Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
Practice Questions and Lab Exercises
Come on, now practice! After every lab, delete the NAT gateway, release the Elastic IP and delete the VPC – a clean account is also a skill.
चला, आता प्रॅक्टिस! प्रत्येक लॅब नंतर NAT गेटवे डिलीट, Elastic IP रिलीज आणि VPC डिलीट करा – स्वच्छ अकाउंट ही पण एक स्किल आहे.
चलो, अब प्रैक्टिस! हर लैब के बाद NAT गेटवे डिलीट, Elastic IP रिलीज़ और VPC डिलीट करो – साफ अकाउंट भी एक स्किल है.
- What are the three private IPv4 ranges? Which CIDR sizes does AWS allow for a VPC?
- How many usable IPs does a /26 subnet have in AWS? Why not 64?
- Split
10.0.0.0/16into four /18 subnets and write their ranges. - A subnet is named
public-subnetbut instances in it cannot reach the internet. List three things to check. - Why is a NACL called stateless? Which outbound rule does a web subnet need because of this?
- Write NACL inbound rules that block
203.0.113.0/24but allow HTTP and HTTPS from everyone else. - Why must a NAT gateway be in a public subnet? What happens to its routes when you delete it?
- Lab: Create
society-vpcwith three subnets, an IGW,public-rtandprivate-rtusing VPC only, then delete it and recreate it with VPC and more and compare. - Lab: Launch a bastion and a private instance; SSH to the private one with
ssh -Jand confirmyumworks only after adding the NAT route. - Lab: Build the full Nginx → PHP-FPM → MariaDB project, show the students list in the browser, test every hop, then clean up completely.
Got it? VPC, subnets, route tables, NACL, security groups, NAT and bastion – this is the foundation of AWS networking. Well done, friends, you have completed all the AWS chapters! Now do this project again on your own.
समजलं का? VPC, सबनेट्स, राउट टेबल्स, NACL, सिक्युरिटी ग्रुप्स, NAT आणि बॅस्टियन – हा AWS नेटवर्किंग चा पाया आहे. शाब्बास मित्रांनो, AWS चे सगळे चॅप्टर्स पूर्ण झाले! आता हा प्रोजेक्ट स्वतः परत करा.
समझ आया? VPC, सबनेट्स, राउट टेबल्स, NACL, सिक्योरिटी ग्रुप्स, NAT और बैस्टियन – यह AWS नेटवर्किंग की नींव है. शाबाश दोस्तों, AWS के सारे चैप्टर्स पूरे हो गए! अब यह प्रोजेक्ट खुद दोबारा करो.
Quick Revision
- VPC: isolated network in one Region; CIDR /16 to /28 from 10/8, 172.16/12, 192.168/16. Default VPC 172.31.0.0/16 (public default subnets); custom VPC = you build everything. Default quota 5 VPCs per Region.
- Subnet: part of the VPC CIDR, lives in exactly one AZ; 5 IPs reserved per subnet; default quota 200 subnets per VPC. 3-tier = 3 subnets (web public, app private, db private); 2 AZs = 6.
- IGW + route tables: one IGW per VPC. Every route table has the
localroute. Public RT:0.0.0.0/0 → igw-; private RT:0.0.0.0/0 → nat-. Public/private is decided by the route table, not the name. - NACL: subnet level, stateless, numbered rules (lowest first, first match wins, final
*deny). Needs outbound ephemeral ports 1024–65535. Block an IP with a deny rule numbered below the allow (90 before 100). - Security group: instance level, stateful, allow only, all rules evaluated; chain by SG ID (web-sg → app-sg → db-sg).
- Bastion + NAT: bastion in public subnet, SSH via
ssh-add+ssh -J/ssh -A, never copy the key. NAT gateway in public subnet with an Elastic IP, billed per hour + per GB: delete it and release the EIP after the lab. - Project: Nginx (
fastcgi_pass 10.0.2.10:9000, PHP files on the app server) → PHP-FPM (listen = 0.0.0.0:9000,listen.allowed_clients = 10.0.1.10) → MariaDB (bind-address, user'app'@'10.0.2.%').