Networking
Part 2 of 6 · Private NetworkingVPC Fundamentals — Subnets, Route Tables, Security Groups & NACLs
Public versus private is a route, not a checkbox. A public subnet sends 0.0.0.0/0 to an internet gateway. Security groups are stateful ENI allow lists. NACLs are stateless subnet filters. Plan non-overlapping CIDRs before you peer.
- 1Gist
- 2Maps
- 3Q&A
- 4Sandbox
Voice readout needs Web Speech Synthesis in this browser.
Security group vs network ACL
Prefer
Security groups for application policy
Stateful allow lists on the ENI. Return traffic is tracked. Prefer SG-to-SG references over wide CIDRs for east-west inside the VPC.
- Allow-only. The union of attached groups applies.
- Return traffic does not need a matching egress rule for the reply.
- Attach the smallest set of groups that name the peer.
Alternative
NACLs as the day-to-day ACL
Stateless subnet filters evaluate numbered rules first-match. You must allow the request and the ephemeral return ports. Easy to blackhole a healthy security group.
- Allow and deny, subnet scope.
- Use them for quarantine or org-wide blocked ports.
- Do not encode app policy here.
Overview
CIDR planning and SG versus NACL show up in almost every AWS networking interview. Public versus private is not a checkbox. It is whether the subnet route table sends 0.0.0.0/0 to an internet gateway (public) or to NAT, a transit gateway, or nowhere (private).
You should be able to:
- Draw packet in, NACL in, security group, process, stateful return, NACL out.
- Reject overlapping
10.0.0.0/16peers before the peering request. - Place gateway and interface endpoints on the right services.
Core concepts
- VPC CIDR — often
/16through/20. Leave room for growth and secondary CIDRs. - Subnets — AZ-scoped. Size for pods and ENIs. EKS often wants larger private
/20s, not a/28. - Route tables — one association per subnet. The implicit local route covers the VPC CIDR. Add a default only when you mean it.
- Internet gateway — horizontally scaled. Attachment makes a public path possible. It does not grant access by itself.
- Security group — stateful allow-list on the ENI. Return traffic is automatic.
- NACL — stateless subnet filter. Must allow ephemeral return ports.
- VPC endpoints — gateway (S3, DynamoDB, no ENI) versus interface (PrivateLink ENI, private DNS, paid).
- PrivateLink — provider exposes an NLB plus an endpoint service. Consumer creates an interface endpoint. Prefer this over a mesh of non-transitive peerings when you only need one service.
Packet path
NACL inbound runs at the subnet boundary before the instance. The security group filters the ENI. The reply is allowed by SG state, then must still pass the NACL outbound rule, including ephemeral ports.
Flow
- 1
1 Packet
- next2 NACL inbound
- 2
2 NACL inbound
- next3 Security group
- 3
3 Security group
- next4 Process
- 4
4 Process
- next5 SG stateful return
- 5
5 SG stateful return
- next6 NACL ephemeral out
- 6
6 NACL ephemeral out
Lesson map
VPC Fundamentals — Subnets, Route Tables, Security Groups & NACLs
Public versus private is a route, not a checkbox. A public subnet sends 0.0.0.0/0 to an internet gateway. Security groups are stateful ENI allow lists. NACLs are stateless subnet filters. Plan non-overlapping CIDRs before you peer.
Architecture. Architecture
Select a node to see why it exists, or an edge to see the protocol, direction, effect, and consequence.
Mermaid export
flowchart TB a["VPC-A"] p["Peering"] b["VPC-B"] a -->|Peer request| p p -->|Reject or| b
Overlapping CIDRs
Two VPCs that both claim 10.0.0.0/16 cannot peer cleanly. The request is rejected or the route blackholes. Fix non-overlapping RFC 1918 ranges per environment, including on-premises, before you connect them.
Sequence
- 1
VPC-A
Overlap 10.0.0.0/16
- 2
VPC-A → Peering
Peer request
- 3
Peering → VPC-B
Reject or blackhole
- 4
VPC-A
Use distinct RFC1918
Gateway vs interface endpoints
- Gateway: route-table target for S3 and DynamoDB. No ENI. Usually the cheap data-plane choice.
