Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

15.6 Route tables: public and private subnets

Near the society gate there is a direction board: "A wing – to the left, parking – downstairs, way out – main gate". A route table is exactly like that – it tells every packet which way to go. And what is a public subnet? The wing whose board says "way out – main gate" is the public one. No magic beyond that.

A route table is a list of routes. Each route has a destination (a CIDR block) and a target (where to send matching packets). When several routes match, the most specific one (the longest prefix) wins.

  • Every route table contains the local route for the VPC CIDR, for example 10.0.0.0/16 → local. You cannot delete it. It is why all subnets in a VPC can reach each other (if the security groups and network ACLs allow it).
  • Each subnet is associated with exactly one route table. A subnet you do not associate explicitly uses the VPC's main route table.
  • One route table can serve many subnets.

Public route table and private route table

public-rt (associated with web-public-1a):

Destination Target Meaning
10.0.0.0/16 local Traffic inside the VPC stays inside
0.0.0.0/0 igw-... (society-igw) Everything else goes to the internet gateway

private-rt (associated with app-private-1a and db-private-1a):

Destination Target Meaning
10.0.0.0/16 local Traffic inside the VPC stays inside
0.0.0.0/0 nat-... (NAT gateway, added in 15.9) Outbound-only internet access for updates

What makes a subnet public or private?

Public route table vs private route table The web server in the public subnet follows public-rt: 0.0.0.0/0 goes to the internet gateway, so it reaches the internet directly. The app server in the private subnet follows private-rt: 0.0.0.0/0 goes to the NAT gateway in the public subnet, which then uses the internet gateway. Both tables also have the local route 10.0.0.0/16 for traffic inside the VPC. Public subnet 10.0.1.0/24 public-rt 10.0.0.0/16 → local 0.0.0.0/0 → igw-… Web server NAT gateway Private subnet 10.0.2.0/24 private-rt 10.0.0.0/16 → local 0.0.0.0/0 → nat-… App server IGW Internet web app

The web server follows public-rt: 0.0.0.0/0 goes to the internet gateway. The app server follows private-rt: 0.0.0.0/0 goes to the NAT gateway in the public subnet. Both tables keep the local route for traffic inside the VPC.

A subnet is public only because its route table has a route 0.0.0.0/0 to an internet gateway. There is no "public" checkbox on a subnet. A private subnet has no route to an internet gateway; at most it has a route to a NAT gateway, which allows connections that start inside and go out, never connections that start on the internet.

Public subnet Private subnet
Default route 0.0.0.0/0 → internet gateway 0.0.0.0/0 → NAT gateway, or no default route
Instances get a public IP Yes (auto-assign on, or an Elastic IP) No
Reachable from the internet Yes, if the security group allows No
Typical servers Web servers, load balancers, bastion, NAT gateway App servers, databases

Create the route tables

  1. VPC → Route tables → Create route table → Name public-rt, VPC society-vpc → Create route table.
  2. Routes tab → Edit routes → Add route → Destination 0.0.0.0/0, Target Internet Gateway → society-igw → Save changes.
  3. Subnet associations tab → Edit subnet associations → tick web-public-1a → Save associations.
  4. Create private-rt in society-vpc the same way, and associate app-private-1a and db-private-1a. Leave its routes as they are for now; the NAT route comes in 15.9.
  5. Leave the main route table with only the local route. Then any new subnet you forget to associate stays private, which is the safe default.
aws ec2 create-route-table --vpc-id vpc-0123456789abcdef0
aws ec2 create-route --route-table-id rtb-0aaa1111bbbb2222c --destination-cidr-block 0.0.0.0/0 --gateway-id igw-0123456789abcdef0
aws ec2 associate-route-table --route-table-id rtb-0aaa1111bbbb2222c --subnet-id subnet-0aaa1111bbbb2222c

Ravindra Bagale's Tip

Many students add the IGW route in public-rt but forget the Subnet associations. Then the browser times out even though the instance has a public IP, because the subnet still uses the main route table. The subnet must appear in the route table's Subnet associations tab. And never give the main route table an IGW route – new subnets become public by mistake.

Lab

Chala, create public-rt and private-rt, add the internet gateway route only to public-rt, and associate the subnets. Then open each subnet's Route table tab and say out loud whether it is public or private, and why.