What is an AWS VPC and a Subnet? Virtual Private Cloud Explained in Five Minutes (Region, Availability Zones, Public vs Private Subnets, Gateways, Route Tables)


Before the full VPC build in Part-5 of the AWS series - which takes an hour and creates fifteen resources - here is the five-minute version that the short video above gives you in 27 seconds: what a VPC is, what a subnet is, and the handful of words around them. If you can explain this page to a colleague, the rest of AWS networking is details.

Table of Content

  1. What is a VPC?
  2. Region, Availability Zone, VPC, subnet - how they nest
  3. What is a subnet?
  4. Public subnet vs private subnet - it is only the route table
  5. The five things around a VPC
  6. The default VPC
  7. Limits worth knowing
  8. Where to go next



1. What is a VPC?

A VPC - Virtual Private Cloud - is your own private network inside an AWS region. The AWS definition: a virtual network dedicated to your AWS account. It is logically isolated from other virtual networks in the AWS Cloud. Think of the region as a city and the VPC as a fenced plot you rent in it. Inside the fence you decide the street numbering (the IP address range, in CIDR notation - 10.0.0.0/16), where the rooms are (subnets), which doors exist to the outside (gateways), who may knock on which door (security groups) and how traffic finds its way (route tables).

Everything with a network interface - EC2 instances, RDS databases, load balancers, Lambda functions in VPC mode, EKS nodes - lives inside a VPC. Nothing else can see into your VPC unless you deliberately connect it (peering, Transit Gateway, PrivateLink, VPN). A VPC is free; you pay only for some of the things you put in it.

A VPC spans a region and is split into subnets, one per Availability Zone, public or private by their route table


2. Region, Availability Zone, VPC, subnet - how they nest

  1. Region - a geographic area (eu-central-1, Frankfurt) with several data-centre groups.
  2. Availability Zone (AZ) - one of those groups (eu-central-1a, 1b, 1c), kilometres apart with independent power and network, so one can fail while the others run.
  3. VPC - belongs to one region and spans all its AZs.
  4. Subnet - a slice of the VPC that lives in exactly one AZ.

So: region ⊃ VPC ⊃ subnet ⊂ AZ. A VPC in Frankfurt cannot have a subnet in Ireland; a subnet in 1a cannot stretch into 1b. That is why every production layout has at least two subnets of each kind, in two AZs - so that losing an AZ does not take the application down.



3. What is a subnet?

A subnet is a range of IP addresses inside the VPC's range, placed in one AZ, into which you launch resources. 10.0.1.0/24 is 256 addresses (251 usable - AWS keeps five) in eu-central-1a. Subnets exist for three reasons -

  1. Placement - choosing a subnet is how you choose the AZ for an instance.
  2. Routing - each subnet is associated with a route table, which decides whether its resources can reach the internet, another VPC, or nothing.
  3. Blast radius and policy - web servers in one subnet, databases in another, with a network ACL per subnet if you want a second firewall layer.

Subnets must not overlap each other and must fit inside the VPC block - the planning is in the CIDR post.


4. Public subnet vs private subnet - it is only the route table

There is no "public" checkbox on a subnet. From the VPC docs: a subnet is public if its route table has a route to an Internet Gateway, private if it does not. In practice -

Public subnetPrivate subnet
Route table0.0.0.0/0 → igw-...0.0.0.0/0 → nat-... (or no default route at all)
Public IP on instancesyes (auto-assign on)no
Reachable from the internetyes, if the security group allowsnever
Can reach the internetyesonly outbound, through the NAT Gateway
What goes hereload balancers, bastion hosts, NAT Gatewaysapplication servers, databases, caches - almost everything

The habit that keeps you safe: put things in private subnets by default and only move something public when a user on the internet must reach it directly - and even then, usually a load balancer rather than the server itself.



5. The five things around a VPC

  1. Internet Gateway (IGW) - the VPC's door to the internet; one per VPC, free, attached once. It also does the one-to-one translation between an instance's private IP and its public IP (what is NAT).
  2. Route tables - lists of "destination → target" rules; every subnet uses one. The local route for the VPC's own range is always there; you add 0.0.0.0/0 to a gateway and specific routes to peers.
  3. NAT Gateway - lets private subnets start connections out (updates, API calls) while nothing can start a connection in. Lives in a public subnet, costs money per hour and per GB (Part-14).
  4. Security groups - stateful firewalls on each instance's network interface; allow rules only; "SSH from my IP, HTTP from the load balancer". Your main firewall.
  5. Network ACLs - stateless allow/deny lists on each subnet; the default allows everything; used for blunt blocks.

Everything else - VPC endpoints, peering, Transit Gateway, VPN, flow logs - is an add-on to this core.


