How to Create a Custom VPC in AWS with Subnets, Internet Gateway and Route Tables
To create a custom VPC in AWS, open VPC → Your VPCs → Create VPC, choose VPC only, give it a name and an IPv4 CIDR block such as 10.0.0.0/16. Then create subnets inside it (for example 10.0.1.0/24 public and 10.0.2.0/24 private), create and attach an internet gateway, and make a public route table with 0.0.0.0/0 → igw-… that you associate with the public subnet. A subnet becomes public only because of that route.
Come on, friends! A VPC is our own housing society – the boundary wall (CIDR), wings (subnets), the main gate (internet gateway) and the list of directions on the notice board (route table). The default VPC is a ready-made flat built by AWS; today we build the society ourselves. Don't worry, there are five steps.
चला मित्रांनो! VPC म्हणजे आपली स्वतःची housing society – boundary wall (CIDR), wings (subnets), main gate (internet gateway) आणि notice board वर दिशांची यादी (route table). Default VPC AWS ने बनवलेला readymade flat आहे; आज आपण society स्वतः बांधूया. घाबरू नका, पाच steps आहेत.
चलो दोस्तों! VPC यानी हमारी अपनी housing society – boundary wall (CIDR), wings (subnets), main gate (internet gateway) और notice board पर दिशाओं की list (route table). Default VPC AWS का बनाया readymade flat है; आज हम society खुद बनाएँगे. घबराओ मत, पाँच steps हैं.
Quick answer
Console path (Region: your choice, for example ap-south-1):
VPC → Your VPCs → Create VPC → VPC only
Name: society-vpc IPv4 CIDR: 10.0.0.0/16
Subnets → Create subnet → web-public-1a 10.0.1.0/24, app-private-1a 10.0.2.0/24
Internet gateways → Create → society-igw → Actions → Attach to VPC → society-vpc
Route tables → Create public-rt → Edit routes → 0.0.0.0/0 → Internet Gateway → society-igw
public-rt → Subnet associations → web-public-1a
The same with the AWS CLI:
VPC=$(aws ec2 create-vpc --cidr-block 10.0.0.0/16 --query Vpc.VpcId --output text)
PUB=$(aws ec2 create-subnet --vpc-id $VPC --cidr-block 10.0.1.0/24 --availability-zone ap-south-1a --query Subnet.SubnetId --output text)
IGW=$(aws ec2 create-internet-gateway --query InternetGateway.InternetGatewayId --output text)
aws ec2 attach-internet-gateway --internet-gateway-id $IGW --vpc-id $VPC
RT=$(aws ec2 create-route-table --vpc-id $VPC --query RouteTable.RouteTableId --output text)
aws ec2 create-route --route-table-id $RT --destination-cidr-block 0.0.0.0/0 --gateway-id $IGW
aws ec2 associate-route-table --route-table-id $RT --subnet-id $PUB
What do I need before creating a custom VPC?
- An AWS account and permission to use Amazon VPC (an IAM user with admin rights is fine for learning).
- A CIDR plan. A VPC can be from
/16(65,536 addresses) to/28(16 addresses), preferably from the private ranges10.0.0.0/8,172.16.0.0/12or192.168.0.0/16. Pick one that does not overlap with other networks you may connect later. See AWS VPC CIDR and subnet calculation. - Nothing costs money in this guide: VPCs, subnets, route tables and internet gateways are free. (NAT gateways and public IPv4 addresses are billed, see the NAT guide.)
What does a custom VPC look like?
The VPC 10.0.0.0/16 lives in one Region. Inside it, each subnet lives in one Availability Zone. A request from the internet enters through the internet gateway and can reach only the public subnet, because only its route table points to the IGW.
VPC 10.0.0.0/16 एका Region मध्ये असतो. त्याच्या आत प्रत्येक subnet एका Availability Zone मध्ये असतो. Internet वरून आलेली request internet gateway मधून आत येते आणि फक्त public subnet पर्यंत पोहोचते, कारण फक्त त्याचं route table IGW कडे जातं.
VPC 10.0.0.0/16 एक Region में रहता है. उसके अंदर हर subnet एक Availability Zone में रहता है. Internet से आई request internet gateway से अंदर आती है और सिर्फ public subnet तक पहुँचती है, क्योंकि सिर्फ उसी का route table IGW की ओर जाता है.
A VPC is a logically isolated virtual network in one Region. A subnet is a slice of the VPC's CIDR that lives in exactly one Availability Zone. The internet gateway (IGW) is the VPC's door to the internet, and a route table tells each subnet where to send traffic.
Every account also has a default VPC (172.31.0.0/16) in each Region, with a public default subnet in every AZ. It is handy for quick tests, but in real projects you build a custom VPC so you decide what is public and what is private.
How do I create a custom VPC step by step?
Step 1 — Create the VPC
VPC → Your VPCs → Create VPC → Resources to create: VPC only → Name tag society-vpc → IPv4 CIDR manual input 10.0.0.0/16 → No IPv6 CIDR block → Tenancy Default → Create VPC.
VPC and more creates subnets, route tables, an internet gateway and optionally NAT gateways in one go. It is great once you understand the parts; the first time, build them one by one.
Step 2 — Create the subnets
Subnets → Create subnet → VPC society-vpc → add each subnet:
| Name | Availability Zone | IPv4 subnet CIDR | Purpose |
|---|---|---|---|
web-public-1a |
ap-south-1a | 10.0.1.0/24 |
Web server, bastion, NAT gateway |
app-private-1a |
ap-south-1a | 10.0.2.0/24 |
Application servers |
db-private-1a |
ap-south-1a | 10.0.3.0/24 |
Database |
Each /24 gives 256 addresses, of which AWS reserves 5, so 251 are usable. For the public subnet, select it → Actions → Edit subnet settings → tick Enable auto-assign public IPv4 address, so instances launched there get a public IP.
