Amazon VPC Made Easy | Public vs Private Subnets | AWS Builder Challenge Day 12 — Transcript
Full transcript
- 0:02Welcome back cloud builders. You have
- 0:04made it to day 12 of the AWS builder
- 0:06challenge.
- 0:07Today we are tackling a topic that makes
- 0:09a lot of beginners nervous.
- 0:11That is networking.
- 0:12But I promise you by the end of this
- 0:14video it's going to make perfect sense.
- 0:17We are diving into the VPC, that is the
- 0:19virtual private cloud.
- 0:21This is arguably the most important
- 0:23lesson in the entire course because 10
- 0:25to 15% of your cloud practitioner exam
- 0:27will come directly from what we talk
- 0:29about today.
- 0:30Plus every single thing you build in the
- 0:32AWS relies on a network. So grab a fresh
- 0:34cup of coffee or chai, open your
- 0:36notebooks and let's secure the private
- 0:38slice of the AWS cloud.
- 0:41So here's what we are covering today.
- 0:43First we will demystify the VPC and talk
- 0:45about the difference between private and
- 0:47public subnets. We are going to look at
- 0:50how traffic flows in and out using
- 0:52internet gateways and NAT gateways. We
- 0:55will see those all. Then we will tackle
- 0:57the most common networking question on
- 0:59the exam. That is difference between
- 1:01security groups and NACLs.
- 1:05Finally we will zoom out and look at the
- 1:06AWS global networking services and we
- 1:08will wrap up all with an awesome
- 1:10hands-on lab where you will build your
- 1:12own custom VPC from scratch. And you
- 1:15stick around until the very end because
- 1:16we are going to do a live walk through
- 1:19of three mock exam questions to test
- 1:21your knowledge. So let's get into it.
- 1:24Let's start with the VPC.
- 1:28Think of the AWS cloud like a massive
- 1:31open piece of land.
- 1:33A VPC, that is virtual private cloud, is
- 1:36when you put a giant secure fence around
- 1:39that specific plot of that land and say
- 1:41this is my corporate network and I
- 1:43control exactly who gets to come in.
- 1:47This is what VPC is.
- 1:49When you create a VPC, you have to
- 1:50assign it an IP address range using
- 1:52something called as CIDR
- 1:54notation.
- 1:56For the exam, you don't need be a math
- 1:58genius, but you do need to know basics.
- 2:01Like if you assign a /16 network,
- 2:06like
- 2:0710.0.0.0/16,
- 2:13you are claiming a massive plot of land
- 2:15with over 65,000
- 2:17private IP addresses.
- 2:19But we don't just throw all our servers
- 2:21into a big room. We divide our VPC into
- 2:24small chunks called subnets.
- 2:28To keep this analogy going,
- 2:30if the VPC is your town that is /16,
- 2:34a subnet is a specific street. Let's say
- 2:37/24
- 2:39with 256 IP addresses.
- 2:42Think of a public subnet like a lobby of
- 2:44a secure office building. It is
- 2:46accessible from the outside street.
- 2:49We put things here that the world needs
- 2:50to see, like our web servers or load
- 2:52balancers.
- 2:54So, what makes it public?
- 2:56It has a direct route to an internet
- 2:58gateway called IGW,
- 3:01which is a literal front door connecting
- 3:03your VPC to the public internet. It
- 3:05allows two-way traffic.
- 3:08Okay? But what about your precious
- 3:10customer databases?
- 3:12You never want those touching the public
- 3:14internet, so we put them in the private
- 3:16subnet.
- 3:17This is like the safe in the back
- 3:19office, and it has absolutely no route
- 3:21to the internet gateway. And if a hacker
- 3:23tries to access your database from the
- 3:24internet, they physically cannot reach
- 3:26it.
- 3:27But here's the catch. If your private
- 3:28database need to download a security
- 3:30update from the internet, it can't go
- 3:32through the front door.
- 3:34This is where the NAT gateway comes in.
- 3:36What is NAT gateway? A NAT gateway sits
- 3:39in the public subnet and it acts like a
- 3:41valet or a mail room, you can say that.
