Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
Come on, friends, now the most important chapter of AWS networking – VPC. Until now we launched every server in the default VPC, and AWS had already built the network for us. Now we build our own network. Picture a housing society: the whole society is the VPC, the wings are subnets, the main gate is the Internet Gateway, the security guard at the wing entrance is the NACL, each flat's lock is the security group, and the direction board near the gate is the route table. At the end we do a real 3-tier project – Nginx, PHP and MySQL in three different subnets. Don't worry, you will get it, slowly slowly you will get it.
चला मित्रांनो, आता AWS networking चा सगळ्यात important chapter – VPC. आजपर्यंत आपण सगळे servers default VPC मध्ये launch केले, आणि network AWS ने आपल्यासाठी आधीच बनवून ठेवलं होतं. आता आपण स्वतःचं network बनवूया. एक housing society डोळ्यासमोर आणा: पूर्ण society म्हणजे VPC, wings म्हणजे subnets, main gate म्हणजे Internet Gateway, wing च्या entrance वरचा security guard म्हणजे NACL, प्रत्येक flat चं कुलूप म्हणजे security group, आणि gate जवळचा direction board म्हणजे route table. शेवटी एक खरा 3-tier project करू – Nginx, PHP आणि MySQL तीन वेगवेगळ्या subnets मध्ये. घाबरू नका, कळेल तुम्हाला, हळू हळू कळेल.
चलो दोस्तों, अब AWS networking का सबसे important chapter – VPC. अब तक हमने सारे servers default VPC में launch किए, और network AWS ने हमारे लिए पहले से बना रखा था. अब हम अपना खुद का network बनाएँगे. एक housing society सामने लाओ: पूरी society यानी VPC, wings यानी subnets, main gate यानी Internet Gateway, wing के entrance पर खड़ा security guard यानी NACL, हर flat का ताला यानी security group, और gate के पास का direction board यानी route table. आखिर में एक असली 3-tier project करेंगे – Nginx, PHP और MySQL तीन अलग-अलग subnets में. घबराओ मत, समझ आएगा, धीरे धीरे समझ आएगा.
What you will learn in this chapter
- Default VPC vs custom VPC
- CIDR blocks for VPCs and subnets
- Public and private subnets
- Internet gateway and route tables
- NACL rules and blocking an IP
- Security group vs NACL
- Bastion host and NAT gateway
- A 3-tier Nginx, PHP, MySQL project
This chapter builds on Chapter 1 (IP addresses, CIDR and NAT), Chapter 5 (EC2 and security groups) and Chapter 10 (PHP with MySQL). Keep the AWS console open in the Asia Pacific (Mumbai) ap-south-1 region and do every step yourself.
Concepts in this chapter
- 15.1What is a VPC? Default VPC vs custom VPC
- 15.2How to create a custom VPC and choose its CIDR block
- 15.3Subnets: default and custom subnets, CIDR and limits
- 15.4Why do we need subnets? The 3-tier layout
- 15.5Internet gateway
- 15.6Route tables: public and private subnets
- 15.7Network ACL: inbound and outbound rules, rule numbers and blocking an IP
- 15.8Security group vs NACL
- 15.9Bastion host (jump server) and NAT gateway
- 15.10Project: build the 3-tier network and launch the servers
- 15.11Project: MySQL, PHP-FPM and Nginx on three tiers
- 15.12Project: test every hop, troubleshoot and clean up