AWS Networking

An experienced DevOps Engineer understands the integration of operations and development in order to deliver code to customers quickly. Has Cloud and monitoring process experience, as well as DevOps development in Windows, Mac, and Linux systems.
AWS Networking provides the foundation for building secure, scalable, and high-performing cloud architectures. By understanding the essential components of AWS Networking, you can efficiently design and manage your resources to meet application requirements while ensuring security and compliance.
This blog explores key AWS Networking components, including Virtual Private Cloud (VPC), subnets, security mechanisms, and advanced connectivity options.
1. Networking Basics
In AWS networking, understanding IP addressing and CIDR (Classless Inter-Domain Routing) is crucial for designing scalable and efficient virtual networks like VPCs (Virtual Private Clouds). Below are detailed explanations, along with examples:
Types of IP Addresses
Public IP Address:
Routable on the internet.
Assigned to resources like EC2 instances for external communication.
Examples:
203.0.113.25,198.51.100.14.
Private IP Address:
Used for internal communication within the VPC.
Not routable on the internet.
Examples (RFC 1918 ranges):
10.0.0.0 - 10.255.255.255172.16.0.0 - 172.31.255.255192.168.0.0 - 192.168.255.255
- Elastic IP Address:
- Static, public IPv4 address you can allocate and attach to an instance.
What is CIDR?
CIDR (Classless Inter-Domain Routing) defines IP ranges using a prefix and mask format:
IP Address/PrefixLength
The IP Address indicates the network.
The PrefixLength specifies the number of bits representing the network part.
Example:
10.0.0.0/24:10.0.0.0is the network address./24means the first 24 bits are reserved for the network.The remaining 8 bits are for hosts, allowing 2⁸ = 256 addresses.
Below are some public sites where you can calculate IPs for CIDR
https://www.ipaddressguide.com/cidr
https://mxtoolbox.com/subnetcalculator.aspx
2. Virtual Private Cloud (VPC)
A Virtual Private Cloud (VPC) is a logically isolated section of AWS where you can launch resources in a customized network. Key features include:
Define IP address ranges using CIDR (e.g., 10.0.0.0/16).
Create isolated environments for applications and data.
Customize subnets, route tables, and gateways.
The following diagram shows an example VPC. The VPC has one subnet in each of the Availability Zones in the Region, EC2 instances in each subnet, and an internet gateway to allow communication between the resources in your VPC and the internet.
Benefits:
Full control over your network.
Enhanced security with private and public subnets.
Integration with other AWS services.
3. Subnets (Public and Private)
A VPC is divided into smaller subnets, which determine resource accessibility. Each subnet must reside entirely within one Availability Zone and cannot span zones.
Public subnet — The subnet has a direct route to an internet gateway. Resources in a public subnet can access the public internet.
Private subnet — The subnet does not have a direct route to an internet gateway. Resources in a private subnet require a NAT device to access the public internet.
Design Tips:
Place application servers in private subnets for enhanced security.
Use public subnets for load balancers or NAT gateways.
4. Route Tables
Route tables define how traffic is routed within a VPC. Each VPC has a main route table by default, and you can create additional custom route tables.
Local Routes: Allow communication within the VPC.
Custom Routes: Direct traffic to external destinations, such as the internet or another VPC.
A Route Table in AWS is like a map that directs network traffic within your VPC or to external networks.
- Purpose: Determines where data should go based on the destination IP address.
How it Works:
Each subnet is associated with a route table.
The route table contains rules (routes) for traffic, such as:
Send traffic to the internet via an Internet Gateway.
Send traffic to another VPC via a Peering Connection.
The following example route table has a static route to an internet gateway and a propagated route to a virtual private gateway. Both routes have a destination of 172.31.0.0/24. Because a static route to an internet gateway takes priority, all traffic destined for 172.31.0.0/24 is routed to the internet gateway.
5. Default VPC
AWS provides a default VPC for each region, simplifying initial setups. It includes:
When we create a default VPC, we do the following to set it up for you:
Create a VPC with a size
/16IPv4 CIDR block (172.31.0.0/16). This provides up to 65,536 private IPv4 addresses.Create a size
/20default subnet in each Availability Zone. This provides up to 4,096 addresses per subnet, a few of which are reserved for our use.Create an internet gateway and connect it to your default VPC.
Add a route to the main route table that points all traffic (
0.0.0.0/0) to the internet gateway.Create a default security group and associate it with your default VPC.
Create a default network access control list (ACL) and associate it with your default VPC.
Associate the default DHCP options set for your AWS account with your default VPC.
6. Internet Gateway (IGW)
An Internet Gateway (IGW) allows resources in a VPC to access the Internet. It:
Enables inbound and outbound internet traffic for public subnets.
Is highly available and scalable.
Usage:
- Attach an IGW to your VPC and associate it with a public subnet’s route table.
7. NAT Gateway
You can use a NAT device to allow resources in private subnets to connect to the internet,
These instances can communicate with services outside the VPC, but they cannot receive unsolicited connection requests.
For example, the following diagram shows a NAT device in a public subnet that allows the EC2 instances in a private subnet to connect to the internet through an internet gateway.
The NAT device replaces the source IPv4 address of the instances with the address of the NAT device.