- 3:43Uh so, your private databases hands its
- 3:45request to the NAT gateway, and the NAT
- 3:47gateway goes out to the internet and
- 3:49gets the update and brings it back. So,
- 3:51this is how it works.
- 3:53So, it allows private servers to talk
- 3:55out, but completely blocks anyone from
- 3:57the internet trying to come in.
- 3:59So, this is how it works.
- 4:03So, now please pay close attention to
- 4:05this slide because I guarantee you you
- 4:07will see this comparison on the exam.
- 4:09AWS gives you two different types of
- 4:11firewalls to protect our servers.
- 4:13The first one is security group and
- 4:15another one is NACLs.
- 4:17So, let's start with security group.
- 4:20Think of a security group as a highly
- 4:22intelligent bouncer standing right
- 4:24outside the door of a specific EC2
- 4:26instance.
- 4:27So, it protects the instance. The most
- 4:30important word to associate with a
- 4:31security group is stateful. What do this
- 4:34means?
- 4:35This means the bouncer has a great
- 4:37memory.
- 4:38When I say bouncer, I mean security
- 4:40group.
- 4:41Let's say if you configure a rule to let
- 4:43traffic in on port 80.
- 4:45The bouncer remembers that traffic.
- 4:48When your server responds, the bouncer
- 4:50automatically lets the traffic back out.
- 4:53You don't have to write an outbound
- 4:54rule.
- 4:56Also, the security groups only have
- 4:58allow rules. You can't write a rule
- 5:00explicitly to block one specific person.
- 5:04All right, so now let's take a look at
- 5:06NACL.
- 5:07That is network access control list.
- 5:11Think of NACL as a border patrol for the
- 5:14entire subnet.
- 5:15It protects the whole neighborhood, not
- 5:17just one house.
- 5:20The keyword for NACLs is stateless.
- 5:24Border patrol has no memory.
- 5:26If you allow traffic in,
- 5:28the guard on the other side doesn't
- 5:29care. They will block the return traffic
- 5:31unless you explicitly write an outbound
- 5:33rule to let it out.
- 5:35You have to write rules for both the
- 5:37directions.
- 5:39However, unlike security groups, NACLs
- 5:41allow you to write explicit deny rules
- 5:43as well.
- 5:44If you find a specific malicious IP
- 5:47address attacking you,
- 5:49you can simply put it on the NACL block
- 5:51list to stop them at the border.
- 5:55So, remember this.
- 5:57Stateful
- 5:59equals security group.
- 6:01And stateless equal
- 6:03NACL.
- 6:07Now, let's zoom out.
- 6:09What happens when your users are in
- 6:10Australia,
- 6:12but your VPC is all the way in New York?
- 6:15If you want to deliver content
- 6:17incredibly fast, you use CloudFront.
- 6:21So, you might have heard this term in
- 6:22previous videos. This is AWS content
- 6:25delivery network.
- 6:27It caches your website images and videos
- 6:29at 100 of edge locations around the
- 6:31world, so that your user in Australia
- 6:33downloads the image from the Sydney, not
- 6:35New York.
- 6:37And talking about Route 53,
- 6:41it is the internet's phone book.
- 6:43It's AWS highly available DNS service.
- 6:45It translates human-friendly names like
- 6:47google.com into the IP addresses
- 6:49computer used to talk to each other.
- 6:52If you have a global app, you can use
- 6:54global accelerator.
- 6:57Instead of user traffic bouncing through
- 6:58the unpredictable public internet,
- 7:00global accelerator routes them through
- 7:01the AWS private lightning-fast fiber
- 7:04optic network as quickly as possible.
- 7:07And finally,
- 7:09how does a corporate office connect to
- 7:10AWS?
- 7:13If you want cheap and secure, use a
- 7:14site-to-site VPN.
- 7:16It creates an encrypted tunnel over the
- 7:18public internet, and it's fast to set
- 7:20up, but your speeds might vary based on
- 7:21the internet traffic.
- 7:23But if you are a massive enterprise that
- 7:25needs guaranteed speed with zero
- 7:26internet congestion,
- 7:28you buy AWS Direct Connect.
- 7:32This is literal private dedicated fiber
- 7:34optic cable connecting your physical
- 7:35data center straight into AWS.
