Real lesson · Cloud infrastructure

This is a real Nodebook lesson.

Nothing below was written for this website. It is a row out of the product’s own database - compiled on 11 September 2026 from 8 sources, fact-checked against them, and drawn here by the same reader a subscriber uses. The only things missing are the ones that would need an account to be worth anything.

  • 6 concepts
  • 8 cited sources
  • 3 code-rendered figures
  • 12 quiz questions
  • 10 flashcards
8 sourcesIntermediate

AWS VPC Subnets, Route Tables, and NAT

A basic AWS VPC network providing internet connectivity for both public and private resources is designed using subnets, route tables, and NAT Gateways. This architecture ensures network isolation, security, and controlled internet access for different types of resources within your virtual cloud environment.

Traffic flow in an AWS VPC with public and private subnets
Concepts · 6
  1. AWS VPC Fundamentals
    Definition

    How can you build your own private, secure network in the cloud, completely separate from everyone else's?

    When you rent an apartment, you get your own private space with distinct walls and a unique address, even though it's part of a larger building. You control what happens inside your unit, separate from other tenants.

    An AWS VPC creates your own private, isolated network inside Amazon's cloud, keeping your resources separate and secure. It lets you define your network topology, including IP address ranges and where traffic can flow. This isolation and control are fundamental for building secure, scalable cloud applications.

    WHAT IT ISAn Amazon Virtual Private Cloud (VPC) is a logically isolated section of the AWS cloud where you launch AWS resources.

    WHAT IT DOESA VPC provides a virtual network environment that you fully control, including its IP address range, subnets, route tables, and network gateways. For example, you can specify a CIDR block like 10.0.0.0/16 for your VPC, then divide it into smaller subnets for different application tiers. This allows you to define a custom network topology that closely resembles a traditional on-premises data center.

    WHY IT MATTERSVPCs are useful because they enable fine-grained control over network security and connectivity, preventing unauthorized access to your applications and data. They are essential for deploying multi-tier applications, isolating production environments, and meeting compliance requirements by segmenting network traffic and controlling internet access.

    Core components contained within an AWS Virtual Private Cloud (VPC).

    Not to be confused with: A simple public cloud instance without a custom VPC configuration. - While an instance launched without explicit VPC configuration still resides within a default VPC, you lack the granular control over IP address ranges, subnet segmentation, and explicit routing rules that a custom VPC provides. It's not truly isolated or configurable to your specific needs, unlike a user-defined VPC which offers full control over the network topology and security boundaries.

    WHY THIS MATTERSWithout a VPC, your cloud resources would lack the necessary network isolation and security controls, making them vulnerable to unauthorized access and difficult to manage. It's the fundamental building block for designing secure, scalable, and compliant cloud architectures, enabling you to segment resources and control their communication pathways.

    TRY IT

    A startup wants to deploy its new application on AWS, ensuring that its database servers cannot be directly accessed from the internet, even if the web servers are public-facing. Should they use a default AWS network setup or configure a custom VPC?

    Hint

    Consider which option provides the most control over network segmentation and access rules.

  2. Subnets: Public and Private
    Comparison

    How do you build a cloud network where some services are open to the world, but others are completely hidden and protected?

    In a large office building, some rooms, like the reception area or a public cafe, are directly accessible from the street, while others, like server rooms or executive offices, require specific internal pathways and permissions to reach.

    Networks need internal divisions to organize resources and control access, much like rooms in a building. Subnets create these logical divisions within a cloud network, allowing specific groups of resources to share an IP address range and routing rules. This segmentation is crucial for security and managing how resources communicate with each other and the internet.

    WHAT IT ISA subnet is a logical subdivision of an IP network within a Virtual Private Cloud (VPC), defined by a contiguous range of IP addresses from the VPC's CIDR block.

