A Practical Tour of AWS Networking: VPCs, Subnets, Gateways, and More

A Practical Tour of AWS Networking: VPCs, Subnets, Gateways, and More

If you're new to AWS, networking is one of the first --- and most confusing --- topics you'll run into. There are subnets, gateways, route tables, security groups, NACLs... and it's not always obvious how they fit together. This article walks through the core building blocks of AWS networking, piece by piece, so you can build a clear mental model of how traffic actually flows in and out of your cloud environment.

The Foundation: VPC (Virtual Private Cloud)

Think of a VPC as your own private data center in the cloud. It's an isolated network environment where you control the IP address ranges, subnets, route tables, and gateways.

A few key things to know about VPCs:

  • Connections into a VPC can be secured using VPN protocols.
  • Within a VPC, you create subnets, which can be designated as public or private.
  • Multiple VPCs can talk to each other through VPC peering.

Everything else in this article --- subnets, gateways, NAT, security groups --- exists inside or around a VPC.

Subnets: Public vs. Private

A VPC is carved up into subnets, and each subnet falls into one of two categories:

  • Public Subnets (DMZ) --- reachable from the internet
  • Private Subnets --- isolated from direct internet access

Whether a subnet is "public" or "private" isn't an inherent property --- it's determined by its route table (more on that below). A subnet is public specifically because its route table sends internet-bound traffic to an Internet Gateway.

VPC Endpoints: Reaching AWS Services Without the Internet

Normally, if a resource inside your VPC wants to talk to a service like S3 or Lambda, that traffic would need to leave your VPC. VPC Endpoints let you connect directly to AWS services without routing traffic over the public internet --- keeping traffic inside the AWS network and reducing exposure.

Security Groups: Instance-Level Firewalls

Security Groups are one of the most commonly used --- and misunderstood --- controls in AWS networking. A few important clarifications:

  • Security groups are not for user or IAM management --- that's a separate concern entirely.
  • They work like a firewall attached to an EC2 instance.
  • They only support allow rules --- anything not explicitly allowed is implicitly denied.
  • Rules can be defined separately for inbound (ingress) and outbound (egress) traffic.
  • Security groups apply at the instance level, not the subnet level.

That last point matters: two instances in the same subnet can have completely different security group rules.

Network ACLs (NACLs): Subnet-Level Firewalls

While security groups protect instances, Network Access Control Lists (NACLs) protect subnets. Key differences from security groups:

  • Applied at the subnet level, not the instance level.
  • Support both allow and deny rules.
  • Rules are evaluated in order --- first match wins.

Because NACLs operate at a different layer than security groups, they're often used together: NACLs as a coarse-grained subnet perimeter, and security groups as fine-grained, per-instance rules.

Route Tables: The Traffic Director

A Route Table defines the rules AWS uses to decide where network traffic gets sent. Each route table is associated with a VPC and specific subnets within it.

In a typical setup, you'll see at least two entries:

  1. A local route that routes traffic within the VPC.
  2. A route for internet access, typically pointing to an Internet Gateway (for public subnets) or a NAT device (for private subnets).

NAT: Letting Private Resources Reach the Internet

Private subnets, by definition, aren't directly reachable from the internet --- but their instances often still need outbound access (think yum update, hitting an external database, wget calls, OS patching). That's where Network Address Translation (NAT) comes in.

  • NAT interconnects private and public networks.
  • An Elastic IP is attached to the NAT device on its public-facing side.
  • It's strictly one-way: instances in a private subnet can reach the internet through NAT, but the internet cannot initiate connections back into your private resources through it.
  • NAT can be implemented as a self-managed NAT instance or as a managed AWS NAT Gateway.
  • NAT gateways operate within a single Availability Zone, so for high availability you'll want one per AZ.

Here's how the traffic flow looks in practice:

Internet Gateway: The Front Door

An Internet Gateway (IGW) is the logical connection between a VPC and the public internet. A few things worth remembering:

  • It's a logical construct, not a physical appliance.
  • Without an IGW, nothing in your VPC is reachable from the internet (unless traffic arrives via a corporate network, VPN, or Direct Connect).
  • An IGW enables traffic in both directions --- but only if a route table entry points the subnet at it.
  • This is exactly what makes a subnet "public": a route table entry sending traffic to the IGW.

To see how NAT and IGW relate to each other architecturally:

VPN Connections: Bridging to On-Premises

When you need a secure connection between your AWS VPC and an on-premises network, AWS provides VPN gateways for exactly that:

  • AWS supports gateways that connect a VPC to local, on-premises networks.
  • These gateways are, effectively, VPN endpoints.
  • The Virtual Private Gateway (VPG) lives on the AWS side, in the cloud.
  • The Customer Gateway (CGW) lives on the customer's side, in their own network.

Transit Gateway: Simplifying Complex Network Topologies

As your AWS footprint grows --- more VPCs, more accounts, more VPN connections --- managing point-to-point connections between everything becomes unwieldy. Transit Gateway solves this by acting as a central hub:

  • Centralizes regional network management.
  • Connects to multiple VPCs at once.
  • Can be peered across multiple AWS accounts.
  • Supports multiple VPN connections simultaneously.
  • Supports multiple AWS Direct Connect gateways simultaneously.

Putting It All Together

Once you understand each piece individually, they combine into a coherent architecture: VPCs contain public and private subnets, route tables direct traffic to IGWs or NAT gateways depending on subnet type, security groups and NACLs layer defense at the instance and subnet level, and Transit Gateway or VPN connections extend the network beyond a single VPC.

Here's what a typical AWS VPC network architecture looks like when all of these components come together:

Wrapping Up

AWS networking can feel overwhelming at first because so many components interact: VPCs, subnets, route tables, gateways, NAT, security groups, and NACLs. But once you see how each piece routes or filters traffic --- and how they layer together --- the whole picture becomes much clearer. Start with the VPC as your container, understand how route tables decide where traffic goes, and layer security controls (NACLs at the subnet level, security groups at the instance level) on top. From there, the rest --- NAT, IGW, VPN, Transit Gateway --- are just different ways of extending that network to the outside world.

相关推荐
数据知道18 小时前
网络地址转换(NAT)与安全:映射原理、打洞与内网暴露风险
网络·安全·智能路由器·内网安全
KaMeidebaby19 小时前
卡梅德生物技术快报|原核膜蛋白表达优化实操手册,膜蛋白的纯化梯度洗脱完整流程
前端·网络·数据库·人工智能·算法
一只小菜鸡..20 小时前
Stanford CS144 学习笔记 (七):跨越虚实的边界——物理层、链路层与无线网络
网络·笔记·学习
且随疾风前行.20 小时前
Android Binder 驱动 - 内核驱动层源码初探
android·网络·binder
寒晓星20 小时前
【网络编程】UDP编程
linux·网络·网络协议·udp
逑之20 小时前
HTTP、HTTPS2
网络·网络协议·http
斌蔚司李21 小时前
Tp-link手动设置有线中继模式(图文版)
网络·智能路由器
运维大师1 天前
【K8S 运维实战】03-网络模型实战CNI
运维·网络·kubernetes
数智化管理手记1 天前
全面预算管理执行偏差大?全面预算管理全流程落地步骤是什么
大数据·网络·数据库·人工智能·数据挖掘