- 7:43All right, everyone. We will spend the
- 7:45last few minutes understanding what VPC
- 7:47is in theory.
- 7:48Now, it's time to build one ourselves.
- 7:50And honestly, this is one of my favorite
- 7:51labs in the entire AWS Cloud
- 7:53Practitioner course, because today we
- 7:55are not just clicking button inside AWS,
- 7:57but we are actually designing our own
- 7:59cloud network.
- 8:00After today's lab, you will understand
- 8:02how AWS networking is built from the
- 8:04ground up. And this is one of the most
- 8:06important in topics in the AWS Cloud
- 8:08Practitioner exam, also.
- 8:09So, let's jump into the AWS console.
- 8:12Simply search for VPC
- 8:15and open the VPC dashboard.
- 8:19Before we create our own VPC, I want you
- 8:21to show something extremely important.
- 8:23On the left-hand side, you will see your
- 8:25VPCs. Click on that.
- 8:28Now, you will probably see something
- 8:30similar to what I'm seeing on the
- 8:31screen. I do have already one VPC
- 8:33created.
- 8:35And most beginners immediately ask this
- 8:37question.
- 8:38So, where did this default VPC come
- 8:40from? I never created it. And that's
- 8:42really a fantastic question.
- 8:44Actually, whenever AWS creates a new
- 8:47region for your account, it
- 8:48automatically creates one ready-to-use
- 8:50VPC.
- 8:53Think of it like buying a brand-new
- 8:54laptop.
- 8:55When you switch it on, Windows is
- 8:56already installed.
- 8:58Similarly, AWS already prepares one
- 9:00network for you that is called default
- 9:02VPC. And inside this default VPC,
- 9:05already AWS already has almost
- 9:07everything like subnets, route tables,
- 9:09internet gateway, ACL, security group.
- 9:12It has already
- 9:14been made, and they are already
- 9:15connected.
- 9:17That's why on previous days, you could
- 9:19simply launch an EC2 instance
- 9:20immediately without creating any
- 9:22networking.
- 9:23AWS had already done all the hard work.
- 9:27So, should you delete this default VPC?
- 9:29This is another common question.
- 9:31Technically, can you delete it? Yes.
- 9:34So, AWS allows you to delete default VPC
- 9:36as well. But, should you?
- 9:39See, for beginners, absolutely not. Many
- 9:42tutorials, sample project,
- 9:44CloudFormation template, beginners lab,
- 9:46they all expect the default VPC to
- 9:48exist. And deleting it won't break AWS,
- 9:51but it may trigger many beginner
- 9:52exercises.
- 9:54If one day you accidentally delete it,
- 9:56don't panic. It can be recreated using
- 9:58the AWS CLI or with the AWS support.
- 10:01But, for learning, I recommend it
- 10:03leaving it exactly as it is.
- 10:05We are simply going to ignore it, and
- 10:07today we will build our own network from
- 10:09scratch. That way you will understand
- 10:10every single networking component
- 10:12instead of relying on AWS to build it
- 10:14automatically.
- 10:16So, to create VPC, click on create VPC.
- 10:20Immediately, you will notice something
- 10:21interesting. AWS gives you two choices.
- 10:24There is VPC only and VPC and more.
- 10:28Think about building a house.
- 10:30The first option is just give me the
- 10:32land.
- 10:33That's VPC only.
- 10:35And the second option is give me the
- 10:37land, the roads, electricity, parking,
- 10:40water,
- 10:41everything already built. That's VPC and
- 10:43more.
- 10:44So, if you select VPC and more, AWS
- 10:46automatically creates public subnets,
- 10:48private subnets, internet gateway, route
- 10:50tables, NAT gateway as well.
- 10:54And several other networking resources.
- 10:56And it's fantastic option for quickly
- 10:58creating production-ready environment.
- 10:59But, today our goal isn't a speed. Our
- 11:02goal is learning. We want to understand
- 11:04what every networking component actually
- 11:06does. So, we will choose VPC only. We
- 11:08will build everything ourselves.
- 11:10Let's simply name this VPC as my custom
- 11:14VPC.
- 11:16Remember, this is just a friendly name.
- 11:18AWS internally identifies the VPC using
- 11:20its VPC ID.
