YouTube2Text

Amazon VPC Made Easy | Public vs Private Subnets | AWS Builder Challenge Day 12 — Transcript

by Pawan Joshi · 4,551 words · 838 segments · language en · Watch on YouTube

Full transcript

  1. 0:02Welcome back cloud builders. You have
  2. 0:04made it to day 12 of the AWS builder
  3. 0:06challenge.
  4. 0:07Today we are tackling a topic that makes
  5. 0:09a lot of beginners nervous.
  6. 0:11That is networking.
  7. 0:12But I promise you by the end of this
  8. 0:14video it's going to make perfect sense.
  9. 0:17We are diving into the VPC, that is the
  10. 0:19virtual private cloud.
  11. 0:21This is arguably the most important
  12. 0:23lesson in the entire course because 10
  13. 0:25to 15% of your cloud practitioner exam
  14. 0:27will come directly from what we talk
  15. 0:29about today.
  16. 0:30Plus every single thing you build in the
  17. 0:32AWS relies on a network. So grab a fresh
  18. 0:34cup of coffee or chai, open your
  19. 0:36notebooks and let's secure the private
  20. 0:38slice of the AWS cloud.
  21. 0:41So here's what we are covering today.
  22. 0:43First we will demystify the VPC and talk
  23. 0:45about the difference between private and
  24. 0:47public subnets. We are going to look at
  25. 0:50how traffic flows in and out using
  26. 0:52internet gateways and NAT gateways. We
  27. 0:55will see those all. Then we will tackle
  28. 0:57the most common networking question on
  29. 0:59the exam. That is difference between
  30. 1:01security groups and NACLs.
  31. 1:05Finally we will zoom out and look at the
  32. 1:06AWS global networking services and we
  33. 1:08will wrap up all with an awesome
  34. 1:10hands-on lab where you will build your
  35. 1:12own custom VPC from scratch. And you
  36. 1:15stick around until the very end because
  37. 1:16we are going to do a live walk through
  38. 1:19of three mock exam questions to test
  39. 1:21your knowledge. So let's get into it.
  40. 1:24Let's start with the VPC.
  41. 1:28Think of the AWS cloud like a massive
  42. 1:31open piece of land.
  43. 1:33A VPC, that is virtual private cloud, is
  44. 1:36when you put a giant secure fence around
  45. 1:39that specific plot of that land and say
  46. 1:41this is my corporate network and I
  47. 1:43control exactly who gets to come in.
  48. 1:47This is what VPC is.
  49. 1:49When you create a VPC, you have to
  50. 1:50assign it an IP address range using
  51. 1:52something called as CIDR
  52. 1:54notation.
  53. 1:56For the exam, you don't need be a math
  54. 1:58genius, but you do need to know basics.
  55. 2:01Like if you assign a /16 network,
  56. 2:06like
  57. 2:0710.0.0.0/16,
  58. 2:13you are claiming a massive plot of land
  59. 2:15with over 65,000
  60. 2:17private IP addresses.
  61. 2:19But we don't just throw all our servers
  62. 2:21into a big room. We divide our VPC into
  63. 2:24small chunks called subnets.
  64. 2:28To keep this analogy going,
  65. 2:30if the VPC is your town that is /16,
  66. 2:34a subnet is a specific street. Let's say
  67. 2:37/24
  68. 2:39with 256 IP addresses.
  69. 2:42Think of a public subnet like a lobby of
  70. 2:44a secure office building. It is
  71. 2:46accessible from the outside street.
  72. 2:49We put things here that the world needs
  73. 2:50to see, like our web servers or load
  74. 2:52balancers.
  75. 2:54So, what makes it public?
  76. 2:56It has a direct route to an internet
  77. 2:58gateway called IGW,
  78. 3:01which is a literal front door connecting
  79. 3:03your VPC to the public internet. It
  80. 3:05allows two-way traffic.
  81. 3:08Okay? But what about your precious
  82. 3:10customer databases?
  83. 3:12You never want those touching the public
  84. 3:14internet, so we put them in the private
  85. 3:16subnet.
  86. 3:17This is like the safe in the back
  87. 3:19office, and it has absolutely no route
  88. 3:21to the internet gateway. And if a hacker
  89. 3:23tries to access your database from the
  90. 3:24internet, they physically cannot reach
  91. 3:26it.
  92. 3:27But here's the catch. If your private
  93. 3:28database need to download a security
  94. 3:30update from the internet, it can't go
  95. 3:32through the front door.
  96. 3:34This is where the NAT gateway comes in.
  97. 3:36What is NAT gateway? A NAT gateway sits
  98. 3:39in the public subnet and it acts like a
  99. 3:41valet or a mail room, you can say that.
