Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

Practice Questions and Lab Exercises

Come on, now practice! After every lab, delete the NAT gateway, release the Elastic IP and delete the VPC – a clean account is also a skill.

  1. What are the three private IPv4 ranges? Which CIDR sizes does AWS allow for a VPC?
  2. How many usable IPs does a /26 subnet have in AWS? Why not 64?
  3. Split 10.0.0.0/16 into four /18 subnets and write their ranges.
  4. A subnet is named public-subnet but instances in it cannot reach the internet. List three things to check.
  5. Why is a NACL called stateless? Which outbound rule does a web subnet need because of this?
  6. Write NACL inbound rules that block 203.0.113.0/24 but allow HTTP and HTTPS from everyone else.
  7. Why must a NAT gateway be in a public subnet? What happens to its routes when you delete it?
  8. Lab: Create society-vpc with three subnets, an IGW, public-rt and private-rt using VPC only, then delete it and recreate it with VPC and more and compare.
  9. Lab: Launch a bastion and a private instance; SSH to the private one with ssh -J and confirm yum works only after adding the NAT route.
  10. Lab: Build the full Nginx → PHP-FPM → MariaDB project, show the students list in the browser, test every hop, then clean up completely.

Got it? VPC, subnets, route tables, NACL, security groups, NAT and bastion – this is the foundation of AWS networking. Well done, friends, you have completed all the AWS chapters! Now do this project again on your own.

Quick Revision

  • VPC: isolated network in one Region; CIDR /16 to /28 from 10/8, 172.16/12, 192.168/16. Default VPC 172.31.0.0/16 (public default subnets); custom VPC = you build everything. Default quota 5 VPCs per Region.
  • Subnet: part of the VPC CIDR, lives in exactly one AZ; 5 IPs reserved per subnet; default quota 200 subnets per VPC. 3-tier = 3 subnets (web public, app private, db private); 2 AZs = 6.
  • IGW + route tables: one IGW per VPC. Every route table has the local route. Public RT: 0.0.0.0/0 → igw-; private RT: 0.0.0.0/0 → nat-. Public/private is decided by the route table, not the name.
  • NACL: subnet level, stateless, numbered rules (lowest first, first match wins, final * deny). Needs outbound ephemeral ports 1024–65535. Block an IP with a deny rule numbered below the allow (90 before 100).
  • Security group: instance level, stateful, allow only, all rules evaluated; chain by SG ID (web-sg → app-sg → db-sg).
  • Bastion + NAT: bastion in public subnet, SSH via ssh-add + ssh -J/ssh -A, never copy the key. NAT gateway in public subnet with an Elastic IP, billed per hour + per GB: delete it and release the EIP after the lab.
  • Project: Nginx (fastcgi_pass 10.0.2.10:9000, PHP files on the app server) → PHP-FPM (listen = 0.0.0.0:9000, listen.allowed_clients = 10.0.1.10) → MariaDB (bind-address, user 'app'@'10.0.2.%').