Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

Common Mistakes I See Students Make

Friends, I see these VPC mistakes in every batch – the NAT gateway in a private subnet, forgetting to associate the route table, no ephemeral ports in the NACL. Read them once; it will save you a lot of time.

  • Creating the NAT gateway in a private subnet. It must be in a public subnet; the private route table then points to it.
  • Creating a route table but never associating it with a subnet. The subnet silently keeps using the main route table.
  • Calling a subnet "public" because of its name. Only a 0.0.0.0/0 → igw-… route makes it public.
  • Forgetting the outbound ephemeral ports (1024–65535) in a custom NACL. Requests arrive, replies are dropped.
  • Putting the deny rule after the allow rule (deny 110 after allow 100). First match wins, so the deny never runs.
  • Overlapping CIDR blocks between VPCs you may later want to connect with peering.
  • Choosing a /28 VPC or tiny subnets and running out of IPs (remember the 5 reserved per subnet).
  • Copying the .pem key onto the bastion. Use ssh-add and ssh -A or ssh -J instead.
  • Opening port 3306 or 9000 to 0.0.0.0/0 instead of chaining security groups.
  • Leaving the NAT gateway and Elastic IP running after the lab. Both are billed per hour.