  100. 3:43Uh so, your private databases hands its
  101. 3:45request to the NAT gateway, and the NAT
  102. 3:47gateway goes out to the internet and
  103. 3:49gets the update and brings it back. So,
  104. 3:51this is how it works.
  105. 3:53So, it allows private servers to talk
  106. 3:55out, but completely blocks anyone from
  107. 3:57the internet trying to come in.
  108. 3:59So, this is how it works.
  109. 4:03So, now please pay close attention to
  110. 4:05this slide because I guarantee you you
  111. 4:07will see this comparison on the exam.
  112. 4:09AWS gives you two different types of
  113. 4:11firewalls to protect our servers.
  114. 4:13The first one is security group and
  115. 4:15another one is NACLs.
  116. 4:17So, let's start with security group.
  117. 4:20Think of a security group as a highly
  118. 4:22intelligent bouncer standing right
  119. 4:24outside the door of a specific EC2
  120. 4:26instance.
  121. 4:27So, it protects the instance. The most
  122. 4:30important word to associate with a
  123. 4:31security group is stateful. What do this
  124. 4:34means?
  125. 4:35This means the bouncer has a great
  126. 4:37memory.
  127. 4:38When I say bouncer, I mean security
  128. 4:40group.
  129. 4:41Let's say if you configure a rule to let
  130. 4:43traffic in on port 80.
  131. 4:45The bouncer remembers that traffic.
  132. 4:48When your server responds, the bouncer
  133. 4:50automatically lets the traffic back out.
  134. 4:53You don't have to write an outbound
  135. 4:54rule.
  136. 4:56Also, the security groups only have
  137. 4:58allow rules. You can't write a rule
  138. 5:00explicitly to block one specific person.
  139. 5:04All right, so now let's take a look at
  140. 5:06NACL.
  141. 5:07That is network access control list.
  142. 5:11Think of NACL as a border patrol for the
  143. 5:14entire subnet.
  144. 5:15It protects the whole neighborhood, not
  145. 5:17just one house.
  146. 5:20The keyword for NACLs is stateless.
  147. 5:24Border patrol has no memory.
  148. 5:26If you allow traffic in,
  149. 5:28the guard on the other side doesn't
  150. 5:29care. They will block the return traffic
  151. 5:31unless you explicitly write an outbound
  152. 5:33rule to let it out.
  153. 5:35You have to write rules for both the
  154. 5:37directions.
  155. 5:39However, unlike security groups, NACLs
  156. 5:41allow you to write explicit deny rules
  157. 5:43as well.
  158. 5:44If you find a specific malicious IP
  159. 5:47address attacking you,
  160. 5:49you can simply put it on the NACL block
  161. 5:51list to stop them at the border.
  162. 5:55So, remember this.
  163. 5:57Stateful
  164. 5:59equals security group.
  165. 6:01And stateless equal
  166. 6:03NACL.
  167. 6:07Now, let's zoom out.
  168. 6:09What happens when your users are in
  169. 6:10Australia,
  170. 6:12but your VPC is all the way in New York?
  171. 6:15If you want to deliver content
  172. 6:17incredibly fast, you use CloudFront.
  173. 6:21So, you might have heard this term in
  174. 6:22previous videos. This is AWS content
  175. 6:25delivery network.
  176. 6:27It caches your website images and videos
  177. 6:29at 100 of edge locations around the
  178. 6:31world, so that your user in Australia
  179. 6:33downloads the image from the Sydney, not
  180. 6:35New York.
  181. 6:37And talking about Route 53,
  182. 6:41it is the internet's phone book.
  183. 6:43It's AWS highly available DNS service.
  184. 6:45It translates human-friendly names like
  185. 6:47google.com into the IP addresses
  186. 6:49computer used to talk to each other.
  187. 6:52If you have a global app, you can use
  188. 6:54global accelerator.
  189. 6:57Instead of user traffic bouncing through
  190. 6:58the unpredictable public internet,
  191. 7:00global accelerator routes them through
  192. 7:01the AWS private lightning-fast fiber
  193. 7:04optic network as quickly as possible.
  194. 7:07And finally,
  195. 7:09how does a corporate office connect to
  196. 7:10AWS?
  197. 7:13If you want cheap and secure, use a
  198. 7:14site-to-site VPN.
  199. 7:16It creates an encrypted tunnel over the
  200. 7:18public internet, and it's fast to set
  201. 7:20up, but your speeds might vary based on
  202. 7:21the internet traffic.
  203. 7:23But if you are a massive enterprise that
  204. 7:25needs guaranteed speed with zero
  205. 7:26internet congestion,
  206. 7:28you buy AWS Direct Connect.
  207. 7:32This is literal private dedicated fiber
  208. 7:34optic cable connecting your physical
  209. 7:35data center straight into AWS.
