Ravindra BagaleCourses & study guides Track your progress

Guides

How to Create a Custom VPC in AWS with Subnets, Internet Gateway and Route Tables

To create a custom VPC in AWS, open VPC → Your VPCs → Create VPC, choose VPC only, give it a name and an IPv4 CIDR block such as 10.0.0.0/16. Then create subnets inside it (for example 10.0.1.0/24 public and 10.0.2.0/24 private), create and attach an internet gateway, and make a public route table with 0.0.0.0/0 → igw-… that you associate with the public subnet. A subnet becomes public only because of that route.

Come on, friends! A VPC is our own housing society – the boundary wall (CIDR), wings (subnets), the main gate (internet gateway) and the list of directions on the notice board (route table). The default VPC is a ready-made flat built by AWS; today we build the society ourselves. Don't worry, there are five steps.

Quick answer

Console path (Region: your choice, for example ap-south-1):

VPC → Your VPCs → Create VPC → VPC only
    Name: society-vpc   IPv4 CIDR: 10.0.0.0/16
Subnets → Create subnet → web-public-1a 10.0.1.0/24, app-private-1a 10.0.2.0/24
Internet gateways → Create → society-igw → Actions → Attach to VPC → society-vpc
Route tables → Create public-rt → Edit routes → 0.0.0.0/0 → Internet Gateway → society-igw
public-rt → Subnet associations → web-public-1a

The same with the AWS CLI:

VPC=$(aws ec2 create-vpc --cidr-block 10.0.0.0/16 --query Vpc.VpcId --output text)
PUB=$(aws ec2 create-subnet --vpc-id $VPC --cidr-block 10.0.1.0/24 --availability-zone ap-south-1a --query Subnet.SubnetId --output text)
IGW=$(aws ec2 create-internet-gateway --query InternetGateway.InternetGatewayId --output text)
aws ec2 attach-internet-gateway --internet-gateway-id $IGW --vpc-id $VPC
RT=$(aws ec2 create-route-table --vpc-id $VPC --query RouteTable.RouteTableId --output text)
aws ec2 create-route --route-table-id $RT --destination-cidr-block 0.0.0.0/0 --gateway-id $IGW
aws ec2 associate-route-table --route-table-id $RT --subnet-id $PUB

What do I need before creating a custom VPC?

  • An AWS account and permission to use Amazon VPC (an IAM user with admin rights is fine for learning).
  • A CIDR plan. A VPC can be from /16 (65,536 addresses) to /28 (16 addresses), preferably from the private ranges 10.0.0.0/8, 172.16.0.0/12 or 192.168.0.0/16. Pick one that does not overlap with other networks you may connect later. See AWS VPC CIDR and subnet calculation.
  • Nothing costs money in this guide: VPCs, subnets, route tables and internet gateways are free. (NAT gateways and public IPv4 addresses are billed, see the NAT guide.)

What does a custom VPC look like?

A custom VPC with three subnets and an internet gateway Inside the region ap-south-1 sits the VPC 10.0.0.0/16. It contains three subnets in one Availability Zone: web-public-1a 10.0.1.0/24, app-private-1a 10.0.2.0/24 and db-private-1a 10.0.3.0/24. A request from the internet enters through the internet gateway attached to the VPC and reaches only the public subnet. Internet Region ap-south-1 (Mumbai) society-vpc 10.0.0.0/16 AZ ap-south-1a IGW web-public-1a10.0.1.0/24 · route 0.0.0.0/0 → IGW Nginx reached app-private-1a10.0.2.0/24 · no route from the internet db-private-1a10.0.3.0/24 · no route from the internet HTTP

The VPC 10.0.0.0/16 lives in one Region. Inside it, each subnet lives in one Availability Zone. A request from the internet enters through the internet gateway and can reach only the public subnet, because only its route table points to the IGW.

A VPC is a logically isolated virtual network in one Region. A subnet is a slice of the VPC's CIDR that lives in exactly one Availability Zone. The internet gateway (IGW) is the VPC's door to the internet, and a route table tells each subnet where to send traffic.

Every account also has a default VPC (172.31.0.0/16) in each Region, with a public default subnet in every AZ. It is handy for quick tests, but in real projects you build a custom VPC so you decide what is public and what is private.

How do I create a custom VPC step by step?

Step 1 — Create the VPC

VPC → Your VPCs → Create VPC → Resources to create: VPC only → Name tag society-vpc → IPv4 CIDR manual input 10.0.0.0/16 → No IPv6 CIDR block → Tenancy Default → Create VPC.

