Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
Common Mistakes I See Students Make
Friends, I see these VPC mistakes in every batch – the NAT gateway in a private subnet, forgetting to associate the route table, no ephemeral ports in the NACL. Read them once; it will save you a lot of time.
मित्रांनो, VPC च्या या चुका मी प्रत्येक batch मध्ये बघतो – NAT gateway private subnet मध्ये, route table associate करायला विसरणं, NACL मध्ये ephemeral ports नाहीत. एकदा वाचून ठेवा, खूप वेळ वाचेल.
दोस्तों, VPC की ये गलतियाँ मैं हर batch में देखता हूँ – NAT gateway private subnet में, route table associate करना भूलना, NACL में ephemeral ports नहीं. एक बार पढ़ लो, बहुत समय बचेगा.
- Creating the NAT gateway in a private subnet. It must be in a public subnet; the private route table then points to it.
- Creating a route table but never associating it with a subnet. The subnet silently keeps using the main route table.
- Calling a subnet "public" because of its name. Only a
0.0.0.0/0 → igw-…route makes it public. - Forgetting the outbound ephemeral ports (1024–65535) in a custom NACL. Requests arrive, replies are dropped.
- Putting the deny rule after the allow rule (deny 110 after allow 100). First match wins, so the deny never runs.
- Overlapping CIDR blocks between VPCs you may later want to connect with peering.
- Choosing a /28 VPC or tiny subnets and running out of IPs (remember the 5 reserved per subnet).
- Copying the
.pemkey onto the bastion. Usessh-addandssh -Aorssh -Jinstead. - Opening port 3306 or 9000 to
0.0.0.0/0instead of chaining security groups. - Leaving the NAT gateway and Elastic IP running after the lab. Both are billed per hour.