- Interface (PrivateLink): ENI and security group per AZ, private DNS, hourly and data charges.
- Use a gateway endpoint for the S3 data plane. Use interface endpoints for ECR, Secrets Manager, SSM, and KMS when you do not want that traffic on NAT.
PrivateLink interview angle: the consumer creates an interface endpoint. The provider exposes an NLB and an endpoint service. Private DNS can overwrite the public hostname to the private ENI. Peering is not transitive. A mesh of peerings grows faster than a service-scoped endpoint. This is network coupling, not a service mesh. East-west proxy policy stays in the sidecar cluster.
Shared design checklist
- Non-overlapping CIDRs across prod, stage, dev, and on-premises.
- Small public
/24subnets, three AZs, for load balancers and NAT. Larger private subnets for compute. - Separate data-tier subnets with tighter security groups.
- VPC Flow Logs to S3 for forensics.
- Tag-based SG automation. Avoid
0.0.0.0/0ingress except the load balancer. - Prefer SG ID references over CIDRs for east-west.
Sandbox: overlap check (Python)
Press Run. Snippets must be self-contained — no network, files, or native modules.
Sandbox: distinct /16 bases (TypeScript)
Demo only. It accepts /16 networks and treats the first two octets as the identity. Use the Python planner for real masks.
Press Run. Snippets must be self-contained — no network, files, or native modules.
GCP and Azure
GCP uses a global VPC, regional subnets, and stateful firewall rules. Azure uses a VNet, NSGs, and Private Link or service endpoints. The interview move is the same: name the address plan, the route, and the stateful filter before the product name.
Pitfalls
Sketch public /24 and private /20 per AZ. Write the default route for each. Add an S3 gateway endpoint on the private route tables. Say which NACL rule you would add only for a quarantine, not for the app.
Interview Q&A
Why are subnets AZ-scoped?
Answer
AWS maps a subnet to one Availability Zone. Multi-AZ HA needs at least one private subnet per AZ, and often a public subnet per AZ for NAT and load balancers.
Why reference another security group instead of a CIDR?
Answer
The peer moves when instances scale. An SG ID still names the role. A CIDR allows every address in the range, including ones you did not mean.
What is the local route?
Answer
An implicit route from the VPC CIDR to local. It is always present. You do not send intra-VPC traffic to an internet gateway.
When do NACLs help?
Answer
Quarantine and org-wide blocked ports. Not day-to-day application ACLs. Return traffic and ephemeral ports must be explicit because NACLs are stateless.
What makes a subnet public?
Answer
Its route table sends the default route to an internet gateway. The workload still needs a public address and a security group that allows the flow.
Gateway endpoint or interface endpoint?
Answer
Gateway for S3 and DynamoDB route targets. Interface when you need a PrivateLink ENI, private DNS, and a security group, such as SSM or ECR.
Why PrivateLink instead of peering everything?
Answer
Peering is not transitive and couples whole CIDRs. PrivateLink exposes one provider service through an NLB to consumers in other accounts or VPCs. You still need authz.
What happens if two VPCs share 10.0.0.0/16?
Answer
Peering is rejected or routes blackhole. Renumber to non-overlapping RFC 1918 ranges per environment.
How big should private subnets be?
Answer
Large enough for ENIs and pods. A /28 fails EKS. Many designs use a small public subnet per AZ and a much larger private subnet.
Does an internet gateway attachment publish every instance?
Answer
No. You still need a route, a public address, and filters. Attachment only makes a public path possible.
Where do flow logs fit?
Answer
VPC Flow Logs to S3 are for forensics after a deny or an unexpected accept. They do not replace security groups.
How does this page relate to NAT and SSM?
Answer
This page is the address plan and the filters. NAT placement and cost are the next lesson. SSM fails closed if private subnets have neither NAT nor interface endpoints.