When sending response traffic to the instances, the NAT device translates the addresses back to the original source IPv4 addresses.
8. VPC Endpoints
An AWS Endpoint is a network interface that allows communication between your VPC (Virtual Private Cloud) and other AWS services without requiring access over the public internet. AWS endpoints provide secure and private connectivity to services in AWS, enhancing security by eliminating the need to route traffic over the internet.
Endpoints are particularly useful in private networks where you want to restrict internet access while allowing your resources to access AWS services securely.
There are two main types of AWS Endpoints:
- Interface Endpoints (powered by AWS PrivateLink)
Gateway Endpoints
1. Interface Endpoints (AWS PrivateLink)
Interface Endpoints are powered by AWS PrivateLink, which provides private connectivity to supported AWS services using elastic network interfaces (ENIs) with private IP addresses in your VPC.
2. Gateway Endpoints
A Gateway Endpoint provides private access to Amazon S3 and DynamoDB directly from your VPC. It routes traffic for these services to the AWS network, bypassing the internet.
Supports Only Specific Services: Currently, gateway endpoints are supported for Amazon S3 and Amazon DynamoDB.
Benefits:
Enhanced security by avoiding internet exposure.
Reduced latency and data transfer costs.
9. Elastic IP Address (EIP)
An Elastic IP Address (EIP) is a static IPv4 address used for:
Ensuring a consistent public address for your instances.
Mapping addresses between different resources during failover.
10. Network Access Control Lists (NACLs)
A network access control list (ACL) allows or denies specific inbound or outbound traffic at the subnet level.
You can use the default network ACL for your VPC, or you can create a custom network ACL for your VPC with rules that are similar to the rules for your security groups to add layer of security to your VPC.
Your VPC automatically comes with a modifiable default network ACL. By default, it allows all inbound and outbound IPv4 traffic and, if applicable, IPv6 traffic.
You can associate a network ACL with multiple subnets.
However, a subnet can be associated with only one network ACL at a time. When you associate a network ACL with a subnet, the previous association is removed.
Best Practices:
Use NACLs for broad subnet-level protection.
Combine with Security Groups for layered security.
11. Security Groups
An AWS Security Group is a virtual firewall that controls inbound and outbound traffic to AWS resources such as EC2 instances within an Amazon Virtual Private Cloud (VPC).
Stateful: Automatically allows return traffic for requests initiated within the group.
Instance-Level Security: Applied to individual EC2 instances or ENIs in a VPC.
Allow Rules Only: Security groups can only allow traffic; they cannot explicitly deny traffic for both inbound and outbound traffic.
Multiple Security Groups: An instance can be associated with multiple security groups.
Default Security Group: Every VPC has a default security group with predefined inbound and outbound rules.
Recommendations:
Use Security Groups for instance-specific traffic control.
Keep rules minimal for tighter security.
12. VPC Peering
A VPC peering connection is a networking connection between two VPCs that enables you to route traffic between them using private IPv4 addresses or IPv6 addresses.
Instances in either VPC can communicate with each other as if they are within the same network. You can create a VPC peering connection between your own VPCs, or with a VPC in another AWS account.
The VPCs can be in different Regions (also known as an inter-region VPC peering connection).
To enable private IPv4 traffic between instances in peered VPCs, you must add a route to the route tables associated with the subnets for both instances.
VPC Peering
Route Table — VPC Peering
Use Cases:
Interconnect applications in separate VPCs.
Share resources between accounts.
13. Transit Gateway
AWS Transit Gateway is a highly scalable and fully managed service that simplifies the connectivity between your Virtual Private Clouds (VPCs), on-premises networks, and other AWS services. It acts as a central hub for managing network connectivity, reducing the complexity of peer-to-peer connections and allowing you to manage large-scale network topologies efficiently.
Transit Gateway
Features:
Support for thousands of connections.
Integrated with Direct Connect and VPN.
Use Case:
- Centralized network management in multi-VPC architectures.
14. Virtual Private Network (VPN)
AWS Virtual Private Network (AWS VPN) is a managed service that allows you to securely connect your on-premises networks or client devices to your AWS environment over an encrypted connection.
You can enable access to your remote network from your VPC by creating an AWS Site-to-Site VPN (Site-to-Site VPN) connection, and configuring routing to pass traffic through the connection.
Benefits:
Securely extend on-premises resources to the cloud.
Cost-effective compared to leased lines.
15. AWS Direct Connect
AWS Direct Connect is a dedicated network service that provides a private and secure connection between your on-premises data center, office, or colocation environment and AWS.
Unlike a VPN, which uses the public internet, Direct Connect establishes a dedicated physical connection, offering more consistent network performance, lower latency, and higher bandwidth.
Advantages:
High bandwidth and low latency.
Avoids internet congestion.
Use Case:
- Reliable connection for hybrid architectures.
Conclusion
AWS Networking is a cornerstone for building robust, scalable, and secure applications in the cloud. By mastering these components, you can design optimized networks tailored to your business needs. Start with basic concepts like VPCs and subnets, then explore advanced options like Transit Gateway and Direct Connect for complex setups. With AWS Networking, the possibilities are limitless!