  210. 7:43All right, everyone. We will spend the
  211. 7:45last few minutes understanding what VPC
  212. 7:47is in theory.
  213. 7:48Now, it's time to build one ourselves.
  214. 7:50And honestly, this is one of my favorite
  215. 7:51labs in the entire AWS Cloud
  216. 7:53Practitioner course, because today we
  217. 7:55are not just clicking button inside AWS,
  218. 7:57but we are actually designing our own
  219. 7:59cloud network.
  220. 8:00After today's lab, you will understand
  221. 8:02how AWS networking is built from the
  222. 8:04ground up. And this is one of the most
  223. 8:06important in topics in the AWS Cloud
  224. 8:08Practitioner exam, also.
  225. 8:09So, let's jump into the AWS console.
  226. 8:12Simply search for VPC
  227. 8:15and open the VPC dashboard.
  228. 8:19Before we create our own VPC, I want you
  229. 8:21to show something extremely important.
  230. 8:23On the left-hand side, you will see your
  231. 8:25VPCs. Click on that.
  232. 8:28Now, you will probably see something
  233. 8:30similar to what I'm seeing on the
  234. 8:31screen. I do have already one VPC
  235. 8:33created.
  236. 8:35And most beginners immediately ask this
  237. 8:37question.
  238. 8:38So, where did this default VPC come
  239. 8:40from? I never created it. And that's
  240. 8:42really a fantastic question.
  241. 8:44Actually, whenever AWS creates a new
  242. 8:47region for your account, it
  243. 8:48automatically creates one ready-to-use
  244. 8:50VPC.
  245. 8:53Think of it like buying a brand-new
  246. 8:54laptop.
  247. 8:55When you switch it on, Windows is
  248. 8:56already installed.
  249. 8:58Similarly, AWS already prepares one
  250. 9:00network for you that is called default
  251. 9:02VPC. And inside this default VPC,
  252. 9:05already AWS already has almost
  253. 9:07everything like subnets, route tables,
  254. 9:09internet gateway, ACL, security group.
  255. 9:12It has already
  256. 9:14been made, and they are already
  257. 9:15connected.
  258. 9:17That's why on previous days, you could
  259. 9:19simply launch an EC2 instance
  260. 9:20immediately without creating any
  261. 9:22networking.
  262. 9:23AWS had already done all the hard work.
  263. 9:27So, should you delete this default VPC?
  264. 9:29This is another common question.
  265. 9:31Technically, can you delete it? Yes.
  266. 9:34So, AWS allows you to delete default VPC
  267. 9:36as well. But, should you?
  268. 9:39See, for beginners, absolutely not. Many
  269. 9:42tutorials, sample project,
  270. 9:44CloudFormation template, beginners lab,
  271. 9:46they all expect the default VPC to
  272. 9:48exist. And deleting it won't break AWS,
  273. 9:51but it may trigger many beginner
  274. 9:52exercises.
  275. 9:54If one day you accidentally delete it,
  276. 9:56don't panic. It can be recreated using
  277. 9:58the AWS CLI or with the AWS support.
  278. 10:01But, for learning, I recommend it
  279. 10:03leaving it exactly as it is.
  280. 10:05We are simply going to ignore it, and
  281. 10:07today we will build our own network from
  282. 10:09scratch. That way you will understand
  283. 10:10every single networking component
  284. 10:12instead of relying on AWS to build it
  285. 10:14automatically.
  286. 10:16So, to create VPC, click on create VPC.
  287. 10:20Immediately, you will notice something
  288. 10:21interesting. AWS gives you two choices.
  289. 10:24There is VPC only and VPC and more.
  290. 10:28Think about building a house.
  291. 10:30The first option is just give me the
  292. 10:32land.
  293. 10:33That's VPC only.
  294. 10:35And the second option is give me the
  295. 10:37land, the roads, electricity, parking,
  296. 10:40water,
  297. 10:41everything already built. That's VPC and
  298. 10:43more.
  299. 10:44So, if you select VPC and more, AWS
  300. 10:46automatically creates public subnets,
  301. 10:48private subnets, internet gateway, route
  302. 10:50tables, NAT gateway as well.
  303. 10:54And several other networking resources.
  304. 10:56And it's fantastic option for quickly
  305. 10:58creating production-ready environment.
  306. 10:59But, today our goal isn't a speed. Our
  307. 11:02goal is learning. We want to understand
  308. 11:04what every networking component actually
  309. 11:06does. So, we will choose VPC only. We
  310. 11:08will build everything ourselves.
  311. 11:10Let's simply name this VPC as my custom
  312. 11:14VPC.
  313. 11:16Remember, this is just a friendly name.