- 11:22The name simply makes it easier for us
- 11:24to recognize.
- 11:26Now, we have come to something that
- 11:28scares almost every beginner.
- 11:30That is CIDR.
- 11:32Don't worry, it looks complicated, but
- 11:34it's actually very simple.
- 11:36Imagine AWS has sold us a huge piece of
- 11:39land, and that land needs boundaries.
- 11:42So, CIDR simply defines those
- 11:44boundaries.
- 11:46Our VPC will own the address space. Let
- 11:48us say 10.0.0.0/16.
- 11:54The number after the slash, that is /16,
- 11:56defines the size of our network. And you
- 11:59don't need to memorize subnet
- 12:00mathematics for the Cloud Practitioner
- 12:02exam. Just remember this simple rule
- 12:04that the smaller the number after the
- 12:06slash, the larger the network.
- 12:08That is a 16, that is /16, network
- 12:11contains around 65,536
- 12:14IP addresses.
- 12:16Think of it as buying an entire
- 12:18city-size plot of land. We're not going
- 12:20to use all the addresses today. We are
- 12:22simply reserving the space.
- 12:24Later, we will divide this larger land
- 12:26into the smaller neighborhoods. These
- 12:27neighborhoods are called subnets.
- 12:31So, let me enter this. And yeah, you
- 12:35will notice this manual input vs. IPAM.
- 12:38What do you mean by that?
- 12:41See, IPAM stands for IP Address Manager.
- 12:46Large companies may have hundreds of
- 12:47VPCs, thousands of subnets, millions of
- 12:50IP addresses.
- 12:51Managing all those addresses manually
- 12:53become difficult.
- 12:55AWS IP Address Manager can automatically
- 12:58allocate IP ranges and prevent
- 12:59conflicts. Since we are creating only in
- 13:02one VPC, so we don't need IPAM for now.
- 13:05We will simply use manual input. And the
- 13:07next option you see is IPv6. IPv6 CIDR
- 13:11block.
- 13:12You might be wondering what happened to
- 13:13IPv5. Actually, IPv5 was an experimental
- 13:17protocol and was never widely adopted.
- 13:21The internet today mainly uses IPv4 and
- 13:23IPv6. And IPv4 has around 4.3 billion
- 13:27addresses.
- 13:29Years ago that sounded like a enormous
- 13:31number, but today with billions of
- 13:33phones, laptop, IoT devices, servers,
- 13:36the world almost has exhausted IPv4
- 13:38addresses. So, IPv6 solved that problem
- 13:42by providing an unimaginably large
- 13:44address space. For today's beginners
- 13:47lab, we don't need IPv6, so we will
- 13:49leave it as no IPv6 CIDR block.
- 13:54Now, let's take a look at another
- 13:55setting that is tenancy.
- 13:58Many beginners ignore this completely,
- 13:59but it actually very easy to understand.
- 14:02Tenancy answers one question.
- 14:04Who owns the physical server? When we
- 14:07select default, AWS can place our
- 14:09virtual machines alongside virtual
- 14:11machines belonging to other AWS customer
- 14:13on the same physical hardware.
- 14:16Don't worry, everything remains
- 14:17completely isolated through
- 14:18virtualization, and that is perfectly
- 14:21fine and perfectly safe as well.
- 14:24The another option we do have is
- 14:25dedicated. That means the physical
- 14:27server belongs to only your AWS account.
- 14:30Large enterprises, government
- 14:31organizations sometimes require
- 14:33dedicated tenancy for compliance
- 14:34reasons.
- 14:36But, it's significantly more expensive,
- 14:37and for almost every project, including
- 14:40this course, default tenancy is exactly
- 14:42what we need.
- 14:44So, I will click on create VPC.
- 14:46And that's it. Congratulation, you have
- 14:48officially built your first custom AWS
- 14:50network. This is not an EC2 instance,
- 14:53not an S3 bucket, but an actual private
- 14:56cloud network.
- 14:58So, let us verify this. Uh you can see I
- 15:01do have two VPCs now. AWS default VPC
- 15:04and the one we just created. Remember,
- 15:07we are going to leave the default VPC
- 15:08untouched, and everything we will build
- 15:10from now on, subnets, internet gateway,
- 15:12route tables, will belong to our new
- 15:15custom VPC.
