Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
Interview Questions
These VPC questions definitely come up in cloud and DevOps interviews. In every answer, don't give the housing society example; give the real technical fact – route, rule number, stateful/stateless.
VPC वर हे प्रश्न cloud आणि DevOps interview मध्ये नक्की येतात. प्रत्येक उत्तरात housing society चं example नाही, तर खरं technical fact सांगा – route, rule number, stateful/stateless.
VPC पर ये सवाल cloud और DevOps interview में ज़रूर आते हैं. हर जवाब में housing society का example नहीं, बल्कि असली technical fact बताओ – route, rule number, stateful/stateless.
- Q1. What is a VPC, and what is the difference between the default VPC and a custom VPC?
- A VPC is a logically isolated virtual network in one AWS Region. The default VPC (172.31.0.0/16) is created by AWS with a public default subnet in every AZ, an internet gateway and a route to it. A custom VPC is created by you, with your own CIDR, subnets, route tables and gateways, and nothing is public until you add an IGW route.
- Q2. What CIDR sizes can a VPC and a subnet have, and how many IPs are usable in a /24 subnet?
- Both can be between /16 (65,536 addresses) and /28 (16 addresses), preferably from the private ranges 10.0.0.0/8, 172.16.0.0/12 and 192.168.0.0/16. AWS reserves 5 addresses in every subnet (network, VPC router, DNS, future use, broadcast), so a /24 gives 256 − 5 = 251 usable IPs.
- Q3. What makes a subnet public?
- Its route table has a route
0.0.0.0/0→ internet gateway (and instances need a public IP to be reachable). A private subnet has no IGW route; for outbound internet it uses0.0.0.0/0→ NAT gateway. - Q4. How does a NAT gateway work, and where do you create it?
- It lets instances in private subnets start outbound connections (updates, APIs) while blocking inbound connections from the internet. A public NAT gateway is created in a public subnet with an Elastic IP; the private route table sends
0.0.0.0/0to it. It is charged per hour and per GB processed. - Q5. Security group vs network ACL?
- Security group: instance (ENI) level, stateful, allow rules only, all rules evaluated. NACL: subnet level, stateless (return traffic needs its own rule, e.g. ephemeral ports 1024–65535), allow and deny rules, evaluated in rule-number order with the first match winning.
- Q6. How do you block a particular IP address from reaching your web servers?
- Security groups cannot deny, so use the subnet's NACL: add an inbound Deny rule with a lower number than the allow rule, e.g. rule 90 deny all traffic from 203.0.113.25/32 before rule 100 allow HTTP from 0.0.0.0/0. For a range, use a CIDR such as 203.0.113.0/24.
- Q7. What is a bastion host, and how do you SSH to a private instance through it?
- A small hardened instance in a public subnet that is the only SSH entry point. Private instances allow port 22 only from the bastion's security group. Load the key into the agent (
ssh-add key.pem) and usessh -J ec2-user@bastion ec2-user@10.0.2.10orssh -A; never copy the private key to the bastion. AWS Systems Manager Session Manager is an alternative with no open port. - Q8. Design a 3-tier web application network in a VPC.
- Web tier (Nginx/ALB) in public subnets, app tier (PHP-FPM) in private subnets, database in private subnets, in at least 2 AZs for high availability (6 subnets; an RDS DB subnet group needs subnets in 2 AZs). Security group chaining: web-sg 80/443 from the internet, app-sg only from web-sg, db-sg 3306 only from app-sg. NAT gateway for private outbound traffic, bastion or Session Manager for admin access.