certslothcertsloth
ANS-C01/Topic 01

AWS / Specialty

Networking: VPC

7 min read5 recall promptsReviewed 2026-10-10

Memory hook: A working connection needs the right address, a forward route, permission and a return path.

Must remember

Addresses and routes come first

  • A VPC is a regional network boundary; a subnet occupies one AZ. Plan nonoverlapping CIDRs before connecting VPCs and on-premises networks. AWS reserves five IPv4 addresses in an ordinary subnet, so a /24 supplies 251 usable IPv4 addresses. Default-VPC conveniences should not be assumed in a custom VPC.
  • A route table selects the most specific matching destination route. A subnet is called public when it has an internet-gateway route, but an IPv4 instance also needs usable public addressing and suitable security rules. A public IP without the route, or the route without the public IP, is insufficient.
  • An internet gateway (IGW) supports the VPC's internet path. A bastion is a deliberate administrative hop; Session Manager can avoid inbound SSH by using the managed agent's outbound service connectivity and IAM permissions.
  • Private addressing does not itself guarantee isolation from every network. Check all routes: peering, transit, VPN and service endpoints may create intentional private connectivity.

Stateful and stateless filters

  • Security groups use stateful allow rules on interfaces/resources. Return traffic for an allowed connection is tracked; there is no explicit SG deny rule. Referencing another SG is useful for tier-to-tier access without maintaining individual IP lists.
  • NACLs apply ordered stateless allow/deny rules at subnet boundaries. Both directions need appropriate rules; HTTPS responses often need outbound ephemeral ports. Lower-numbered matching rules determine the decision, so an earlier deny can defeat a later allow.
  • A permitted filter cannot compensate for a missing route, and a correct route cannot override a denying filter. Trace the actual source/destination seen at each network hop.

Egress and service endpoints

  • NAT instances require operating-system management, routing, security rules and appropriate source/destination-check changes. NAT gateways reduce appliance management; time, processing and associated address charges still matter. NAT permits outbound-initiated connectivity, not unsolicited inbound sessions.
  • The traditional zonal public NAT gateway sits in a public subnet; same-AZ routing with one per required AZ avoids a single-AZ egress dependency. Current AWS also offers regional NAT gateways, which can automatically expand across AZs and do not require a hosting public subnet. Know which mode a question describes; regional mode currently does not provide private NAT. A single regional resource is not a promise of one-AZ pricing.
  • Gateway endpoints for S3 and DynamoDB add route-table targets without an endpoint-hour fee. They are not general transit access for clients in peered VPCs or on-premises networks.
  • Interface endpoints and AWS PrivateLink provide private access to supported services through endpoint networking and DNS, typically using private ENIs and SGs for interface endpoints. They can expose a particular service instead of granting full VPC-to-VPC routing. Hourly/per-AZ and data charges require comparison against the actual traffic pattern.
  • Endpoint policies, where supported, limit use through that endpoint. They do not override missing IAM permissions or a denying bucket/resource policy. Network reachability and API authorization are separate checks.

Connect networks and resolve names

  • VPC peering connects compatible nonoverlapping networks with explicit routes; it is not transitive. A–B and B–C do not establish an A–C path through B. Transit Gateway supplies a routed hub for many VPCs and on-premises connections; attachment and route-table configuration still control permitted paths.
  • Site-to-Site VPN connects networks using encrypted tunnels over IP connectivity. VPN CloudHub supports compatible hub-and-spoke VPN site communication. Client VPN supplies remote-user access, with authentication, authorization and routes; it is not the same workload as linking two corporate networks.
  • Direct Connect provides dedicated connectivity and more predictable network characteristics, with physical provisioning considerations. It is not encrypted by default. Use appropriate application TLS, supported MACsec or VPN designs when encryption is required. Direct Connect Gateway connects eligible virtual-interface designs to multiple VPCs/Regions; it is not an automatic transitive VPC router.
  • Route 53 Resolver inbound endpoints let external networks query supported AWS DNS namespaces. Outbound endpoints and forwarding rules send matching VPC queries toward external DNS. Direction follows the query, and DNS resolution still needs underlying network reachability. See DNS notes.

IPv6, observation and cost

  • Amazon-provided public IPv6 addresses are globally routable; routing and filters control reachability. An egress-only IGW permits outbound-initiated internet flows for public IPv6 addresses. Reaching IPv4-only destinations from IPv6 is a separate translation requirement.
  • AWS also supports private IPv6 through IPAM, including ULA and private GUA ranges. IGWs and egress-only IGWs drop these private ranges; internet access requires a suitable intermediary with public addressing. “Outbound-only” and “private IPv6 address” are different properties.
  • Flow logs summarize supported IP flows, including accepted/rejected traffic, rather than packet payloads. Delivering to S3 and querying with Athena supports analysis. Traffic mirroring copies supported packet traffic for inspection; Network Firewall provides managed network filtering/inspection. WAF specializes in supported HTTP request paths.
  • Add the whole path's cost: public IPv4, NAT processing, cross-AZ/Region transfer, endpoints, load balancers and inspection. Service quotas, subnet address capacity and standby-region limits can prevent scale-out even when an architecture diagram looks sound.

Choose under exam pressure

Clue in the requirement Choose or investigate
Private VPC workloads only need same-Region S3 Gateway endpoint and suitable policies
Expose one supported private service to another account PrivateLink rather than broad routed connectivity
Many VPCs need transitive routing Transit Gateway
Remote employees need authenticated private access Client VPN
On-premises DNS must query private AWS names Resolver inbound endpoint plus connectivity
VPC clients need corporate DNS zones Resolver outbound endpoint and rules
Outbound-only internet access using public IPv6 addresses Egress-only IGW
Inspect actual packet content Suitable mirroring/inspection design

Traps

  • A subnet name, SG rule or public IP alone does not establish a complete path.
  • A gateway endpoint is not a replacement for all interface endpoints or for hybrid connectivity.
  • Older “all NAT gateways are zonal” shorthand is incomplete. Preserve the availability mode and routing assumptions in the question.

Active recall

1. An EC2 instance has a default IGW route but only a private IPv4 address. Why does ordinary internet access fail?

The direct IPv4 IGW path requires suitable public addressing. Provide the appropriate public address or a private-egress/NAT design, or use a service endpoint if only that service is needed; the route alone is insufficient.

2. HTTPS enters a subnet but responses are dropped by its NACL. What differs from SG behavior?

NACLs are stateless and require a matching outbound allowance for the response's ephemeral destination ports. SG connection tracking does not supply the missing NACL rule.

3. A partner needs one private API, not access to all VPC networks. Why consider PrivateLink instead of peering?

PrivateLink can expose the supported service boundary without creating broad routed network connectivity. Evaluate endpoint/service configuration, authorization and DNS rather than assuming private access grants all application permissions.

4. On-premises clients can reach AWS addresses but cannot resolve a private hosted-zone name. Which DNS direction is relevant?

An inbound Resolver endpoint provides the query path into AWS DNS, with suitable forwarding on the on-premises resolver. An outbound endpoint handles the opposite query direction and would not by itself solve this case.

5. A design uses one zonal NAT gateway for private workloads in two AZs. What tradeoff should be identified?

It introduces a dependency on the NAT's AZ and potentially cross-AZ transfer charges. Compare per-AZ zonal gateways or an appropriate regional NAT design, including real pricing and supported connectivity requirements.

Terraform anchor: CIDR functions and preconditions check address assumptions; independent route, policy and return-path checks establish whether the intended connection works.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.