-चार subnets के लिए जगह नहीं बचती. VPC को /16 दो और subnets को /24. Primary CIDR बाद में बदला नहीं जा सकता, इसलिए plan पहले कागज़ पर करो. क्रम याद रखो.
Lab
Chala, create society-vpc with 10.0.0.0/16 using VPC only, and turn on DNS hostnames. Then open the VPC's details and write down its main route table ID and default network ACL ID. Both were created for you automatically.
Step-by-step guides