VPC and more creates subnets, route tables, an internet gateway and optionally NAT gateways in one go. It is great once you understand the parts; the first time, build them one by one.

Step 2 — Create the subnets

Subnets → Create subnet → VPC society-vpc → add each subnet:

Name Availability Zone IPv4 subnet CIDR Purpose
web-public-1a ap-south-1a 10.0.1.0/24 Web server, bastion, NAT gateway
app-private-1a ap-south-1a 10.0.2.0/24 Application servers
db-private-1a ap-south-1a 10.0.3.0/24 Database

Each /24 gives 256 addresses, of which AWS reserves 5, so 251 are usable. For the public subnet, select it → Actions → Edit subnet settings → tick Enable auto-assign public IPv4 address, so instances launched there get a public IP.

Step 3 — Create and attach the internet gateway

Internet gateways → Create internet gateway → Name society-igw → Create → Actions → Attach to VPC → society-vpc. The state changes from Detached to Attached. A VPC can have only one internet gateway attached.

Step 4 — Create the public route table

Route tables → Create route table → Name public-rt → VPC society-vpc → Create. Then Routes → Edit routes → Add route:

Destination Target
10.0.0.0/16 local (already there, cannot be removed)
0.0.0.0/0 Internet Gateway → society-igw

Subnet associations → Edit subnet associations → tick web-public-1a → Save associations.

Step 5 — Keep the private subnets private

Create private-rt with only the local route and associate app-private-1a and db-private-1a with it. Later you can add 0.0.0.0/0 → nat-… for outbound updates: How to set up a NAT gateway for a private subnet.

Test it: launch a small instance in web-public-1a with a security group that allows SSH from My IP, and connect to its public IP. It works because the subnet's route table points to the IGW. 🏠

Ravindra Bagale's Tip

Many students create the route table and even add the route – but forget the Subnet associations. Then the subnet quietly uses the main route table and the instance gets no internet. Note: as soon as you create a route table, associate it, and open the subnet's Route table tab to confirm.

How do I fix common custom VPC problems?

Ghabru naka 😅 — these are the usual ones:

Symptom Likely cause Fix
Instance has no public IP Auto-assign public IPv4 is off in the subnet Enable it in subnet settings, or allocate and associate an Elastic IP
SSH or HTTP times out to a public instance Route table has no 0.​0.​0.​0/​0 → igw-…, or it is not associated Add the route and the subnet association
The CIDR '10.​0.​1.​0/​24' conflicts with another subnet Two subnets overlap Use the next free block, e.g. 10.0.4.0/24
The CIDR '10.​1.​0.​0/​24' is invalid for a subnet The subnet is not inside the VPC's CIDR Choose a block inside 10.0.0.0/16
The vpc ... has dependencies and cannot be deleted Instances, NAT gateways or ENIs still exist Terminate instances, delete NAT gateways, then delete the VPC
Cannot attach a second internet gateway Only one IGW per VPC Use the one already attached

Try it at home

Build society-vpc by hand with the five steps, launch one instance in the public subnet and one in the private subnet, and check which one you can reach. Then delete everything and build it again with VPC and more — compare what AWS created for you.

Got it? VPC only, CIDR 10.0.0.0/16, subnets, attach the IGW, the public route table and the association – this is the order for building the society. Once you build it by hand, VPC and more will make sense immediately.

Frequently asked questions

How do I create a custom VPC in AWS?

In the VPC console choose Create VPC, VPC only, enter a name and an IPv4 CIDR such as 10.0.0.0/16. Then create subnets, attach an internet gateway and add a route table with 0.0.0.0/0 to the internet gateway for the public subnet.

What is the difference between "VPC only" and "VPC and more"?

VPC only creates just the VPC; you add subnets, gateways and route tables yourself. VPC and more creates the VPC with subnets, route tables, an internet gateway and optional NAT gateways in one step.

What is the difference between the default VPC and a custom VPC?

AWS creates a default VPC (172.31.0.0/16) in every Region with public subnets in each AZ. A custom VPC is one you design: your CIDR, your subnets, and nothing is public until you add an internet gateway route.

How many VPCs can I create?

The default quota is 5 VPCs per Region, and it can be increased through Service Quotas. Each VPC can have one internet gateway and, by default, up to 200 subnets.

Does a custom VPC cost money?

No. VPCs, subnets, route tables, network ACLs, security groups and internet gateways are free. NAT gateways, public IPv4 addresses and data transfer are billed.

Why can my instance in the new VPC not reach the internet?

Usually the subnet has no route 0.0.0.0/0 to the internet gateway, the route table is not associated with the subnet, the internet gateway is not attached, or the instance has no public IP.