  314. 11:18AWS internally identifies the VPC using
  315. 11:20its VPC ID.
  316. 11:22The name simply makes it easier for us
  317. 11:24to recognize.
  318. 11:26Now, we have come to something that
  319. 11:28scares almost every beginner.
  320. 11:30That is CIDR.
  321. 11:32Don't worry, it looks complicated, but
  322. 11:34it's actually very simple.
  323. 11:36Imagine AWS has sold us a huge piece of
  324. 11:39land, and that land needs boundaries.
  325. 11:42So, CIDR simply defines those
  326. 11:44boundaries.
  327. 11:46Our VPC will own the address space. Let
  328. 11:48us say 10.0.0.0/16.
  329. 11:54The number after the slash, that is /16,
  330. 11:56defines the size of our network. And you
  331. 11:59don't need to memorize subnet
  332. 12:00mathematics for the Cloud Practitioner
  333. 12:02exam. Just remember this simple rule
  334. 12:04that the smaller the number after the
  335. 12:06slash, the larger the network.
  336. 12:08That is a 16, that is /16, network
  337. 12:11contains around 65,536
  338. 12:14IP addresses.
  339. 12:16Think of it as buying an entire
  340. 12:18city-size plot of land. We're not going
  341. 12:20to use all the addresses today. We are
  342. 12:22simply reserving the space.
  343. 12:24Later, we will divide this larger land
  344. 12:26into the smaller neighborhoods. These
  345. 12:27neighborhoods are called subnets.
  346. 12:31So, let me enter this. And yeah, you
  347. 12:35will notice this manual input vs. IPAM.
  348. 12:38What do you mean by that?
  349. 12:41See, IPAM stands for IP Address Manager.
  350. 12:46Large companies may have hundreds of
  351. 12:47VPCs, thousands of subnets, millions of
  352. 12:50IP addresses.
  353. 12:51Managing all those addresses manually
  354. 12:53become difficult.
  355. 12:55AWS IP Address Manager can automatically
  356. 12:58allocate IP ranges and prevent
  357. 12:59conflicts. Since we are creating only in
  358. 13:02one VPC, so we don't need IPAM for now.
  359. 13:05We will simply use manual input. And the
  360. 13:07next option you see is IPv6. IPv6 CIDR
  361. 13:11block.
  362. 13:12You might be wondering what happened to
  363. 13:13IPv5. Actually, IPv5 was an experimental
  364. 13:17protocol and was never widely adopted.
  365. 13:21The internet today mainly uses IPv4 and
  366. 13:23IPv6. And IPv4 has around 4.3 billion
  367. 13:27addresses.
  368. 13:29Years ago that sounded like a enormous
  369. 13:31number, but today with billions of
  370. 13:33phones, laptop, IoT devices, servers,
  371. 13:36the world almost has exhausted IPv4
  372. 13:38addresses. So, IPv6 solved that problem
  373. 13:42by providing an unimaginably large
  374. 13:44address space. For today's beginners
  375. 13:47lab, we don't need IPv6, so we will
  376. 13:49leave it as no IPv6 CIDR block.
  377. 13:54Now, let's take a look at another
  378. 13:55setting that is tenancy.
  379. 13:58Many beginners ignore this completely,
  380. 13:59but it actually very easy to understand.
  381. 14:02Tenancy answers one question.
  382. 14:04Who owns the physical server? When we
  383. 14:07select default, AWS can place our
  384. 14:09virtual machines alongside virtual
  385. 14:11machines belonging to other AWS customer
  386. 14:13on the same physical hardware.
  387. 14:16Don't worry, everything remains
  388. 14:17completely isolated through
  389. 14:18virtualization, and that is perfectly
  390. 14:21fine and perfectly safe as well.
  391. 14:24The another option we do have is
  392. 14:25dedicated. That means the physical
  393. 14:27server belongs to only your AWS account.
  394. 14:30Large enterprises, government
  395. 14:31organizations sometimes require
  396. 14:33dedicated tenancy for compliance
  397. 14:34reasons.
  398. 14:36But, it's significantly more expensive,
  399. 14:37and for almost every project, including
  400. 14:40this course, default tenancy is exactly
  401. 14:42what we need.
  402. 14:44So, I will click on create VPC.
  403. 14:46And that's it. Congratulation, you have
  404. 14:48officially built your first custom AWS
  405. 14:50network. This is not an EC2 instance,
  406. 14:53not an S3 bucket, but an actual private
  407. 14:56cloud network.
  408. 14:58So, let us verify this. Uh you can see I
  409. 15:01do have two VPCs now. AWS default VPC
  410. 15:04and the one we just created. Remember,
  411. 15:07we are going to leave the default VPC
  412. 15:08untouched, and everything we will build
  413. 15:10from now on, subnets, internet gateway,
  414. 15:12route tables, will belong to our new
  415. 15:15custom VPC.
