Route Table
A set of rules inside a VPC directing where network traffic goes based on destination IP. Every subnet must associate with one route table. Public subnets route to the Internet Gateway, private subnets route to NAT Gateway.
What is a Route Table
A Route Table is a list of routing rules. When a packet leaves a subnet, the route table decides where it goes based on the destination IP address.
Public Subnet Route Table:Destination Target10.0.0.0/16 local ← any IP in the VPC stays inside0.0.0.0/0 igw-abc123 ← everything else goes to Internet Gateway Private Subnet Route Table:Destination Target10.0.0.0/16 local ← VPC traffic stays inside0.0.0.0/0 nat-abc123 ← outbound internet via NAT Gatewaypl-xxxxxx vpce-abc123 ← S3 traffic via VPC Gateway Endpoint (free)The Local Route
Every route table has a local route that cannot be deleted:
10.0.0.0/16 → localThis means any packet destined for an IP within the VPC CIDR stays inside the VPC and routes directly — no gateway needed.
Longest-Prefix Match
When multiple routes could match a destination, the most specific (longest prefix) wins:
Routes: 10.0.0.0/16 → local, 0.0.0.0/0 → IGWPacket to 10.0.1.50: Matches 10.0.0.0/16 (prefix length 16) → local route wins Matches 0.0.0.0/0 (prefix length 0) → less specific, ignoredResult: routes locallyVPC Endpoint Route
When you create an S3 Gateway Endpoint, AWS automatically adds a route:
pl-xxxxxx (S3 prefix list) → vpce-xxxxxxxx (endpoint ID)Packets going to S3 IPs match this route and go through the endpoint — free, private, inside AWS.
One Route Table, Many Subnets
Route Table: public-rt Associated with: public-subnet-1a and public-subnet-1b Both subnets share the same routing rules Route Table: private-rt-1a Associated with: private-subnet-1a only Routes outbound to NAT Gateway in AZ-1a Route Table: private-rt-1b Associated with: private-subnet-1b only Routes outbound to NAT Gateway in AZ-1b (separate for HA)RememberEvery subnet must be associated with exactly one route table. If a subnet has no explicit association, it uses the VPC's Main Route Table — which by default has only the local route (no internet access).
Frequently Asked Questions
Why does a subnet need an explicit route table association instead of using a network-wide default?
AWS VPCs deliberately have no single network-wide routing table — every subnet is associated with exactly one route table (either explicitly, or the VPC's implicit main route table if none is assigned), and that's what makes 'public' and 'private' subnet distinctions possible in the first place. A subnet is 'public' purely because its route table sends 0.0.0.0/0 to an Internet Gateway; there's no other flag that makes a subnet public.
What's a common route table mistake that silently breaks outbound internet access for a private subnet?
Forgetting to add a route sending 0.0.0.0/0 to a NAT Gateway in the private subnet's route table — the NAT Gateway itself can be provisioned correctly and still do nothing if no route points traffic at it. Also common: pointing the default route at a NAT Gateway that lives in a different Availability Zone than the private subnet, which works but adds unnecessary cross-AZ data transfer cost — NAT Gateways aren't AZ-redundant by default, so each AZ typically needs its own.