Overview and What You Will Learn
In this lab, you will create a VNet with a properly sized address space, divide it into subnets for different application tiers, and understand why the initial CIDR planning decision is hard to undo once resources are already deployed inside it.
Why This Matters in Production
A team at a startup creates a VNet with a small address range because "we only have a few VMs right now," and eighteen months later, once the application has grown and needs more subnets than the original range can accommodate, the only real fix is building an entirely new, larger VNet and migrating everything into it. Planning the address space generously from day one avoids this exact rebuild.
Core Principles
A VNet is your own isolated, private network inside Azure, defined by a CIDR address range and then divided into Subnets - smaller ranges within that overall space, typically one per application tier.
+------------------------------------------+| VNet: 10.0.0.0/16 (~65,000 addresses) || || +-------------------------------------+ || | Subnet: subnet-web (10.0.1.0/24) | || +-------------------------------------+ || || +-------------------------------------+ || | Subnet: subnet-app (10.0.2.0/24) | || +-------------------------------------+ || || +-------------------------------------+ || | Subnet: subnet-data (10.0.3.0/24) | || +-------------------------------------+ |+------------------------------------------+Each subnet acts as its own boundary for applying Network Security Group rules and routing decisions - separating tiers into different subnets is what makes it possible to apply different security rules to your web tier versus your database tier.
Detailed Step-by-Step Practical Lab
- Create a Resource Group:
az group create --name rg-vnet-lab-mumbai --location centralindia- Create a VNet with a generously sized address space and a first subnet:
az network vnet create \ --resource-group rg-vnet-lab-mumbai \ --name vnet-lab \ --address-prefix 10.0.0.0/16 \ --subnet-name subnet-web \ --subnet-prefix 10.0.1.0/24- Add two more subnets for the application and data tiers:
az network vnet subnet create \ --resource-group rg-vnet-lab-mumbai \ --vnet-name vnet-lab \ --name subnet-app \ --address-prefix 10.0.2.0/24 az network vnet subnet create \ --resource-group rg-vnet-lab-mumbai \ --vnet-name vnet-lab \ --name subnet-data \ --address-prefix 10.0.3.0/24- List all subnets to confirm the address space was divided as expected:
az network vnet subnet list \ --resource-group rg-vnet-lab-mumbai \ --vnet-name vnet-lab \ --output table- Confirm the total available address space remaining, to see how much room is left for future subnets:
az network vnet show \ --resource-group rg-vnet-lab-mumbai \ --name vnet-lab \ --query "addressSpace.addressPrefixes" --output tsvNoteA /16 VNet with three /24 subnets carved out of it still has room for well over a hundred more /24 subnets - this headroom is exactly why starting with a /16 rather than a smaller range matters, even if only a few subnets are needed today.
- Clean up:
az group delete --name rg-vnet-lab-mumbai --yes --no-waitProduction Best Practices & Common Pitfalls
Common MistakeSizing a VNet's address space based only on current, immediately known requirements. A VNet's CIDR block cannot be expanded after creation - if the workload later grows beyond the original range, the only fix is building an entirely new, larger VNet and migrating every resource into it.
TipAlways start VNets at /16 and divide into small subnets like /24, rather than starting small and hoping growth stays within a tight range. The unused address space in an oversized VNet costs nothing - it's simply reserved for whenever it's actually needed.
- Separate subnets by tier, not by convenience. Web, application, and data tiers in separate subnets makes it possible to apply different, appropriately scoped Network Security Group rules to each - collapsing everything into one subnet removes that isolation.
- Azure reserves 5 IP addresses per subnet for its own internal use (network address, VPC router, DNS, a reserved address, and broadcast) - plan subnet sizes accounting for this, not just the raw address count.
Quick Reference & Troubleshooting Commands
| Command | Description |
|---|---|
az network vnet create |
Create a new Virtual Network with an initial subnet |
az network vnet subnet create |
Add another subnet to an existing VNet |
az network vnet subnet list |
List all subnets within a VNet |
az network vnet show --query "addressSpace" |
Check a VNet's configured address space |