  416. 15:17So now, we own a huge piece of land with
  417. 15:20over 65,000
  418. 15:22possible IP addresses. But obviously, uh
  419. 15:24we are not going to build one giant
  420. 15:26city. Just like real cities are divided
  421. 15:28into neighborhoods, our VPC also needs
  422. 15:30to be divided into smaller sections.
  423. 15:32Those sections are called subnets, and
  424. 15:34that's exactly what we are going to
  425. 15:36build in the next part.
  426. 15:39So, we now have our own custom VPC, but
  427. 15:41right now our VPC is completely empty.
  428. 15:44Think of it as buying a used piece of
  429. 15:46land. You own the land, but there are no
  430. 15:48roads, no buildings, no neighborhoods,
  431. 15:50nothing.
  432. 15:51So, the next logical step is to divide
  433. 15:53this large network into smaller
  434. 15:54sections. In AWS, these smaller sections
  435. 15:57are called subnets.
  436. 15:59Before we create them, let's first
  437. 16:00understand what a subnet actually is.
  438. 16:03Imagine
  439. 16:05this rectangle is our VPC.
  440. 16:08Earlier, what I said was like buying an
  441. 16:10entire city and ask yourself, would a
  442. 16:12real city have this only one huge
  443. 16:14neighborhood?
  444. 16:16Of course not.
  445. 16:17A city is divided into different areas,
  446. 16:20residential area, commercial area,
  447. 16:23industrial area,
  448. 16:24school zone, hospital zone. Exactly the
  449. 16:27same thing happens in AWS. Instead of
  450. 16:29putting every EC2 instances in one giant
  451. 16:32network, we divide the VPC into smaller
  452. 16:34networks.
  453. 16:35Those smaller networks are called
  454. 16:37subnets.
  455. 16:38So, remember this definition. A subnet
  456. 16:40is simply a smaller network inside a
  457. 16:43VPC.
  458. 16:45Now, let's click on subnets.
  459. 16:47You will probably notice something here.
  460. 16:50Uh that is I have already have three
  461. 16:52subnets.
  462. 16:53And this is where many beginners become
  463. 16:54confused. They ask, "Sir, we haven't
  464. 16:56created any subnets yet."
  465. 16:58So, where did these come from?
  466. 17:01Excellent question. Let's look
  467. 17:03carefully. Notice all the three subnets
  468. 17:05belong to the default VPC,
  469. 17:07not our custom VPC.
  470. 17:10AWS automatically creates them. But why
  471. 17:13exactly three? Let's find it out. See,
  472. 17:17every AWS region contains one or more
  473. 17:19availability zones.
  474. 17:21Remember from previous lesson, an AZ is
  475. 17:23an independent data center or more
  476. 17:25accurately one or more closely connected
  477. 17:27data centers.
  478. 17:29The Mumbai region has three AZs, that is
  479. 17:31AP South 1A, AP South 1B, and 1C. So,
  480. 17:35AWS automatically creates one subnet
  481. 17:37inside each availability zones for the
  482. 17:39default VPC.
  483. 17:41That's why we exactly see three default
  484. 17:44subnets.
  485. 17:45If tomorrow, let's say AWS adds one
  486. 17:47another AWS
  487. 17:48availability zones to this region,
  488. 17:50future default VPC may include another
  489. 17:52default subnet as well.
  490. 17:55Another question is, why can't AWS
  491. 17:57create one giant subnet?
  492. 18:00Suppose your entire office building has
  493. 18:02only one room.
  494. 18:03Think about it. Where would the HR sit?
  495. 18:06Where would the finance sit? Where would
  496. 18:08the engineering sit?
  497. 18:11Networking works the same way.
  498. 18:13Different applications usually belong to
  499. 18:14the different subnets. Some need
  500. 18:16internet access, some should never be
  501. 18:18exposed to the internet. Some are
  502. 18:20databases, some are web servers.
  503. 18:23Separating them into different subnet
  504. 18:25makes the network more secure and
  505. 18:27scalable, and it is easier to manage as
  506. 18:29well.
  507. 18:31So, let's examine one of the default
  508. 18:32subnets. You will notice something like
  509. 18:34172.31.0.0/20.
  510. 18:40Another one says 172.31.16.0/20.
  511. 18:46And another
  512. 18:4831.32.0/20.
  513. 18:51So, why are these different?
  514. 18:54Because every subnet must have its own
  515. 18:56unique range of IP addresses.
  516. 18:59Imagine two houses having exactly same
  517. 19:01postal address. The courier would never
  518. 19:03know where to deliver packages.