6. The default VPC

Every region in your account comes with a default VPC - 172.31.0.0/16, one public /20 subnet per AZ, an Internet Gateway, and a main route table that sends 0.0.0.0/0 to it. It exists so that "Launch instance" works on day one without you knowing any of this. It is fine for a lab (Part-4 uses it) and wrong for anything real: every subnet is public, and its 172.31.0.0/16 range collides with many office networks when you later want a VPN. If you delete it by accident, Actions → Create default VPC brings it back.


7. Limits worth knowing

From the VPC quotas -

  • 5 VPCs per region by default (adjustable), 200 subnets per VPC, 5 Elastic IPs per region.
  • VPC CIDR between /16 and /28; up to five IPv4 CIDR blocks per VPC (you can add, never shrink or change).
  • One Internet Gateway per VPC; 5 NAT Gateways per AZ.
  • 5 security groups per network interface, 60 rules per group.
  • VPC, subnets, route tables, IGW, security groups and NACLs are free; NAT Gateways, public IPv4 addresses, endpoints and data transfer are not.


8. Where to go next

  1. Understand the address ranges - what is CIDR - and how private subnets reach the internet - what is NAT.
  2. Build the real thing by hand - Part-5: VPC with public and private subnets, Internet Gateway, NAT Gateway and route tables, then test it with an EC2 instance.
  3. Connect VPCs - peering for two, Transit Gateway for many - and reach AWS services privately with VPC endpoints.
  4. Do it as code - the Terraform VPC in the ALB and SSL guide.

The one sentence to remember: a VPC is your isolated network in a region, a subnet is a slice of it in one AZ, and whether a subnet is public or private is decided only by its route table. The official overview is what is Amazon VPC.


More videos on this topic - two one-minute shorts - how to create a VPC and a subnet, and what Availability Zones are -



AWS step by step series -

  1. Part-1 : AWS IAM user - create a user, group, policy, access keys and MFA
  2. Part-2 : AWS Organizations - multi-account setup, OUs and SCPs
  3. Part-3 : AWS assume IAM role - trust policy, switch role in console and CLI
  4. Part-4 : How to launch an EC2 instance - key pair, security group, SSH
  5. Part-5 : AWS VPC - public and private subnets, Internet Gateway, NAT Gateway, route tables
  6. Part-8 : EC2 launch template - versions, default version, source template, SSM parameter AMI
  7. Part-10 : EC2 Auto Scaling - launch template, Auto Scaling group, target tracking, ALB
  8. Part-11 : AWS WAF - web ACL, managed rules, rate limiting, geo blocking
  9. Part-12 : AWS VPC Peering - connect two VPCs, routes, security groups, DNS
  10. Part-13 : AWS Transit Gateway - hub-and-spoke for many VPCs and on-premises
  11. Part-14 : AWS NAT Gateway deep dive - public vs private, limits, cost, troubleshooting
  12. Part-15 : Amazon Route 53 - hosted zones, records, alias, routing policies, health checks
  13. Part-16 : AWS security groups - inbound and outbound rules, stateful, referencing, quotas
  14. Part-16 : AWS Certificate Manager - free TLS certificates for ALB, CloudFront and API Gateway
  15. Part-17 : AWS Lambda - function URLs, environment variables and layers
  16. Part-18 : Network Load Balancer - setup, and ALB vs NLB
  17. Part-19 : VPC endpoints - gateway and interface endpoints (PrivateLink) instead of NAT
  18. Part-20 : AWS PrivateLink - publish your own service with an endpoint service and NLB
  19. Part-20 : Amazon EBS volumes - types, attach, mount, resize, snapshots, encryption
  20. Part-21 : VPC Flow Logs - CloudWatch Logs, S3, record format, Logs Insights, Athena
  21. Part-21 : EC2 Spot Instances - pricing, interruptions, mixed instances groups
  22. Part-24 : AWS Control Tower - landing zone, controls, Account Factory, Identity Center

Networking fundamentals -

  1. What is a VPC and a subnet? AWS networking in five minutes
  2. What is CIDR? Calculate IP ranges for VPCs and subnets
  3. What is NAT? Static NAT, dynamic NAT and PAT explained

More AWS guides -

  1. What is AWS CloudFormation? Templates, stacks, change sets, drift, StackSets
  2. Learn AWS S3 - the complete course
  3. AWS API Gateway - REST API with Lambda, authorizers, Terraform
  4. AWS Advanced Networking Specialty (ANS-C01) - course companion
  5. AWS ECS and Fargate - how to deploy a Docker container
  6. AWS S3 - how to host a static website
  7. Terraform create EC2 instance on AWS
  8. Terraform AWS IAM - users, roles and policies
  9. Terraform and AWS multi-account setup
  10. Terraform - setting up an ALB and SSL

Posts in this series