Amazon VPC Networking for Cloud Engineers
Learn to design and build AWS VPCs: CIDR planning, public and private subnets, route tables, NAT, security groups, endpoints, and flow logs.
What You'll Learn
Understanding Why VPCs Exist
A VPC is the network boundary around everything else you run on AWS, so every later cloud skill sits inside one.
Planning CIDR Blocks
IP ranges are the one VPC decision that is painful to undo, so plan them before you create anything.
Building Public Subnets with an Internet Gateway
A server you cannot reach is not much use, and a server anyone can reach is a risk, so you need to know exactly what makes a subnet public.
Reaching the Internet from Private Subnets with NAT
Private servers still need to download patches and call external APIs, and NAT lets them do that without being reachable from outside.
Routing Traffic with Route Tables
Every packet leaving a subnet is checked against a route table. When a connection fails, the route table is one of the first places to look.
Filtering Traffic with Security Groups and NACLs
Routes decide whether traffic can get somewhere. Firewalls decide whether it is allowed to arrive.
Skills You'll Master
Curriculum Index11 topics
Understanding Why VPCs Exist
A VPC is the network boundary around everything else you run on AWS, so every later cloud skill sits inside one.
Planning CIDR Blocks
IP ranges are the one VPC decision that is painful to undo, so plan them before you create anything.
Building Public Subnets with an Internet Gateway
A server you cannot reach is not much use, and a server anyone can reach is a risk, so you need to know exactly what...
Reaching the Internet from Private Subnets with NAT
Private servers still need to download patches and call external APIs, and NAT lets them do that without being...
Routing Traffic with Route Tables
Every packet leaving a subnet is checked against a route table.
Filtering Traffic with Security Groups and NACLs
Routes decide whether traffic can get somewhere. Firewalls decide whether it is allowed to arrive.
Reaching AWS Services Privately with VPC Endpoints
Traffic to AWS services does not have to leave through a NAT gateway and the internet.
Connecting VPCs with Peering and Transit Gateway
Real organisations run many VPCs, and some of them need to talk to each other.
Debugging with VPC Flow Logs and Reachability Analyzer
"Why can A not reach B?" is the most common networking question on AWS, and two tools answer it without guessing.
Hands-on Lab: Build a Two-AZ VPC with SSM Access
You will build a VPC with public and private subnets in two AZs, launch one instance in each tier, reach them with...
Quick Reference and Common Mistakes
Quick reference Common mistakes Treating a subnet as public because of its name is a frequent error.
Career Impact
Roles that use the skills in this module.
Cloud Engineer
DevOps Engineer
Solutions Architect
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
A public subnet has a route to an Internet Gateway in its route table. A private subnet does not. An individual instance also needs a public IP address to be reachable from the internet, even in a public subnet.
No. You need one only when instances in private subnets must start connections to the internet, for example to download packages. If they only talk to AWS services, VPC endpoints are often cheaper and safer.
Use security groups as your main control. They are stateful and attach to resources. Network ACLs are stateless, work at the subnet level, and are best kept for coarse rules such as blocking a range of addresses.
You cannot change the primary CIDR block, but you can add secondary CIDR blocks. Planning the primary range properly still matters, because overlapping ranges block peering and VPN connections.