  519. 19:06The same thing would happen in the
  520. 19:07networking as well. If two subnets share
  521. 19:09the same IP range, AWS wouldn't know
  522. 19:11where the traffic should go.
  523. 19:14That's why every subnet gets its own
  524. 19:16unique CIDR block.
  525. 19:18You will also see various other options
  526. 19:20like it shows 4091 available IP
  527. 19:23addresses.
  528. 19:24And yeah, filtering the subnets. So, let
  529. 19:27us skip these things and first create
  530. 19:30our first subnet.
  531. 19:32I will click on create subnet. And the
  532. 19:34first option ask us to select the VPC.
  533. 19:37Why? Because a subnet cannot exist by
  534. 19:39itself. Every subnet belongs to exactly
  535. 19:42one VPC.
  536. 19:43Uh think of it as this way, you can't
  537. 19:45build a neighborhood without first
  538. 19:47buying the land.
  539. 19:49The VPC is the land and the subnet is
  540. 19:51the neighborhood.
  541. 19:53So, choose my custom VPC.
  542. 19:57The next option ask us to select the
  543. 19:59availability zone. Many beginners wonder
  544. 20:01why I'm choosing an availability zone
  545. 20:03for a subnet.
  546. 20:05Because one subnet can belong to only
  547. 20:07one AZ. It cannot span multiple AZs.
  548. 20:12Think of a city.
  549. 20:14One neighborhood cannot exist in two
  550. 20:15different cities at the same time.
  551. 20:18Similarly, one subnet cannot exist
  552. 20:19inside two AZs.
  553. 20:21If you want resources in another
  554. 20:23availability zone,
  555. 20:25you create another subnet there.
  556. 20:27This design is what gives AWS high
  557. 20:29availability.
  558. 20:31If one AZ experiences a failure, your
  559. 20:33resources in another AZ continue
  560. 20:35running.
  561. 20:37Let's create our first subnet. Let's
  562. 20:38name it public subnet and AZ is AP South
  563. 20:42A1.
  564. 20:44And IPv4 CIDR, let me put 10.0.1.0/24.
  565. 20:52Now, many students immediately ask,
  566. 20:54"Sir, why we are writing 10.0.1.0/24?"
  567. 20:59Let's understand that as well.
  568. 21:01Uh remember earlier our VPC owned this
  569. 21:04entire address range, that is
  570. 21:0610.0.0.0/16.
  571. 21:09We wrote that.
  572. 21:11Now, we are carving out one small piece
  573. 21:13of it. That small piece becomes our
  574. 21:15public subnet.
  575. 21:17The /24 means the subnet contains 256 IP
  576. 21:20addresses. Again, AWS reserves five
  577. 21:23addresses, so approximately 251
  578. 21:25addresses remain usable.
  579. 21:28That's more than enough for our lab.
  580. 21:31Now, let's create another subnet. Let's
  581. 21:32name it private subnet.
  582. 21:36Availability zone, I will select AP
  583. 21:39South 1B, and CIDR block
  584. 21:4310.0.2.0/24.
  585. 21:49Notice something important, the CIDR
  586. 21:51block is different.
  587. 21:52Why is that? Because no two subnets can
  588. 21:56overlap.
  589. 21:57If our first subnet owns 1.0/24,
  590. 22:02then our second subnet must use another
  591. 22:04range. That I'm using 2.0/24.
  592. 22:09Now, AWS exactly knows which IP
  593. 22:11addresses belong to which subnet.
  594. 22:14So, you might have noticed that AWS
  595. 22:16console allows you to create multiple
  596. 22:18subnet in one screen. So, that's simply
  597. 22:21a convenience feature instead of opening
  598. 22:22the create subnet page multiple times,
  599. 22:25AWS lets you define several subnet
  600. 22:28configuration before clicking create.
  601. 22:31Each subnet has its own name, AZ, and
  602. 22:34CIDR block. AWS simply creates all of
  603. 22:36them together.
  604. 22:38So, till now we have created one VPC,
  605. 22:40and inside VPC we have created subnets.
  606. 22:44We have created two subnets, private and
  607. 22:46public.
  608. 22:48But right now, both of these subnets are
  609. 22:50completely isolated. Neither of them has
  610. 22:52internet access.
  611. 22:53Why? Because we have built
  612. 22:55neighborhoods, but we haven't built any
  613. 22:57roads connecting them to the outside
  614. 22:59world.
  615. 23:00And that's what exactly we will do next
  616. 23:02and in this next part we will create our
  617. 23:05own network gateway and understand how
  618. 23:08it actually works behind the scenes and
  619. 23:10connect our VPC to the internet just
  620. 23:11like connecting the city to a national
  621. 23:13highway.
  622. 23:14So let's create one. On the navigation
  623. 23:16menu click on internet gateways.
