NETWORKING / 02
Amazon VPC
Your logically isolated network in the cloud
THE BIG PICTURE
A private subnet reaching the internet
- Private subnetWorkloads without public IPs
- NAT gatewayIn a public subnet
- Internet gatewayAttached to the VPC
- InternetOutbound connections
Example with a public zonal NAT gateway: private workloads initiate outbound connections; return traffic follows that connection.
01CIDR blocks and subnets
- VPC IPv4 CIDR block sizes range from /16 (largest) to /28 (smallest).
- Use RFC 1918 private ranges and keep them unique across all accounts and Regions.
- The primary CIDR block cannot be changed after creation; secondary blocks can be added.
- Each subnet reserves five addresses, so a /28 has 11 usable for ENIs and endpoints.
- A subnet sits in one Availability Zone; spread each tier across at least two.
02Public and private subnets
- A subnet is public when its route table has a direct route to an internet gateway.
- The gateway alone is not enough: the instance also needs a public IPv4 or IPv6 address.
- Private subnets have no direct IGW route; outbound IPv4 internet traffic can use NAT.
- Egress-only internet gateways allow outbound IPv6 and block internet-initiated inbound.
- Three tiers: public for internet-facing load balancers, private for apps, isolated for data.
03Route tables
- Every subnet is associated with exactly one route table; a table can serve many subnets.
- Subnets without an explicit association use the VPC's main route table.
- The local route for the VPC CIDR is always present and cannot be deleted.
- Routes match by longest prefix; a /24 route wins over a /16 for the same packet.
- Keep the main route table free of custom routes; create named tables per tier.
04NAT gateways
- A zonal public NAT gateway needs a public subnet and Elastic IP; private NAT uses no EIP.
- Private subnets send 0.0.0.0/0 to the NAT gateway ID in their route table.
- Use one zonal NAT per AZ, or a regional NAT gateway that expands across workload AZs.
- NAT charges cover AZ-hours and GB processed; cross-AZ traffic can add transfer charges.
- Idle TCP flows are dropped after a fixed timeout; use keepalives on long connections.
05Security groups
- Security groups are stateful; return traffic of an allowed connection is automatic.
- Allow rules only; anything not allowed is denied. There are no deny rules.
- They attach to network interfaces, not subnets; one instance can carry several groups.
- A rule can name another security group as its source, so membership follows instances.
- New groups allow no inbound traffic. The default group allows only its own members.
06Network ACLs
- Network ACLs are stateless: inbound and outbound rules are checked separately.
- Return traffic must match an explicit rule, so allow the peer's ephemeral port range.
- Rules are evaluated by number, lowest first; the first match decides.
- Each subnet has exactly one network ACL; the default ACL allows all traffic.
- A custom network ACL denies everything until you add rules; leave gaps in rule numbers.
07VPC endpoints
- Gateway endpoints cover S3 and DynamoDB only; they are a route table target, not an ENI.
- Gateway endpoints have no hourly charge and are not reachable from on-premises networks.
- Interface endpoints (AWS PrivateLink) place an ENI with a private IP in your subnets.
- Interface endpoints are billed per hour per AZ and per GB; they use security groups.
- Private DNS on interface endpoints makes standard service hostnames resolve to them.
08Peering and Transit Gateway
- VPC peering connects two VPCs only; it is not transitive through a third VPC.
- Peering needs non-overlapping CIDR blocks and routes added in both VPCs' route tables.
- Transit Gateway is a regional hub; route tables control which attachments can talk.
- Transit Gateway routes between attachments transitively, avoiding a full peering mesh.
- Peering: per GB across AZs or Regions. Transit Gateway: per attachment-hour and per GB.
09VPN and Direct Connect
- Site-to-Site VPN gives two IPsec tunnels per connection; configure both for redundancy.
- Attach VPNs to a virtual private gateway or Transit Gateway; pick static or BGP.
- Direct Connect is a private link to AWS; traffic is not encrypted by default.
- A Direct Connect gateway links virtual interfaces to VGWs or Transit Gateways.
- Overlapping on-premises and VPC ranges break routing; plan address space early.
10DNS and Route 53 Resolver
- Amazon DNS server listens at the VPC base address plus two (10.0.0.2 in 10.0.0.0/16).
- DNS support and DNS hostnames are separate settings; private endpoint DNS needs both.
- Route 53 Resolver inbound endpoints let on-premises DNS query private zones in the VPC.
- Outbound endpoints plus forwarding rules send chosen domains to on-premises DNS.
- Resolver endpoints use subnet ENIs; billing covers endpoint hours and queries.
11Flow logs and monitoring
- Flow logs capture IP traffic metadata for a VPC, a subnet, or one network interface.
- Send logs to CloudWatch Logs, S3 or Firehose; each record shows accept or reject.
- Some AWS-internal traffic, such as instance metadata and Amazon DNS, is not logged.
- Flow logs do not affect traffic but publish in batches on an aggregation interval.
- Reachability Analyzer checks a path and names the component that blocks it.
12Common pitfalls
- Direct internet access needs an IGW route and public address; private IPv4 egress can use NAT.
- Missing ephemeral return ports in a network ACL cause timeouts that look like bugs.
- Overlapping CIDRs block peering and hybrid routing; fix ranges before building.
- A single zonal NAT is an AZ outage risk; use per-AZ gateways or regional NAT.
- Admin ports open to 0.0.0.0/0 expose hosts; limit sources to SGs or known ranges.
Go to the source
Use AWS documentation for current limits, availability, and pricing.