VPC: Subnets, NAT & Firewalls
AWS for Interviews: lesson 5 of 18
Routes decide where a packet can go; firewalls decide whether it may.
Lesson 5 of 18 · 7 min
VPC: Subnets, NAT & Firewalls
Step 1 of 11
A VPC is your private network in one Region. Each subnet lives in exactly one Availability Zone.
The Idea
A VPC is a private network spanning every Availability Zone in a Region; each subnet sits in one zone. A subnet is public when its route table sends 0.0.0.0/0 to an internet gateway. Private subnets reach out through a NAT gateway in a public subnet. Security groups are stateful allow-lists on instances; network ACLs are stateless, numbered allow and deny rules on subnets.
Real-World Example
A web app puts its load balancer and NAT gateway in public subnets and its app servers and database in private ones. The database's security group allows port 5432 only from the app servers' security group.
The Tradeoff
A NAT gateway bills per hour and per GB processed, so send S3 and DynamoDB traffic through gateway endpoints instead. Keep NACLs coarse: because they are stateless, every reply needs its own rule.
Hands-On
# illustrative — IDs are placeholders
aws ec2 create-route --route-table-id rtb-public \
--destination-cidr-block 0.0.0.0/0 --gateway-id igw-0abc
aws ec2 create-route --route-table-id rtb-private \
--destination-cidr-block 0.0.0.0/0 --nat-gateway-id nat-0abc
aws ec2 authorize-security-group-ingress --group-id sg-db \
--protocol tcp --port 5432 --source-group sg-app
Your turn
Put the steps in the right order.
- The load balancer in a public subnet receives it
- The database accepts the app's query because the app's security group is allowed
- The request enters through the internet gateway
- The app server in a private subnet handles it
Mini quiz
1 / 3
What makes a subnet public?
Sources
- Subnets for your VPC — Amazon VPC User Guide
- NAT gateway use cases — Amazon VPC User Guide
- Compare security groups and network ACLs — Amazon VPC User Guide
- Gateway endpoints — AWS PrivateLink