  624. 23:19Now click on create internet gateway.
  625. 23:23You will notice AWS only ask for one
  626. 23:26thing that is a name tag. Then let's
  627. 23:27call it my
  628. 23:29AWS.
  629. 23:31Now you might wonder why isn't AWS
  630. 23:33asking me to select my VPC? That's
  631. 23:35because we are only creating the
  632. 23:37internet gateway.
  633. 23:38At this stage it exists independently.
  634. 23:41It just It is just like buying a new
  635. 23:43Wi-Fi router. Buying the router doesn't
  636. 23:45automatically connect it to your home
  637. 23:47network.
  638. 23:48You still have to plug it it in.
  639. 23:51Similarly, after creating an internet
  640. 23:53gateway, we still need to attach it to
  641. 23:55VPC.
  642. 23:57Click create internet gateway. Perfect.
  643. 23:59Now our internet gateway exists, but it
  644. 24:02is still isn't connected to anything. So
  645. 24:04I will click on attach to VPC over here.
  646. 24:07Now AWS ask which VPC do you want to
  647. 24:10connect this internet gateway to so? I
  648. 24:11will select my custom VPC that I just
  649. 24:14created now.
  650. 24:15Click attach and done.
  651. 24:18Now our VPC has a connection point to
  652. 24:20the internet.
  653. 24:21But here's something very important.
  654. 24:23Just attaching an internet gateway does
  655. 24:25not give internet access to the EC2
  656. 24:27instances.
  657. 24:29Many beginners think that this step is
  658. 24:31enough. It isn't.
  659. 24:33The internet gateway is available, but
  660. 24:35our subnets don't know yet how to reach
  661. 24:36it. For that we need something called as
  662. 24:39route table.
  663. 24:41So now let's understand what route table
  664. 24:43actually is.
  665. 24:44Think of route table as a Google Maps
  666. 24:46for your network.
  667. 24:48Whenever an EC2 instance sends data, AWS
  668. 24:51checks the route table and ask, "Where
  669. 24:53should I send this packet?"
  670. 24:56And the route table provides the answer.
  671. 25:00It contains a list of routes where each
  672. 25:02route has two parts.
  673. 25:04Destination
  674. 25:06and target.
  675. 25:07The destination tells AWS where the
  676. 25:09traffic wants to go
  677. 25:11and the target tells AWS where to send
  678. 25:13that traffic.
  679. 25:15Without a route table, AWS has no idea
  680. 25:18where the packets should travel.
  681. 25:20On the left menu, you can see route
  682. 25:22tables. Click on that. You will probably
  683. 25:24see several uh route tables. Some belong
  684. 25:26to the default VPC.
  685. 25:29We don't want those. You will find this
  686. 25:31main route table that automatically uh
  687. 25:33AWS has created when we created our VPC.
  688. 25:36Every VPC automatically gets its one
  689. 25:39main route table. We are going to use
  690. 25:41this route table as our public subnet.
  691. 25:44Open the routes table.
  692. 25:46Click edit routes. You will notice there
  693. 25:49is already one route that is destination
  694. 25:5110.0.0.0/16
  695. 25:53target local.
  696. 25:55What does this mean? This route tells
  697. 25:57AWS if the traffic is destined for any
  698. 26:00IP address inside the VPC,
  699. 26:03keep it inside the VPC.
  700. 26:06This route is automatically created by
  701. 26:07AWS. Never delete it. Uh it allows
  702. 26:10resources inside the VPC to communicate
  703. 26:11with each other. Now let's add another
  704. 26:14route that is
  705. 26:16add route.
  706. 26:17For destination, enter 0.0.0.0/
  707. 26:210.
  708. 26:22This is one of the most important values
  709. 26:24in AWS networking. It means every IPv4
  710. 26:27address that isn't inside my VPC
  711. 26:30or simply anywhere on the internet.
  712. 26:32Now for target, choose internet gateway
  713. 26:37and then select
  714. 26:38my AWS
  715. 26:41and click on save.
  716. 26:43So now congratulations, we have just
  717. 26:44told AWS whenever traffic wants to go
  718. 26:47anywhere on the internet, send it to our
  719. 26:50internet gateway.
  720. 26:53But wait, we are still not finished.
  721. 26:54Right now, the route table isn't
  722. 26:56actually being used by our public
  723. 26:57subnet.
  724. 26:59So, let's fix that.
  725. 27:00Stay inside the same route table and
  726. 27:02open the subnet association tab.
  727. 27:05And click on edit subnet associations.
  728. 27:09Select public subnet, click save
  729. 27:11associations, and done.
  730. 27:14Now, our public subnet is using this
  731. 27:16route table.