- 15:17So now, we own a huge piece of land with
- 15:20over 65,000
- 15:22possible IP addresses. But obviously, uh
- 15:24we are not going to build one giant
- 15:26city. Just like real cities are divided
- 15:28into neighborhoods, our VPC also needs
- 15:30to be divided into smaller sections.
- 15:32Those sections are called subnets, and
- 15:34that's exactly what we are going to
- 15:36build in the next part.
- 15:39So, we now have our own custom VPC, but
- 15:41right now our VPC is completely empty.
- 15:44Think of it as buying a used piece of
- 15:46land. You own the land, but there are no
- 15:48roads, no buildings, no neighborhoods,
- 15:50nothing.
- 15:51So, the next logical step is to divide
- 15:53this large network into smaller
- 15:54sections. In AWS, these smaller sections
- 15:57are called subnets.
- 15:59Before we create them, let's first
- 16:00understand what a subnet actually is.
- 16:03Imagine
- 16:05this rectangle is our VPC.
- 16:08Earlier, what I said was like buying an
- 16:10entire city and ask yourself, would a
- 16:12real city have this only one huge
- 16:14neighborhood?
- 16:16Of course not.
- 16:17A city is divided into different areas,
- 16:20residential area, commercial area,
- 16:23industrial area,
- 16:24school zone, hospital zone. Exactly the
- 16:27same thing happens in AWS. Instead of
- 16:29putting every EC2 instances in one giant
- 16:32network, we divide the VPC into smaller
- 16:34networks.
- 16:35Those smaller networks are called
- 16:37subnets.
- 16:38So, remember this definition. A subnet
- 16:40is simply a smaller network inside a
- 16:43VPC.
- 16:45Now, let's click on subnets.
- 16:47You will probably notice something here.
- 16:50Uh that is I have already have three
- 16:52subnets.
- 16:53And this is where many beginners become
- 16:54confused. They ask, "Sir, we haven't
- 16:56created any subnets yet."
- 16:58So, where did these come from?
- 17:01Excellent question. Let's look
- 17:03carefully. Notice all the three subnets
- 17:05belong to the default VPC,
- 17:07not our custom VPC.
- 17:10AWS automatically creates them. But why
- 17:13exactly three? Let's find it out. See,
- 17:17every AWS region contains one or more
- 17:19availability zones.
- 17:21Remember from previous lesson, an AZ is
- 17:23an independent data center or more
- 17:25accurately one or more closely connected
- 17:27data centers.
- 17:29The Mumbai region has three AZs, that is
- 17:31AP South 1A, AP South 1B, and 1C. So,
- 17:35AWS automatically creates one subnet
- 17:37inside each availability zones for the
- 17:39default VPC.
- 17:41That's why we exactly see three default
- 17:44subnets.
- 17:45If tomorrow, let's say AWS adds one
- 17:47another AWS
- 17:48availability zones to this region,
- 17:50future default VPC may include another
- 17:52default subnet as well.
- 17:55Another question is, why can't AWS
- 17:57create one giant subnet?
- 18:00Suppose your entire office building has
- 18:02only one room.
- 18:03Think about it. Where would the HR sit?
- 18:06Where would the finance sit? Where would
- 18:08the engineering sit?
- 18:11Networking works the same way.
- 18:13Different applications usually belong to
- 18:14the different subnets. Some need
- 18:16internet access, some should never be
- 18:18exposed to the internet. Some are
- 18:20databases, some are web servers.
- 18:23Separating them into different subnet
- 18:25makes the network more secure and
- 18:27scalable, and it is easier to manage as
- 18:29well.
- 18:31So, let's examine one of the default
- 18:32subnets. You will notice something like
- 18:34172.31.0.0/20.
- 18:40Another one says 172.31.16.0/20.
- 18:46And another
- 18:4831.32.0/20.
- 18:51So, why are these different?
- 18:54Because every subnet must have its own
- 18:56unique range of IP addresses.
- 18:59Imagine two houses having exactly same
- 19:01postal address. The courier would never
- 19:03know where to deliver packages.
