VPC Networking

Your private network in AWS: subnets, internet and NAT gateways, VPN, and Direct Connect.

What is it?

An Amazon VPC (Virtual Private Cloud) is a logically isolated network you define inside a Region. You choose its IP range in CIDR notation (for example 10.0.0.0/16) and carve it into subnets, each living in a single AZ.

  • Public subnet: has a route to an Internet Gateway (IGW), so resources with public IPs can reach and be reached from the internet.
  • Private subnet: no direct route from the internet; ideal for databases and app servers.
  • NAT gateway: lets private resources start outbound connections (for updates, APIs) without accepting inbound connections. It lives in a public subnet.
  • Route tables: decide where traffic from a subnet goes.
  • Virtual private gateway + Site-to-Site VPN: an encrypted tunnel over the internet to your on-premises network.
  • AWS Direct Connect: a dedicated private network connection from your site to AWS, with more consistent performance than the internet.

Other connectors you will meet: VPC peering (connect two VPCs), Transit Gateway (a hub for many VPCs and networks), and VPC endpoints (reach AWS services privately without the internet).

Explain like I'm 10

A VPC is a gated campus. The main gate (internet gateway) opens onto a public plaza (public subnet) with the reception and cafe. Behind it sit private office buildings (private subnets) with no street entrance; staff walk out through a controlled side door (NAT) when they need something, but strangers cannot walk in. A private tunnel to head office is the VPN; a dedicated road is Direct Connect.

Examples

Planning a VPC

VPC            10.0.0.0/16        (65,536 addresses)
  public-a     10.0.0.0/24   AZ a   route 0.0.0.0/0 -> IGW   (load balancer, NAT)
  public-b     10.0.1.0/24   AZ b   route 0.0.0.0/0 -> IGW
  private-a    10.0.10.0/24  AZ a   route 0.0.0.0/0 -> NAT   (app servers)
  private-b    10.0.11.0/24  AZ b   route 0.0.0.0/0 -> NAT
  data-a       10.0.20.0/24  AZ a   no internet route        (databases)
  data-b       10.0.21.0/24  AZ b   no internet route

Use the IP/CIDR calculator tool to check ranges and avoid overlaps (important if you later connect to on-premises).

Building a VPC with the CLI

VPC=$(aws ec2 create-vpc --cidr-block 10.0.0.0/16 --query Vpc.VpcId --output text)
SUBNET=$(aws ec2 create-subnet --vpc-id "$VPC" --cidr-block 10.0.0.0/24 \
  --availability-zone eu-west-1a --query Subnet.SubnetId --output text)
IGW=$(aws ec2 create-internet-gateway --query InternetGateway.InternetGatewayId --output text)
aws ec2 attach-internet-gateway --internet-gateway-id "$IGW" --vpc-id "$VPC"
RT=$(aws ec2 create-route-table --vpc-id "$VPC" --query RouteTable.RouteTableId --output text)
aws ec2 create-route --route-table-id "$RT" --destination-cidr-block 0.0.0.0/0 --gateway-id "$IGW"
aws ec2 associate-route-table --route-table-id "$RT" --subnet-id "$SUBNET"

A subnet is 'public' because its route table points to an IGW, not because of its name.

How it works

Every packet leaving a subnet is matched against that subnet's route table; the most specific matching route wins. local routes keep traffic inside the VPC. A route to an IGW makes a subnet public (instances also need a public or Elastic IP). A route to a NAT gateway lets private instances initiate outbound traffic: the NAT translates their private addresses to its own public one and returns replies.

For on-premises connectivity, a VPN gives encrypted connectivity quickly over the internet, while Direct Connect takes longer to set up but gives a private, steadier link. Many designs use both: Direct Connect primary, VPN backup.

   Internet
      |
  [ Internet Gateway ]
      |
 +----+------------------ VPC 10.0.0.0/16 ---------------+
 | Public subnet           Private subnet                  |
 | [ALB] [NAT GW] <------- [App servers]  (outbound only)  |
 |                          |                              |
 |                       [Database subnet - no internet]   |
 +---------+-----------------------------------------------+
           |                      |
   [Virtual private gateway]  [Direct Connect]
        VPN tunnel -------- On-premises network

Why does it exist?

Early cloud servers sat on flat shared networks. A VPC gives you the equivalent of your own network design - address ranges, routing, segmentation - so you can expose only what must be public and keep the rest isolated.

When to use it

Every workload on EC2, RDS, and many other services lives in a VPC. Use public subnets for load balancers, private subnets for apps and data, NAT for outbound access, VPN or Direct Connect for hybrid.

When not to use it

Do not put databases in public subnets 'for convenience'. Do not choose Direct Connect for a quick proof of concept (lead time) - start with VPN. Avoid NAT gateways for AWS service traffic if a VPC endpoint can keep it private and cheaper.

Common mistakes

  • Overlapping CIDR ranges that block later VPC peering or VPN connectivity.

  • Choosing a /16 everywhere without planning, or a range too small to grow.

  • Placing a single NAT gateway in one AZ and losing outbound access if that AZ fails.

  • Forgetting the route table association, so the subnet is not actually public.

  • Believing Direct Connect is encrypted by default (it is private, not automatically encrypted).

Practice exercises

  1. Easy:

    Explain why a subnet with an IGW route is called public and what else an instance needs to be reachable.

  2. Medium:

    Use the CIDR calculator to split 10.0.0.0/16 into six /24 subnets without overlap.

  3. Medium:

    Draw the route tables for public, private, and data subnets.

  4. Hard:

    Design connectivity from an office to AWS needing high reliability. Combine Direct Connect and VPN and describe failover.

Interview questions

What makes a subnet public?

A route to an Internet Gateway in its route table (plus public IP addressing for the resources).

NAT gateway purpose?

Allows instances in private subnets to initiate outbound connections to the internet while preventing inbound connections from it.

VPN vs Direct Connect?

A VPN is an encrypted tunnel over the public internet, quick to set up; Direct Connect is a dedicated private connection with more consistent latency and bandwidth.

Exam-style: Which component allows internet access for a public subnet?

An Internet Gateway.

Exam-style: A company needs a private, dedicated link between its data center and AWS. Which service?

AWS Direct Connect.