Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

15.3 Subnets: default and custom subnets, CIDR and limits

A society has wings – A wing, B wing. In the same way a VPC has subnets. And every wing stands on one piece of land – just as every subnet lives in exactly one Availability Zone. Note: a single subnet never spreads across two AZs.

A subnet is a range of IP addresses inside the VPC's CIDR block. Every subnet sits in exactly one Availability Zone; it cannot span two AZs, and you cannot move it to another AZ later. Instances get their private IP from the subnet they are launched into.

  • Default subnets exist only in the default VPC: one per AZ, each /20, with auto-assign public IPv4 turned on.
  • Custom subnets are the ones you create. Their CIDR must fit inside the VPC CIDR, must not overlap another subnet in the VPC, and must be between /16 and /28.
Splitting a /16 VPC into /24 subnets The VPC 10.0.0.0/16 has 65,536 addresses. It is split into /24 subnets of 256 addresses each: 10.0.1.0/24, 10.0.2.0/24 and 10.0.3.0/24, up to 256 such subnets. In every subnet AWS reserves 5 addresses: .0 network, .1 VPC router, .2 DNS, .3 future use and .255 broadcast, so 251 are usable. VPC 10.0.0.0/16 16 fixed bits · 2^16 = 65,536 addresses 10.0.1.0/24256 addresses 10.0.2.0/24256 addresses 10.0.3.0/24256 addresses … up to 256 /24 blocks(default quota 200 subnets) Inside 10.0.1.0/24, AWS keeps 5 addresses: 10.0.1.0network 10.0.1.1VPC router 10.0.1.2DNS 10.0.1.3future use 10.0.1.255broadcast Usable: 10.0.1.4 – 10.0.1.254 = 256 − 5 = 251 IPs

A /16 VPC has 65,536 addresses. Split into /24 subnets, each gets 256 addresses, but AWS reserves 5 in every subnet (network, VPC router, DNS, future use, broadcast), so 251 are usable.

How many IPs can I really use? (5 are reserved)

AWS reserves 5 addresses in every subnet. For 10.0.1.0/24:

Address Reserved for
10.0.1.0 Network address
10.0.1.1 The VPC router
10.0.1.2 The Amazon-provided DNS server
10.0.1.3 Future use by AWS
10.0.1.255 Network broadcast address (AWS does not support broadcast, so it is reserved)

So a /24 gives 256 − 5 = 251 usable addresses, and a /28 gives only 16 − 5 = 11.

How many subnets can a VPC have?

  • Quota: 200 subnets per VPC by default (you can request more). A Region allows 5 VPCs by default.
  • Maths: a /16 VPC split into /24 subnets gives 2^(24 − 16) = 256 possible subnets: 10.0.0.0/24, 10.0.1.0/24, 10.0.2.0/24 … 10.0.255.0/24. The 200 quota is reached first.

Our subnet plan

Subnet name CIDR AZ What runs there Type
web-public-1a 10.0.1.0/24 ap-south-1a Nginx web server, bastion host, NAT gateway Public
app-private-1a 10.0.2.0/24 ap-south-1a PHP-FPM application server Private
db-private-1a 10.0.3.0/24 ap-south-1a MySQL (MariaDB) database server Private

Create the subnets

  1. VPC → Subnets → Create subnet → VPC ID: society-vpc.
  2. Subnet name web-public-1a, Availability Zone ap-south-1a, IPv4 subnet CIDR block 10.0.1.0/24.
  3. Click Add new subnet and repeat for app-private-1a (10.0.2.0/24) and db-private-1a (10.0.3.0/24), both in ap-south-1a.
  4. Click Create subnet.
  5. Select web-public-1a → Actions → Edit subnet settings → tick Enable auto-assign public IPv4 address → Save. Only this subnet gets it.
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.0.1.0/24 \
  --availability-zone ap-south-1a --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=web-public-1a}]'
aws ec2 modify-subnet-attribute --subnet-id subnet-0aaa1111bbbb2222c --map-public-ip-on-launch

In the subnet list, the Available IPv4 addresses column shows 251 for each new /24. That is the reserved-5 rule in action.

Ravindra Bagale's Tip

Many students think 256 servers fit in a /24 subnet. No! AWS keeps 5 IPs in every subnet – only 251 in a /24, and just 11 in a /28. If you make a small subnet and the servers grow later, you run out of IPs, and a subnet's CIDR cannot be changed later. Take a slightly bigger subnet from the start.

Lab

Chala, create the three subnets above and enable auto-assign public IPv4 only on web-public-1a. Check the Available IPv4 addresses column. Then try to create a fourth subnet 10.0.1.128/25: the console refuses, because it overlaps 10.0.1.0/24.