  732. 27:18This means every EC2 instance launched
  733. 27:20inside this subnet will follow these
  734. 27:22routing rules.
  735. 27:24Now, let's configure the private subnet.
  736. 27:27Go back to the route tables.
  737. 27:29Click create route table.
  738. 27:31Name it private route table.
  739. 27:36Okay, and then choose the VPC, the one
  740. 27:39that we just created.
  741. 27:42Click on create.
  742. 27:45Okay.
  743. 27:46Great. So, open this new route table and
  744. 27:49now go to subnet associations.
  745. 27:54And click on edit subnet associations
  746. 27:56and select
  747. 27:59private subnet.
  748. 28:01And save.
  749. 28:03Now, notice something important. Open
  750. 28:05the routes table and you will see this.
  751. 28:0910.0.0.0/16
  752. 28:12local. That's it. We are not going to
  753. 28:14add another rule.
  754. 28:17Specifically, we are not adding
  755. 28:190.0.0.0/0,
  756. 28:21that is the internet gateway.
  757. 28:23Why? This is supposed to be a private
  758. 28:25subnet. Resources inside a private
  759. 28:27subnet should be able to communicate
  760. 28:29with other resources inside the VPC, but
  761. 28:31they should not be directly reachable
  762. 28:33from the internet.
  763. 28:36By simply not adding an internet route,
  764. 28:38we have completely isolated this subnet
  765. 28:40from the outside world.
  766. 28:42So, yes.
  767. 28:44Uh, what we have done till now? We have
  768. 28:45created custom VPC. We then created
  769. 28:48public subnets and private subnet.
  770. 28:51Then we created and attached an internet
  771. 28:52gateway.
  772. 28:54Then we configured a public route table
  773. 28:56with 0.0.0.0/0.
  774. 28:59That is the internet gateway.
  775. 29:01We associated the public subnet with
  776. 29:03this route table.
  777. 29:05Also, we created a separate private
  778. 29:07route table that contains only the local
  779. 29:08route.
  780. 29:10As a result, an EC2 instance launched in
  781. 29:13the public subnet can communicate with
  782. 29:15the internet.
  783. 29:17Provided it also has a public IPv4
  784. 29:19address and an appropriate security
  785. 29:21group rules.
  786. 29:23Any EC2 instance launched in the private
  787. 29:25subnet can communicate only within the
  788. 29:27VPC and remains isolated from the public
  789. 29:29internet.
  790. 29:30This is the same networking pattern you
  791. 29:32will see in many real AWS architectures,
  792. 29:35and it is an important concept for the
  793. 29:37AWS certified cloud practitioner exam as
  794. 29:39well.
  795. 29:41So, remember this one.
  796. 29:44It is so incredibly satisfying to watch
  797. 29:46this come together.
  798. 29:47Please take time to run through this lab
  799. 29:49in your own console as well.
  800. 29:52Now, let's do a quick rapid-fire recap
  801. 29:54of everything we have covered today.
  802. 29:57So, let's see what connects a public
  803. 29:59subnet to the internet.
  804. 30:01The answer is an internet gateway.
  805. 30:05What lets private instances download
  806. 30:08updates safely?
  807. 30:11A NAT gateway.
  808. 30:14And which firewall is stateful protects
  809. 30:16the instance?
  810. 30:18A security group.
  811. 30:20Correct one.
  812. 30:22Which firewall is stateless and protects
  813. 30:25the subnet?
  814. 30:26That is
  815. 30:27NACL.
  816. 30:30And what gives you a dedicated private
  817. 30:32fiber connection to AWS?
  818. 30:35The answer is
  819. 30:37Direct Connect.
  820. 30:40This was a heavy day.
  821. 30:42So, your homework tonight is critical.
  822. 30:44Jump into the practice portal and knock
  823. 30:46down 20 networking questions.
  824. 30:48And yeah, I guess there will be 10. So,
  825. 30:51knock down any amount of question that
  826. 30:53are in the practice portal today.
  827. 30:55Focus really hard on those scenario
  828. 30:56question that try to trick you between
  829. 30:58the security groups and NACLs.
  830. 31:01Tomorrow on day 13, we are diving into
  831. 31:03databases.
  832. 31:05We will break down RDS, Aurora,
  833. 31:07DynamoDB, Redshift. And it is going to
  834. 31:10be a fantastic session.
  835. 31:13So, that's all for today.
  836. 31:14Keep building.
  837. 31:16Keep learning.
  838. 31:17I will see you tomorrow.

About this transcript

This page contains the full transcript of Amazon VPC Made Easy | Public vs Private Subnets | AWS Builder Challenge Day 12 by Pawan Joshi, generated from the public captions YouTube serves with the video. The transcript has 4,551 words across 838 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.