Step 3 — Create and attach the internet gateway
Internet gateways → Create internet gateway → Name society-igw → Create → Actions → Attach to VPC → society-vpc. The state changes from Detached to Attached. A VPC can have only one internet gateway attached.
Step 4 — Create the public route table
Route tables → Create route table → Name public-rt → VPC society-vpc → Create. Then Routes → Edit routes → Add route:
| Destination | Target |
|---|---|
10.0.0.0/16 |
local (already there, cannot be removed) |
0.0.0.0/0 |
Internet Gateway → society-igw |
Subnet associations → Edit subnet associations → tick web-public-1a → Save associations.
Step 5 — Keep the private subnets private
Create private-rt with only the local route and associate app-private-1a and db-private-1a with it. Later you can add 0.0.0.0/0 → nat-… for outbound updates: How to set up a NAT gateway for a private subnet.
Test it: launch a small instance in web-public-1a with a security group that allows SSH from My IP, and connect to its public IP. It works because the subnet's route table points to the IGW. 🏠
Ravindra Bagale's Tip
Many students create the route table and even add the route – but forget the Subnet associations. Then the subnet quietly uses the main route table and the instance gets no internet. Note: as soon as you create a route table, associate it, and open the subnet's Route table tab to confirm.
Ravindra Bagale's Tip – मराठी
बरेच students route table बनवतात, route पण टाकतात – पण Subnet associations करायला विसरतात. मग subnet शांतपणे main route table वापरतो आणि instance ला internet मिळत नाही. लक्ष द्या: route table बनवला की लगेच associate करा, आणि subnet चा Route table tab उघडून confirm करा.
Ravindra Bagale's Tip – हिंदी
बहुत से students route table बनाते हैं, route भी डालते हैं – पर Subnet associations करना भूल जाते हैं. फिर subnet चुपचाप main route table इस्तेमाल करता है और instance को internet नहीं मिलता. ध्यान दो: route table बनाते ही associate करो, और subnet का Route table tab खोलकर confirm करो.
How do I fix common custom VPC problems?
Ghabru naka 😅 — these are the usual ones:
| Symptom | Likely cause | Fix |
|---|---|---|
| Instance has no public IP | Auto-assign public IPv4 is off in the subnet | Enable it in subnet settings, or allocate and associate an Elastic IP |
| SSH or HTTP times out to a public instance | Route table has no 0.0.0.0/0 → igw-…, or it is not associated |
Add the route and the subnet association |
The CIDR '10.0.1.0/24' conflicts with another subnet |
Two subnets overlap | Use the next free block, e.g. 10.0.4.0/24 |
The CIDR '10.1.0.0/24' is invalid for a subnet |
The subnet is not inside the VPC's CIDR | Choose a block inside 10.0.0.0/16 |
The vpc ... has dependencies and cannot be deleted |
Instances, NAT gateways or ENIs still exist | Terminate instances, delete NAT gateways, then delete the VPC |
| Cannot attach a second internet gateway | Only one IGW per VPC | Use the one already attached |
Try it at home
Build society-vpc by hand with the five steps, launch one instance in the public subnet and one in the private subnet, and check which one you can reach. Then delete everything and build it again with VPC and more — compare what AWS created for you.
Learn it properly
This guide is the short path. The free AWS course has a full VPC chapter with labs:
- What is a VPC? Default VPC vs custom VPC
- How to create a custom VPC and choose its CIDR block
- Subnets: default and custom subnets, CIDR and limits
- Internet gateway · Route tables: public and private subnets
- Related guides: Public vs private subnet · CIDR and subnet calculation · 3-tier architecture project
Got it? VPC only, CIDR 10.0.0.0/16, subnets, attach the IGW, the public route table and the association – this is the order for building the society. Once you build it by hand, VPC and more will make sense immediately.
समजलं का? VPC only, CIDR 10.0.0.0/16, subnets, IGW attach, public route table आणि association – हा society बांधायचा क्रम. एकदा हाताने बनवला की VPC and more पण लगेच कळेल.
समझ आया? VPC only, CIDR 10.0.0.0/16, subnets, IGW attach, public route table और association – यह society बनाने का क्रम है. एक बार हाथ से बना लिया तो VPC and more भी तुरंत समझ आएगा.
Frequently asked questions
How do I create a custom VPC in AWS?
In the VPC console choose Create VPC, VPC only, enter a name and an IPv4 CIDR such as 10.0.0.0/16. Then create subnets, attach an internet gateway and add a route table with 0.0.0.0/0 to the internet gateway for the public subnet.
What is the difference between "VPC only" and "VPC and more"?
VPC only creates just the VPC; you add subnets, gateways and route tables yourself. VPC and more creates the VPC with subnets, route tables, an internet gateway and optional NAT gateways in one step.
What is the difference between the default VPC and a custom VPC?
AWS creates a default VPC (172.31.0.0/16) in every Region with public subnets in each AZ. A custom VPC is one you design: your CIDR, your subnets, and nothing is public until you add an internet gateway route.
How many VPCs can I create?
The default quota is 5 VPCs per Region, and it can be increased through Service Quotas. Each VPC can have one internet gateway and, by default, up to 200 subnets.
Does a custom VPC cost money?
No. VPCs, subnets, route tables, network ACLs, security groups and internet gateways are free. NAT gateways, public IPv4 addresses and data transfer are billed.
Why can my instance in the new VPC not reach the internet?
Usually the subnet has no route 0.0.0.0/0 to the internet gateway, the route table is not associated with the subnet, the internet gateway is not attached, or the instance has no public IP.