- 19:06The same thing would happen in the
- 19:07networking as well. If two subnets share
- 19:09the same IP range, AWS wouldn't know
- 19:11where the traffic should go.
- 19:14That's why every subnet gets its own
- 19:16unique CIDR block.
- 19:18You will also see various other options
- 19:20like it shows 4091 available IP
- 19:23addresses.
- 19:24And yeah, filtering the subnets. So, let
- 19:27us skip these things and first create
- 19:30our first subnet.
- 19:32I will click on create subnet. And the
- 19:34first option ask us to select the VPC.
- 19:37Why? Because a subnet cannot exist by
- 19:39itself. Every subnet belongs to exactly
- 19:42one VPC.
- 19:43Uh think of it as this way, you can't
- 19:45build a neighborhood without first
- 19:47buying the land.
- 19:49The VPC is the land and the subnet is
- 19:51the neighborhood.
- 19:53So, choose my custom VPC.
- 19:57The next option ask us to select the
- 19:59availability zone. Many beginners wonder
- 20:01why I'm choosing an availability zone
- 20:03for a subnet.
- 20:05Because one subnet can belong to only
- 20:07one AZ. It cannot span multiple AZs.
- 20:12Think of a city.
- 20:14One neighborhood cannot exist in two
- 20:15different cities at the same time.
- 20:18Similarly, one subnet cannot exist
- 20:19inside two AZs.
- 20:21If you want resources in another
- 20:23availability zone,
- 20:25you create another subnet there.
- 20:27This design is what gives AWS high
- 20:29availability.
- 20:31If one AZ experiences a failure, your
- 20:33resources in another AZ continue
- 20:35running.
- 20:37Let's create our first subnet. Let's
- 20:38name it public subnet and AZ is AP South
- 20:42A1.
- 20:44And IPv4 CIDR, let me put 10.0.1.0/24.
- 20:52Now, many students immediately ask,
- 20:54"Sir, why we are writing 10.0.1.0/24?"
- 20:59Let's understand that as well.
- 21:01Uh remember earlier our VPC owned this
- 21:04entire address range, that is
- 21:0610.0.0.0/16.
- 21:09We wrote that.
- 21:11Now, we are carving out one small piece
- 21:13of it. That small piece becomes our
- 21:15public subnet.
- 21:17The /24 means the subnet contains 256 IP
- 21:20addresses. Again, AWS reserves five
- 21:23addresses, so approximately 251
- 21:25addresses remain usable.
- 21:28That's more than enough for our lab.
- 21:31Now, let's create another subnet. Let's
- 21:32name it private subnet.
- 21:36Availability zone, I will select AP
- 21:39South 1B, and CIDR block
- 21:4310.0.2.0/24.
- 21:49Notice something important, the CIDR
- 21:51block is different.
- 21:52Why is that? Because no two subnets can
- 21:56overlap.
- 21:57If our first subnet owns 1.0/24,
- 22:02then our second subnet must use another
- 22:04range. That I'm using 2.0/24.
- 22:09Now, AWS exactly knows which IP
- 22:11addresses belong to which subnet.
- 22:14So, you might have noticed that AWS
- 22:16console allows you to create multiple
- 22:18subnet in one screen. So, that's simply
- 22:21a convenience feature instead of opening
- 22:22the create subnet page multiple times,
- 22:25AWS lets you define several subnet
- 22:28configuration before clicking create.
- 22:31Each subnet has its own name, AZ, and
- 22:34CIDR block. AWS simply creates all of
- 22:36them together.
- 22:38So, till now we have created one VPC,
- 22:40and inside VPC we have created subnets.
- 22:44We have created two subnets, private and
- 22:46public.
- 22:48But right now, both of these subnets are
- 22:50completely isolated. Neither of them has
- 22:52internet access.
- 22:53Why? Because we have built
- 22:55neighborhoods, but we haven't built any
- 22:57roads connecting them to the outside
- 22:59world.
- 23:00And that's what exactly we will do next
- 23:02and in this next part we will create our
- 23:05own network gateway and understand how
- 23:08it actually works behind the scenes and
- 23:10connect our VPC to the internet just
- 23:11like connecting the city to a national
- 23:13highway.
