SimAWSby ShahriarLabs
Search

The network your resources live in · Chapter 1 of 3

How VPC routing creates public subnets

Public and private subnets are defined by route tables rather than simple checkboxes, but mastering subnet configuration and IP limits lets you design a secure, scalable network boundary.

FoundationsBuilds the idea from nothing. No prior AWS assumed.

The route table determines subnet accessibility

What makes a subnet public in an AWS VPC?

VPC 10.0.0.0/16Public Subnet 10.0.1.0/24Private Subnet 10.0.2.0/24Internet Gatewayigw-01234Public EC210.0.1.10Private EC210.0.2.10A subnet is only public if its route table explicitly routes 0.0.0.0/0 traffic to an Internet Gateway.

The Internet Gateway attaches to the VPC border to provide internet connectivity.

1/4
  1. 01

    There is no public checkbox

    When you create a subnet in the AWS Console, there is no setting that declares it public or private. A subnet is public only because its associated route table contains a route that points `0.0.0.0/0` to an Internet Gateway. Without this route, instances in the subnet cannot communicate with the public internet.

  2. 02

    Why subnets live in one zone

    A subnet represents a range of IP addresses within a VPC. Physically, a subnet is bound to a single Availability Zone. This separation ensures that a hardware failure in one data centre does not interrupt traffic on subnets running in other zones.

  3. 03

    The purpose of private subnets

    Private subnets are designed for backend services like databases or internal APIs that must never be exposed to the internet. These subnets do not have a route to an Internet Gateway. Instead, they use a NAT Gateway to fetch updates, or remain completely isolated.

Check yourself

You launch an EC2 instance with a public IP address into a subnet, but it cannot reach the internet. What is the most likely networking misconfiguration?

Under the hoodThe same thing from underneath: limits, failure modes, numbers.

IP planning and size limitations

How do subnet sizing and AWS-reserved IP addresses affect your network design?

VPC 10.0.0.0/16Public Subnet 10.0.1.0/24Private Subnet 10.0.2.0/24Internet Gatewayigw-01234Public EC210.0.1.10Private EC210.0.2.10A subnet is only public if its route table explicitly routes 0.0.0.0/0 traffic to an Internet Gateway.

The Internet Gateway attaches to the VPC border to provide internet connectivity.

1/4
  1. 01

    The reserved IPs in every subnet

    In every subnet you create, AWS reserves exactly five IP addresses for internal networking services. These include the network address, the VPC router, the DNS server, a reserved address for future use, and the broadcast address. You cannot assign these addresses to your instances.

  2. 02

    Min and max subnet sizes

    Subnet sizes are defined using CIDR block notation. The smallest subnet AWS permits is a `/28`, which provides 16 IP addresses. After subtracting the five reserved IPs, you are left with only 11 usable addresses for compute resources.

  3. 03

    Planning for scaling

    If a subnet runs out of IP addresses, you cannot launch new instances or scaling nodes within that zone. Because you cannot resize an existing subnet CIDR block, you must allocate large enough blocks from the start to accommodate peak workloads.

The numbers

AWS reserved IPs per subnet
5 IP addressesFirst four and last one IP in every subnet CIDR block.
Usable IPs in a /28 subnet
11 IPsCalculated as 16 total IPs minus the 5 reserved by AWS.
Minimum subnet size
/28 CIDR blockProvides 16 total IP addresses.
Maximum subnet size
/16 CIDR blockProvides 65,536 total IP addresses.
VPC CIDR range
/16 largest, /28 smallestA smaller prefix number means a bigger block: a /16 holds 65,536 addresses and a /28 holds 16. The VPC CIDR cannot be shrunk later, only extended with additional blocks.

Check yourself

You provision a new subnet with the CIDR block 10.0.0.0/28. How many instances can you run in this subnet?

Official references & further reading

These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.

Report an error or suggest a clearer explanation →