Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
15.3 Subnets: default and custom subnets, CIDR and limits
A society has wings – A wing, B wing. In the same way a VPC has subnets. And every wing stands on one piece of land – just as every subnet lives in exactly one Availability Zone. Note: a single subnet never spreads across two AZs.
Society मध्ये wings असतात – A wing, B wing. तसेच VPC मध्ये subnets. आणि प्रत्येक wing एकाच जमिनीवर उभी असते – तसाच प्रत्येक subnet एकाच Availability Zone मध्ये असतो. लक्ष द्या, एकच subnet दोन AZ मध्ये पसरत नाही.
Society में wings होते हैं – A wing, B wing. वैसे ही VPC में subnets. और हर wing एक ही ज़मीन पर खड़ी होती है – वैसे ही हर subnet एक ही Availability Zone में होता है. ध्यान दो, एक subnet कभी दो AZ में नहीं फैलता.
A subnet is a range of IP addresses inside the VPC's CIDR block. Every subnet sits in exactly one Availability Zone; it cannot span two AZs, and you cannot move it to another AZ later. Instances get their private IP from the subnet they are launched into.
- Default subnets exist only in the default VPC: one per AZ, each
/20, with auto-assign public IPv4 turned on. - Custom subnets are the ones you create. Their CIDR must fit inside the VPC CIDR, must not overlap another subnet in the VPC, and must be between
/16and/28.
A /16 VPC has 65,536 addresses. Split into /24 subnets, each gets 256 addresses, but AWS reserves 5 in every subnet (network, VPC router, DNS, future use, broadcast), so 251 are usable.
/16 VPC मध्ये 65,536 addresses असतात. /24 subnets मध्ये वाटले तर प्रत्येकाला 256 addresses मिळतात, पण AWS प्रत्येक subnet मध्ये 5 राखून ठेवतो (network, VPC router, DNS, future use, broadcast), म्हणून 251 वापरता येतात.
/16 VPC में 65,536 addresses होते हैं. /24 subnets में बाँटने पर हर एक को 256 addresses मिलते हैं, पर AWS हर subnet में 5 रख लेता है (network, VPC router, DNS, future use, broadcast), इसलिए 251 इस्तेमाल हो सकते हैं.
How many IPs can I really use? (5 are reserved)
AWS reserves 5 addresses in every subnet. For 10.0.1.0/24:
| Address | Reserved for |
|---|---|
10.0.1.0 |
Network address |
10.0.1.1 |
The VPC router |
10.0.1.2 |
The Amazon-provided DNS server |
10.0.1.3 |
Future use by AWS |
10.0.1.255 |
Network broadcast address (AWS does not support broadcast, so it is reserved) |
So a /24 gives 256 − 5 = 251 usable addresses, and a /28 gives only 16 − 5 = 11.
How many subnets can a VPC have?
- Quota: 200 subnets per VPC by default (you can request more). A Region allows 5 VPCs by default.
- Maths: a
/16VPC split into/24subnets gives 2^(24 − 16) = 256 possible subnets:10.0.0.0/24,10.0.1.0/24,10.0.2.0/24…10.0.255.0/24. The 200 quota is reached first.
Our subnet plan
| Subnet name | CIDR | AZ | What runs there | Type |
|---|---|---|---|---|
web-public-1a |
10.0.1.0/24 |
ap-south-1a |
Nginx web server, bastion host, NAT gateway | Public |
app-private-1a |
10.0.2.0/24 |
ap-south-1a |
PHP-FPM application server | Private |
db-private-1a |
10.0.3.0/24 |
ap-south-1a |
MySQL (MariaDB) database server | Private |
Create the subnets
- VPC → Subnets → Create subnet → VPC ID:
society-vpc. - Subnet name
web-public-1a, Availability Zoneap-south-1a, IPv4 subnet CIDR block10.0.1.0/24. - Click Add new subnet and repeat for
app-private-1a(10.0.2.0/24) anddb-private-1a(10.0.3.0/24), both inap-south-1a. - Click Create subnet.
- Select
web-public-1a→ Actions → Edit subnet settings → tick Enable auto-assign public IPv4 address → Save. Only this subnet gets it.
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.0.1.0/24 \
--availability-zone ap-south-1a --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=web-public-1a}]'
aws ec2 modify-subnet-attribute --subnet-id subnet-0aaa1111bbbb2222c --map-public-ip-on-launch
In the subnet list, the Available IPv4 addresses column shows 251 for each new /24. That is the reserved-5 rule in action.
Ravindra Bagale's Tip
Many students think 256 servers fit in a /24 subnet. No! AWS keeps 5 IPs in every subnet – only 251 in a /24, and just 11 in a /28. If you make a small subnet and the servers grow later, you run out of IPs, and a subnet's CIDR cannot be changed later. Take a slightly bigger subnet from the start.
Ravindra Bagale's Tip – मराठी
बऱ्याच students ना वाटतं /24 subnet मध्ये 256 servers बसतात. नाही! AWS प्रत्येक subnet मधले 5 IPs राखून ठेवतो – /24 मध्ये 251 च, आणि /28 मध्ये फक्त 11. Subnet छोटा बनवला आणि नंतर servers वाढले की IP संपतात, आणि subnet चा CIDR नंतर बदलता येत नाही. आधीच जरा मोठा subnet घ्या.
Ravindra Bagale's Tip – हिंदी
बहुत से students सोचते हैं कि /24 subnet में 256 servers आ जाते हैं. नहीं! AWS हर subnet में 5 IPs रख लेता है – /24 में सिर्फ 251, और /28 में सिर्फ 11. Subnet छोटा बनाया और बाद में servers बढ़े तो IP खत्म हो जाते हैं, और subnet का CIDR बाद में बदला नहीं जा सकता. शुरू से ही थोड़ा बड़ा subnet लो.
Lab
Chala, create the three subnets above and enable auto-assign public IPv4 only on web-public-1a. Check the Available IPv4 addresses column. Then try to create a fourth subnet 10.0.1.128/25: the console refuses, because it overlaps 10.0.1.0/24.
Step-by-step guide