- 23:14So let's create one. On the navigation
- 23:16menu click on internet gateways.
- 23:19Now click on create internet gateway.
- 23:23You will notice AWS only ask for one
- 23:26thing that is a name tag. Then let's
- 23:27call it my
- 23:29AWS.
- 23:31Now you might wonder why isn't AWS
- 23:33asking me to select my VPC? That's
- 23:35because we are only creating the
- 23:37internet gateway.
- 23:38At this stage it exists independently.
- 23:41It just It is just like buying a new
- 23:43Wi-Fi router. Buying the router doesn't
- 23:45automatically connect it to your home
- 23:47network.
- 23:48You still have to plug it it in.
- 23:51Similarly, after creating an internet
- 23:53gateway, we still need to attach it to
- 23:55VPC.
- 23:57Click create internet gateway. Perfect.
- 23:59Now our internet gateway exists, but it
- 24:02is still isn't connected to anything. So
- 24:04I will click on attach to VPC over here.
- 24:07Now AWS ask which VPC do you want to
- 24:10connect this internet gateway to so? I
- 24:11will select my custom VPC that I just
- 24:14created now.
- 24:15Click attach and done.
- 24:18Now our VPC has a connection point to
- 24:20the internet.
- 24:21But here's something very important.
- 24:23Just attaching an internet gateway does
- 24:25not give internet access to the EC2
- 24:27instances.
- 24:29Many beginners think that this step is
- 24:31enough. It isn't.
- 24:33The internet gateway is available, but
- 24:35our subnets don't know yet how to reach
- 24:36it. For that we need something called as
- 24:39route table.
- 24:41So now let's understand what route table
- 24:43actually is.
- 24:44Think of route table as a Google Maps
- 24:46for your network.
- 24:48Whenever an EC2 instance sends data, AWS
- 24:51checks the route table and ask, "Where
- 24:53should I send this packet?"
- 24:56And the route table provides the answer.
- 25:00It contains a list of routes where each
- 25:02route has two parts.
- 25:04Destination
- 25:06and target.
- 25:07The destination tells AWS where the
- 25:09traffic wants to go
- 25:11and the target tells AWS where to send
- 25:13that traffic.
- 25:15Without a route table, AWS has no idea
- 25:18where the packets should travel.
- 25:20On the left menu, you can see route
- 25:22tables. Click on that. You will probably
- 25:24see several uh route tables. Some belong
- 25:26to the default VPC.
- 25:29We don't want those. You will find this
- 25:31main route table that automatically uh
- 25:33AWS has created when we created our VPC.
- 25:36Every VPC automatically gets its one
- 25:39main route table. We are going to use
- 25:41this route table as our public subnet.
- 25:44Open the routes table.
- 25:46Click edit routes. You will notice there
- 25:49is already one route that is destination
- 25:5110.0.0.0/16
- 25:53target local.
- 25:55What does this mean? This route tells
- 25:57AWS if the traffic is destined for any
- 26:00IP address inside the VPC,
- 26:03keep it inside the VPC.
- 26:06This route is automatically created by
- 26:07AWS. Never delete it. Uh it allows
- 26:10resources inside the VPC to communicate
- 26:11with each other. Now let's add another
- 26:14route that is
- 26:16add route.
- 26:17For destination, enter 0.0.0.0/
- 26:210.
- 26:22This is one of the most important values
- 26:24in AWS networking. It means every IPv4
- 26:27address that isn't inside my VPC
- 26:30or simply anywhere on the internet.
- 26:32Now for target, choose internet gateway
- 26:37and then select
- 26:38my AWS
- 26:41and click on save.
- 26:43So now congratulations, we have just
- 26:44told AWS whenever traffic wants to go
- 26:47anywhere on the internet, send it to our
- 26:50internet gateway.
- 26:53But wait, we are still not finished.
- 26:54Right now, the route table isn't
- 26:56actually being used by our public
- 26:57subnet.
- 26:59So, let's fix that.
- 27:00Stay inside the same route table and
- 27:02open the subnet association tab.
- 27:05And click on edit subnet associations.
- 27:09Select public subnet, click save
- 27:11associations, and done.
