Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
15.6 Route tables: public and private subnets
Near the society gate there is a direction board: "A wing – to the left, parking – downstairs, way out – main gate". A route table is exactly like that – it tells every packet which way to go. And what is a public subnet? The wing whose board says "way out – main gate" is the public one. No magic beyond that.
Society च्या gate जवळ direction board असतो: "A wing – डावीकडे, parking – खाली, बाहेर जायचं – main gate". Route table अगदी असाच – प्रत्येक packet ला सांगतो कोणत्या दिशेने जा. आणि public subnet म्हणजे काय? ज्या wing च्या board वर "बाहेर – main gate" लिहिलं आहे, तीच public. बाकी काही जादू नाही.
Society के gate के पास direction board होता है: "A wing – बाईं ओर, parking – नीचे, बाहर जाना – main gate". Route table बिल्कुल ऐसा ही है – हर packet को बताता है किस दिशा में जाना है. और public subnet क्या है? जिस wing के board पर "बाहर – main gate" लिखा है, वही public. इसके अलावा कोई जादू नहीं.
A route table is a list of routes. Each route has a destination (a CIDR block) and a target (where to send matching packets). When several routes match, the most specific one (the longest prefix) wins.
- Every route table contains the local route for the VPC CIDR, for example
10.0.0.0/16→local. You cannot delete it. It is why all subnets in a VPC can reach each other (if the security groups and network ACLs allow it). - Each subnet is associated with exactly one route table. A subnet you do not associate explicitly uses the VPC's main route table.
- One route table can serve many subnets.
Public route table and private route table
public-rt (associated with web-public-1a):
| Destination | Target | Meaning |
|---|---|---|
10.0.0.0/16 |
local |
Traffic inside the VPC stays inside |
0.0.0.0/0 |
igw-... (society-igw) |
Everything else goes to the internet gateway |
private-rt (associated with app-private-1a and db-private-1a):
| Destination | Target | Meaning |
|---|---|---|
10.0.0.0/16 |
local |
Traffic inside the VPC stays inside |
0.0.0.0/0 |
nat-... (NAT gateway, added in 15.9) |
Outbound-only internet access for updates |
What makes a subnet public or private?
The web server follows public-rt: 0.0.0.0/0 goes to the internet gateway. The app server follows private-rt: 0.0.0.0/0 goes to the NAT gateway in the public subnet. Both tables keep the local route for traffic inside the VPC.
Web server public-rt पाळतो: 0.0.0.0/0 internet gateway कडे जातो. App server private-rt पाळतो: 0.0.0.0/0 public subnet मधल्या NAT gateway कडे जातो. दोन्ही route tables मध्ये VPC च्या आतल्या traffic साठी local route असतो.
Web server public-rt मानता है: 0.0.0.0/0 internet gateway की ओर जाता है. App server private-rt मानता है: 0.0.0.0/0 public subnet के NAT gateway की ओर जाता है. दोनों route tables में VPC के अंदर के traffic के लिए local route रहता है.
A subnet is public only because its route table has a route 0.0.0.0/0 to an internet gateway. There is no "public" checkbox on a subnet. A private subnet has no route to an internet gateway; at most it has a route to a NAT gateway, which allows connections that start inside and go out, never connections that start on the internet.
| Public subnet | Private subnet | |
|---|---|---|
| Default route | 0.0.0.0/0 → internet gateway |
0.0.0.0/0 → NAT gateway, or no default route |
| Instances get a public IP | Yes (auto-assign on, or an Elastic IP) | No |
| Reachable from the internet | Yes, if the security group allows | No |
| Typical servers | Web servers, load balancers, bastion, NAT gateway | App servers, databases |
Create the route tables
- VPC → Route tables → Create route table → Name
public-rt, VPCsociety-vpc→ Create route table. - Routes tab → Edit routes → Add route → Destination
0.0.0.0/0, Target Internet Gateway →society-igw→ Save changes. - Subnet associations tab → Edit subnet associations → tick
web-public-1a→ Save associations. - Create
private-rtinsociety-vpcthe same way, and associateapp-private-1aanddb-private-1a. Leave its routes as they are for now; the NAT route comes in 15.9. - Leave the main route table with only the local route. Then any new subnet you forget to associate stays private, which is the safe default.
aws ec2 create-route-table --vpc-id vpc-0123456789abcdef0
aws ec2 create-route --route-table-id rtb-0aaa1111bbbb2222c --destination-cidr-block 0.0.0.0/0 --gateway-id igw-0123456789abcdef0
aws ec2 associate-route-table --route-table-id rtb-0aaa1111bbbb2222c --subnet-id subnet-0aaa1111bbbb2222c
Ravindra Bagale's Tip
Many students add the IGW route in public-rt but forget the Subnet associations. Then the browser times out even though the instance has a public IP, because the subnet still uses the main route table. The subnet must appear in the route table's Subnet associations tab. And never give the main route table an IGW route – new subnets become public by mistake.
Ravindra Bagale's Tip – मराठी
बरेच students public-rt मध्ये IGW चा route add करतात पण Subnet associations करायला विसरतात. मग instance ला public IP असूनही browser मध्ये timeout येतो, कारण subnet अजून main route table वापरतो. Route table च्या Subnet associations tab मध्ये subnet दिसला पाहिजे. आणि main route table ला IGW route कधीच देऊ नका – नवीन subnets चुकून public होतात.
Ravindra Bagale's Tip – हिंदी
बहुत से students public-rt में IGW का route add करते हैं पर Subnet associations करना भूल जाते हैं. फिर instance के पास public IP होने के बावजूद browser में timeout आता है, क्योंकि subnet अभी भी main route table इस्तेमाल करता है. Route table के Subnet associations tab में subnet दिखना चाहिए. और main route table को IGW route कभी मत दो – नए subnets गलती से public हो जाते हैं.
Lab
Chala, create public-rt and private-rt, add the internet gateway route only to public-rt, and associate the subnets. Then open each subnet's Route table tab and say out loud whether it is public or private, and why.
Step-by-step guide