    WHAT IT DOESSubnets isolate resources, allowing administrators to apply specific security and routing policies to groups of instances. A subnet's classification as 'public' or 'private' is determined by its associated route table: a public subnet has a route to an Internet Gateway (IGW), enabling direct internet access for resources within it, while a private subnet lacks such a route, preventing direct internet access. For example, a web server might reside in a public subnet, directly accessible from the internet, while its database backend lives in a private subnet, shielded from direct external exposure.

    WHY IT MATTERSThis distinction is fundamental for implementing a robust security posture and controlling data flow. Public subnets host internet-facing resources, ensuring they can serve external requests, whereas private subnets protect sensitive resources by restricting their direct internet exposure, often routing outbound traffic through a NAT Gateway for controlled updates or external API calls. This separation enforces the principle of least privilege for network access.

    Not to be confused with: Mistaking a subnet's 'public' or 'private' status as an inherent property set at creation, rather than a dynamic configuration. - The public or private nature of a subnet is not an intrinsic attribute; it is determined entirely by its associated route table. If the route table contains a route to an Internet Gateway (IGW) for 0.0.0.0/0 (all internet traffic), it's public; otherwise, it's private. This means a subnet can change its status if its route table is modified.

    WHY THIS MATTERSProper subnet design is critical for security compliance, preventing unauthorized access to sensitive data and applications. It also dictates how resources within your VPC can communicate with the internet, enabling controlled outbound access for private resources while exposing only necessary services to the public.

    TRY IT

    You've configured a new subnet (10.0.3.0/24) in your VPC. You want instances in this subnet to be able to download software updates from the internet, but you explicitly do NOT want them to be directly accessible from the internet. How should you configure its route table?

    Hint

    Consider the difference in routing for direct internet access versus controlled outbound-only access.

  3. Internet Gateway & Public Connectivity
    Process

    How do your cloud servers get online to serve websites or fetch updates?

    When you connect your home router to your internet service provider's modem, you're establishing a gateway for your local network to reach the wider internet.

    How do computers in your cloud network talk to the internet? An Internet Gateway provides the necessary connection point. It acts as a horizontally scaled, redundant VPC component that allows communication between instances in your VPC and the internet.

    WHAT IT ISAn Internet Gateway (IGW) is a logically redundant, highly available VPC component.

    WHAT IT DOESIt enables instances in a VPC to connect to the internet and vice versa by providing a target for internet-bound traffic in route tables. This allows public IPv4 addresses and Elastic IPs to be reachable from the internet.

    WHY IT MATTERSAttaching an IGW to your VPC and configuring route tables for public subnets is essential for any resource that needs direct internet access, like web servers or public APIs. It ensures your public-facing applications are accessible globally.

    Steps to enable public internet connectivity for a subnet in AWS VPC.
    Walk through an example

    You need to enable internet access for a web server running on an EC2 instance in a public subnet within your AWS VPC.

    1. Create an Internet Gateway.
      This establishes the logical connection point for internet traffic to and from your VPC.
    2. Attach the Internet Gateway to your VPC.
      This links the IGW directly to your specific virtual network, making it available for routing traffic within that VPC.
    3. Modify the route table associated with your public subnet.
      This directs traffic from the public subnet to the IGW for external communication.
    4. Add a default route (0.0.0.0/0) to the Internet Gateway.
      This tells all traffic destined for any IP address outside the VPC's CIDR block to use the IGW as its next hop.

    So: The public subnet's instances can now send and receive traffic from the internet, provided they have public IP addresses and security group rules allow it.

    Not to be confused with: Simply attaching an Internet Gateway to a VPC. - Attaching an IGW to a VPC does not automatically grant internet access to all subnets; you must explicitly configure route tables to direct internet-bound traffic to the IGW for specific subnets.

    WHY THIS MATTERSWithout an Internet Gateway and proper route table configuration, instances in your public subnets cannot communicate with the internet, rendering public-facing applications inaccessible. This setup is fundamental for any internet-facing application hosted in AWS.