- 27:14Now, our public subnet is using this
- 27:16route table.
- 27:18This means every EC2 instance launched
- 27:20inside this subnet will follow these
- 27:22routing rules.
- 27:24Now, let's configure the private subnet.
- 27:27Go back to the route tables.
- 27:29Click create route table.
- 27:31Name it private route table.
- 27:36Okay, and then choose the VPC, the one
- 27:39that we just created.
- 27:42Click on create.
- 27:45Okay.
- 27:46Great. So, open this new route table and
- 27:49now go to subnet associations.
- 27:54And click on edit subnet associations
- 27:56and select
- 27:59private subnet.
- 28:01And save.
- 28:03Now, notice something important. Open
- 28:05the routes table and you will see this.
- 28:0910.0.0.0/16
- 28:12local. That's it. We are not going to
- 28:14add another rule.
- 28:17Specifically, we are not adding
- 28:190.0.0.0/0,
- 28:21that is the internet gateway.
- 28:23Why? This is supposed to be a private
- 28:25subnet. Resources inside a private
- 28:27subnet should be able to communicate
- 28:29with other resources inside the VPC, but
- 28:31they should not be directly reachable
- 28:33from the internet.
- 28:36By simply not adding an internet route,
- 28:38we have completely isolated this subnet
- 28:40from the outside world.
- 28:42So, yes.
- 28:44Uh, what we have done till now? We have
- 28:45created custom VPC. We then created
- 28:48public subnets and private subnet.
- 28:51Then we created and attached an internet
- 28:52gateway.
- 28:54Then we configured a public route table
- 28:56with 0.0.0.0/0.
- 28:59That is the internet gateway.
- 29:01We associated the public subnet with
- 29:03this route table.
- 29:05Also, we created a separate private
- 29:07route table that contains only the local
- 29:08route.
- 29:10As a result, an EC2 instance launched in
- 29:13the public subnet can communicate with
- 29:15the internet.
- 29:17Provided it also has a public IPv4
- 29:19address and an appropriate security
- 29:21group rules.
- 29:23Any EC2 instance launched in the private
- 29:25subnet can communicate only within the
- 29:27VPC and remains isolated from the public
- 29:29internet.
- 29:30This is the same networking pattern you
- 29:32will see in many real AWS architectures,
- 29:35and it is an important concept for the
- 29:37AWS certified cloud practitioner exam as
- 29:39well.
- 29:41So, remember this one.
- 29:44It is so incredibly satisfying to watch
- 29:46this come together.
- 29:47Please take time to run through this lab
- 29:49in your own console as well.
- 29:52Now, let's do a quick rapid-fire recap
- 29:54of everything we have covered today.
- 29:57So, let's see what connects a public
- 29:59subnet to the internet.
- 30:01The answer is an internet gateway.
- 30:05What lets private instances download
- 30:08updates safely?
- 30:11A NAT gateway.
- 30:14And which firewall is stateful protects
- 30:16the instance?
- 30:18A security group.
- 30:20Correct one.
- 30:22Which firewall is stateless and protects
- 30:25the subnet?
- 30:26That is
- 30:27NACL.
- 30:30And what gives you a dedicated private
- 30:32fiber connection to AWS?
- 30:35The answer is
- 30:37Direct Connect.
- 30:40This was a heavy day.
- 30:42So, your homework tonight is critical.
- 30:44Jump into the practice portal and knock
- 30:46down 20 networking questions.
- 30:48And yeah, I guess there will be 10. So,
- 30:51knock down any amount of question that
- 30:53are in the practice portal today.
- 30:55Focus really hard on those scenario
- 30:56question that try to trick you between
- 30:58the security groups and NACLs.
- 31:01Tomorrow on day 13, we are diving into
- 31:03databases.
- 31:05We will break down RDS, Aurora,
- 31:07DynamoDB, Redshift. And it is going to
- 31:10be a fantastic session.
- 31:13So, that's all for today.
- 31:14Keep building.
- 31:16Keep learning.
- 31:17I will see you tomorrow.
About this transcript
This page contains the full transcript of Amazon VPC Made Easy | Public vs Private Subnets | AWS Builder Challenge Day 12 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 4,551 words across 838 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.