Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

15.4 Why do we need subnets? The 3-tier layout

What do you think happens if we keep all servers in one subnet? Think... The web server needs a path to the internet, so the database gets the same path too! That is why separate subnets. A society works the same way – a separate wing for visitors, and a separate record room for the office, where nobody from outside can walk straight in.

Subnets let you give different routing and different network rules to different groups of servers. Route tables and network ACLs attach to a subnet, so everything inside it gets the same treatment:

  • Security: the database subnet has no route from the internet at all, so nobody outside can even try to reach it.
  • Smaller blast radius: if the web server is hacked, the attacker still has to cross more rules to reach the data.
  • Clear rules per tier: web, app and database each get their own route table, network ACL and security groups.
  • High availability: subnets in two AZs let the same tier keep running when one AZ has a problem.

The 3-tier architecture

A classic web application has three tiers, and each tier gets its own subnet:

Tier Also called Runs Subnet Reachable from
1. Web Presentation tier Nginx (static files, forwards PHP) Public 10.0.1.0/24 The internet (80/443)
2. App Logic tier PHP-FPM (your code) Private 10.0.2.0/24 Only the web tier
3. Database Data tier MySQL / MariaDB Private 10.0.3.0/24 Only the app tier
               Internet
                  |
          [ Internet gateway ]
                  |
+----------- VPC 10.0.0.0/16 -------------+
|  Public subnet    10.0.1.0/24           |
|    Nginx web server, bastion, NAT GW    |
|              |  port 9000               |
|  Private subnet   10.0.2.0/24           |
|    PHP-FPM app server                   |
|              |  port 3306               |
|  Private subnet   10.0.3.0/24           |
|    MySQL database                       |
+-----------------------------------------+

So 3 tiers need at least 3 subnets, one per tier. That is the design of the project in 15.10–15.12.

High availability: 2 AZs = 6 subnets

In production, each tier runs in two AZs, so the same layout is repeated in a second AZ:

Tier ap-south-1a ap-south-1b
Web (public) 10.0.1.0/24 10.0.11.0/24
App (private) 10.0.2.0/24 10.0.12.0/24
Database (private) 10.0.3.0/24 10.0.13.0/24

Two AWS services even insist on it: an Application Load Balancer needs subnets in at least two AZs, and an RDS DB subnet group must contain subnets in at least two AZs (even for a Single-AZ database). For learning, one AZ is enough and costs less.

Ravindra Bagale's Tip

In interviews they ask: "How many subnets does a 3-tier architecture need?" Many students say "one" or "two". The right answer: at least 3 – one per tier. For high availability, 2 AZs, which means 6 subnets. And an RDS subnet group needs subnets in at least 2 AZs. Say these three points together and the interviewer is happy.

Practice task

Chala, design a network for a fictional college result portal: web, app and database tiers in two AZs. Write a table with six subnet names, CIDR blocks from 10.20.0.0/16, AZs and public or private for each.

Got it? The VPC is the society, subnets are the wings, and a separate wing for every tier. Now let's move on and build the society's main gate – the Internet Gateway.