    TRY IT

    You've created a new VPC and a public subnet. You launch an EC2 instance with a public IP in this subnet, but it cannot ping external websites. What is the most likely missing configuration step?

    Hint

    Consider the three main components needed for public internet access in a VPC.

  4. Route Tables & Traffic Flow
    Definition

    How does your network traffic know where to go once it leaves your computer?

    When you send a letter, the postal service uses the address and a series of sorting centers to guide it to its final destination.

    Network traffic needs directions to find its way between different parts of a network or to the internet. Route tables act like a network's GPS, telling data packets which path to take to reach their destination. They contain rules that map destination IP address ranges to specific targets, like gateways or other network interfaces.

    WHAT IT ISA route table is a set of rules, called routes, that determines where network traffic is directed.

    WHAT IT DOESEach route specifies a destination CIDR block and a target, which is the next hop for traffic matching that destination. For instance, a route might direct all traffic for 10.0.0.0/16 to a local gateway, while traffic for 0.0.0.0/0 (the internet) goes to an Internet Gateway. Every subnet in a Virtual Private Cloud (VPC) must be explicitly associated with one route table, or it implicitly uses the VPC's main route table.

    WHY IT MATTERSRoute tables are fundamental for controlling network flow, enabling instances within different subnets to communicate and allowing specific subnets to access the internet while others remain private. They ensure that data packets reach their intended recipients efficiently and securely, preventing misrouted traffic or unintended exposure.

    Not to be confused with: Network Access Control Lists (NACLs) or Security Groups - Route tables direct traffic by specifying the next hop based on destination IP, while NACLs and Security Groups filter or block traffic based on rules like port numbers and protocols. Route tables are about 'where to send it,' not 'whether to allow it.'

    WHY THIS MATTERSAccurate route table configuration is critical for network segmentation, connectivity, and security. Misconfigured routes can lead to communication failures, such as instances unable to reach critical services, or introduce security vulnerabilities by inadvertently exposing private resources to the internet.

    TRY IT

    You have an EC2 instance in Subnet A (CIDR 10.0.1.0/24) that needs to communicate with another EC2 instance in Subnet B (CIDR 10.0.2.0/24), both within the same VPC. Does the route table associated with Subnet A require a specific custom route for this communication?

    Hint

    Consider how traffic within the same VPC is typically handled by default.

  5. NAT Gateway for Private Access
    Process

    How can a server stay hidden from the internet but still download necessary software updates?

    When you make a call from your office phone, the external caller sees the main office number, not your direct line, allowing you to call out but preventing direct calls to your desk.

    Private servers need internet access for updates without being exposed directly. A NAT Gateway translates private IP addresses to a public one for outbound connections. This allows instances in private subnets to initiate connections to the internet while preventing unsolicited inbound traffic.

    WHAT IT ISA NAT Gateway is a managed AWS service that provides Network Address Translation.

    WHAT IT DOESIt enables instances in a private subnet to connect to the internet or other AWS services outside the VPC, but prevents the internet from initiating connections to those instances. The NAT Gateway translates the private IP addresses of instances to its own public Elastic IP address when sending traffic out, and then translates the response back to the private IP.

    WHY IT MATTERSThis provides a crucial security layer, allowing private resources like database servers to fetch software updates or interact with external APIs without direct internet exposure. It simplifies network architecture by centralizing outbound internet access for private subnets, eliminating the need for each private instance to have a public IP.

    Walk through an example

    You need to enable a web application's backend servers, located in a private subnet, to download external dependencies without exposing them to direct internet access.

    1. Create a NAT Gateway in a public subnet.
      NAT Gateways require a public IP address and must reside in a public subnet with an associated Internet Gateway to route traffic to the internet.
    2. Allocate an Elastic IP address to the NAT Gateway.
      An Elastic IP provides a static, public IP address that the NAT Gateway uses for all outbound traffic, ensuring consistent internet-facing identity and preventing IP changes.
    3. Update the route table associated with your private subnet.
      Add a default route (0.0.0.0/0) pointing to the NAT Gateway's ID as the target. This directs all internet-bound traffic from the private subnet through the NAT Gateway.
    4. Verify connectivity from a private instance.
      Launch an EC2 instance in the private subnet and attempt to ping an external IP address or download a package. This confirms the outbound internet access is working via the NAT Gateway.

