All infographics

NETWORKING / 02

Amazon VPC

Your logically isolated network in the cloud

Download sheet SVG

THE BIG PICTURE

A private subnet reaching the internet

  1. Private subnetWorkloads without public IPs
  2. NAT gatewayIn a public subnet
  3. Internet gatewayAttached to the VPC
  4. InternetOutbound connections

Example with a public zonal NAT gateway: private workloads initiate outbound connections; return traffic follows that connection.

01CIDR blocks and subnets

  • VPC IPv4 CIDR block sizes range from /16 (largest) to /28 (smallest).
  • Use RFC 1918 private ranges and keep them unique across all accounts and Regions.
  • The primary CIDR block cannot be changed after creation; secondary blocks can be added.
  • Each subnet reserves five addresses, so a /28 has 11 usable for ENIs and endpoints.
  • A subnet sits in one Availability Zone; spread each tier across at least two.

02Public and private subnets

  • A subnet is public when its route table has a direct route to an internet gateway.
  • The gateway alone is not enough: the instance also needs a public IPv4 or IPv6 address.
  • Private subnets have no direct IGW route; outbound IPv4 internet traffic can use NAT.
  • Egress-only internet gateways allow outbound IPv6 and block internet-initiated inbound.
  • Three tiers: public for internet-facing load balancers, private for apps, isolated for data.

03Route tables

  • Every subnet is associated with exactly one route table; a table can serve many subnets.
  • Subnets without an explicit association use the VPC's main route table.
  • The local route for the VPC CIDR is always present and cannot be deleted.
  • Routes match by longest prefix; a /24 route wins over a /16 for the same packet.
  • Keep the main route table free of custom routes; create named tables per tier.

04NAT gateways

  • A zonal public NAT gateway needs a public subnet and Elastic IP; private NAT uses no EIP.
  • Private subnets send 0.0.0.0/0 to the NAT gateway ID in their route table.
  • Use one zonal NAT per AZ, or a regional NAT gateway that expands across workload AZs.
  • NAT charges cover AZ-hours and GB processed; cross-AZ traffic can add transfer charges.
  • Idle TCP flows are dropped after a fixed timeout; use keepalives on long connections.

05Security groups

  • Security groups are stateful; return traffic of an allowed connection is automatic.
  • Allow rules only; anything not allowed is denied. There are no deny rules.
  • They attach to network interfaces, not subnets; one instance can carry several groups.
  • A rule can name another security group as its source, so membership follows instances.
  • New groups allow no inbound traffic. The default group allows only its own members.

06Network ACLs

  • Network ACLs are stateless: inbound and outbound rules are checked separately.
  • Return traffic must match an explicit rule, so allow the peer's ephemeral port range.
  • Rules are evaluated by number, lowest first; the first match decides.
  • Each subnet has exactly one network ACL; the default ACL allows all traffic.
  • A custom network ACL denies everything until you add rules; leave gaps in rule numbers.

07VPC endpoints

  • Gateway endpoints cover S3 and DynamoDB only; they are a route table target, not an ENI.
  • Gateway endpoints have no hourly charge and are not reachable from on-premises networks.
  • Interface endpoints (AWS PrivateLink) place an ENI with a private IP in your subnets.
  • Interface endpoints are billed per hour per AZ and per GB; they use security groups.
  • Private DNS on interface endpoints makes standard service hostnames resolve to them.

08Peering and Transit Gateway

  • VPC peering connects two VPCs only; it is not transitive through a third VPC.
  • Peering needs non-overlapping CIDR blocks and routes added in both VPCs' route tables.
  • Transit Gateway is a regional hub; route tables control which attachments can talk.
  • Transit Gateway routes between attachments transitively, avoiding a full peering mesh.
  • Peering: per GB across AZs or Regions. Transit Gateway: per attachment-hour and per GB.

09VPN and Direct Connect

  • Site-to-Site VPN gives two IPsec tunnels per connection; configure both for redundancy.
  • Attach VPNs to a virtual private gateway or Transit Gateway; pick static or BGP.
  • Direct Connect is a private link to AWS; traffic is not encrypted by default.
  • A Direct Connect gateway links virtual interfaces to VGWs or Transit Gateways.
  • Overlapping on-premises and VPC ranges break routing; plan address space early.

10DNS and Route 53 Resolver

  • Amazon DNS server listens at the VPC base address plus two (10.0.0.2 in 10.0.0.0/16).
  • DNS support and DNS hostnames are separate settings; private endpoint DNS needs both.
  • Route 53 Resolver inbound endpoints let on-premises DNS query private zones in the VPC.
  • Outbound endpoints plus forwarding rules send chosen domains to on-premises DNS.
  • Resolver endpoints use subnet ENIs; billing covers endpoint hours and queries.

11Flow logs and monitoring

  • Flow logs capture IP traffic metadata for a VPC, a subnet, or one network interface.
  • Send logs to CloudWatch Logs, S3 or Firehose; each record shows accept or reject.
  • Some AWS-internal traffic, such as instance metadata and Amazon DNS, is not logged.
  • Flow logs do not affect traffic but publish in batches on an aggregation interval.
  • Reachability Analyzer checks a path and names the component that blocks it.

12Common pitfalls

  • Direct internet access needs an IGW route and public address; private IPv4 egress can use NAT.
  • Missing ephemeral return ports in a network ACL cause timeouts that look like bugs.
  • Overlapping CIDRs block peering and hybrid routing; fix ranges before building.
  • A single zonal NAT is an AZ outage risk; use per-AZ gateways or regional NAT.
  • Admin ports open to 0.0.0.0/0 expose hosts; limit sources to SGs or known ranges.

Go to the source

Use AWS documentation for current limits, availability, and pricing.

VPC subnet types and routing NAT gateway connectivity types Regional NAT gateways NAT gateway basics