Skip to main content

Subnet

A segment of a VPC's IP address range locked to one Availability Zone. Public subnets route internet traffic to an Internet Gateway. Private subnets route outbound traffic to a NAT Gateway.

What is a Subnet

A subnet divides your VPC into smaller IP ranges — one per Availability Zone. Resources in a subnet stay in that AZ. For high availability, always use subnets in at least two AZs.

◈ DIAGRAM
VPC: 10.0.0.0/16
├── Subnet: 10.0.1.0/24 in ap-south-1a (256 total, 251 usable)
├── Subnet: 10.0.2.0/24 in ap-south-1b (256 total, 251 usable)
├── Subnet: 10.0.10.0/24 in ap-south-1a (private)
└── Subnet: 10.0.11.0/24 in ap-south-1b (private)

Subnet Sizing Formula

TEXT
Total IPs = 2 ^ (32 - CIDR number)
/28 = 2^4 = 16 IPs (16 - 5 = 11 usable)
/27 = 2^5 = 32 IPs (32 - 5 = 27 usable)
/26 = 2^6 = 64 IPs (64 - 5 = 59 usable)
/24 = 2^8 = 256 IPs (256 - 5 = 251 usable)
/20 = 2^12 = 4,096 IPs (use for EKS — pods consume IPs fast)

Public Subnet Requirements

◈ DIAGRAM
1. VPC has Internet Gateway attached
2. Route Table: 0.0.0.0/0 → igw-xxxxxxxx
3. Instance has public IP (auto-assign enabled or Elastic IP)

Private Subnet with NAT Gateway

◈ DIAGRAM
Route Table for private subnet:
10.0.0.0/16 → local (stays in VPC)
0.0.0.0/0 → nat-gateway-id (outbound internet via NAT)
EC2 in private subnet can reach internet (outbound only)
Internet cannot reach EC2 in private subnet (no public IP)

Auto-Assign Public IP

◈ DIAGRAM
Public subnets: enable auto-assign public IPv4
Private subnets: keep disabled
EC2 → Actions → Networking → manage IP addresses
Or set at subnet level: VPC → Subnets → Edit subnet settings
Remember

Subnets cannot be resized after creation. Size generously — /24 gives 251 usable IPs. For EKS clusters use /20 or larger because VPC CNI gives every pod a real VPC IP.

Common Mistake

Creating only one subnet per AZ or putting all resources in one AZ. Always create at least two subnets across two AZs for any production workload.

Frequently Asked Questions

Why does an AWS subnet have to live in a single Availability Zone?

Subnets are the mechanism by which AWS maps a piece of your VPC's IP range to physical infrastructure in one specific AZ — this is intentional, so that when you deploy resources across multiple subnets in different AZs, an outage in one AZ doesn't take down resources in another. This is why highly-available architectures always span at least two, often three, subnets across different AZs rather than relying on one large subnet.

What's the most common subnet sizing mistake teams make when setting up a VPC?

Under-sizing subnets early on — picking a /28 or /27 CIDR block that fills up once you add auto-scaling groups, Lambda ENIs, or a few extra services, and resizing a subnet's CIDR after resources exist is not straightforward. It's generally safer to plan generously (e.g., /20 or /21 per subnet in a large VPC) up front, since subnet count and size decisions are hard to unwind later without significant rework.