    So: The backend servers in the private subnet can now securely initiate outbound connections to the internet for updates and dependencies.

    Not to be confused with: An Internet Gateway (IGW) attached to a public subnet. - An IGW directly enables both inbound and outbound internet traffic for instances with public IPs, exposing them. A NAT Gateway, conversely, only allows outbound connections for private instances, preventing unsolicited inbound traffic from the internet.

    WHY THIS MATTERSWithout a NAT Gateway, private instances would either lack internet access for essential tasks like software updates, or require public IPs, compromising their security posture. This mechanism is fundamental for building secure, multi-tier applications in AWS where backend services must remain isolated from direct internet exposure.

    TRY IT

    Your company's compliance policy requires all database servers to reside in private subnets, but they must regularly fetch security patches from vendor websites. Describe the routing configuration needed for the private subnet's route table to meet this requirement.

    Hint

    Consider how private instances communicate with the internet through a NAT Gateway.

  6. Basic VPC Architecture Patterns
    Spatial

    How do you build a cloud network that lets some parts talk to the internet freely, while keeping other critical parts completely hidden?

    When designing a building, architects designate specific areas for public access, like lobbies, and secure areas for sensitive operations, like server rooms, each with distinct entry and exit controls.

    Arranging network components correctly lets cloud applications communicate securely and access the internet when needed. These arrangements combine subnets, gateways, and routing rules to control traffic flow. Understanding these patterns ensures resources are both accessible and protected according to their function.

    WHAT IT ISA Basic VPC Architecture Pattern is a standardized configuration of AWS networking components within a Virtual Private Cloud.

    WHAT IT DOESThese patterns define how resources are isolated into public or private subnets, how they gain internet access via an Internet Gateway (IGW), and how private resources can initiate outbound connections using a NAT Gateway. For example, a common pattern places web servers in public subnets and database servers in private subnets.1

    WHY IT MATTERSArchitectural patterns provide blueprints for secure and scalable cloud deployments, preventing common misconfigurations that expose sensitive data or disrupt service availability. They ensure that only intended traffic reaches specific resources, aligning network design with security and operational requirements.2

    Not to be confused with: Placing a database server directly into a public subnet with a public IP address. - This configuration directly exposes the database to the internet, bypassing the security and isolation provided by private subnets and NAT Gateways. Private subnets, by contrast, ensure resources can only be reached from within the VPC or via controlled outbound connections.3

    WHY THIS MATTERSIncorrect VPC patterns lead to security vulnerabilities, performance bottlenecks, or complete service outages, directly impacting application reliability and data integrity. Properly designed architectures are fundamental for maintaining a robust and secure cloud environment, especially when handling sensitive customer data or critical business operations.4

    TRY IT

    A company initially deployed a simple web application with its web servers in a public subnet and its database in a private subnet, using an Internet Gateway and a NAT Gateway. Now, they want to add a new internal analytics service that needs to periodically fetch updates from a third-party API on the internet, but should never be directly accessible from the internet. Where should this analytics

    Hint

    Consider which subnet type provides the necessary outbound connectivity without exposing the service to inbound internet traffic.

Sources · 8
Practice

Reading it is the easy half.

In the app this lesson does not stop here. Each of the 6 concepts ends with a prompt you answer from memory before you are shown the answer, and behind them sit 12 quiz questions and 10 flashcards. What you get shaky on comes back on a schedule built from how you actually did - which is the whole point, and the reason it needs an account: your answers and your review dates have to live somewhere.

3 free lessons a month. No card.

Two more, in other subjects