Amazon Virtual Private Cloud (Amazon VPC) lets you create isolated private networks inside AWS. A good VPC design is not just about creating subnets. It is about planning address space, routing, segmentation, access control, observability, and future connectivity before workloads arrive.
Reading Order
- Public and Private AWS Networking
- VPC Foundations and Custom VPCs
- VPC IP Planning and CIDR Design
- VPC Subnets and Availability Zones
- VPC Router and Route Tables
- DHCP, DNS, and Option Sets
- IPv6 in AWS VPCs
- Stateful vs Stateless Firewalls
- Security Groups
- Network ACLs
- VPC Flow Logs
- VPC Traffic Mirroring
- Secure Multi-Tier VPC Reference Architecture
Core Model
flowchart TD Region["AWS Region"] VPC["VPC<br/>Regional isolated network"] AZA["Availability Zone A"] AZB["Availability Zone B"] SubnetA["Subnet<br/>one AZ"] SubnetB["Subnet<br/>one AZ"] Router["VPC router<br/>subnet +1 gateway"] RT["Route tables"] SG["Security groups<br/>ENI level"] NACL["Network ACLs<br/>subnet boundary"] Logs["Flow Logs / Traffic Mirroring"] Region --> VPC VPC --> AZA --> SubnetA VPC --> AZB --> SubnetB SubnetA --> Router SubnetB --> Router RT --> Router SG --> SubnetA NACL --> SubnetA VPC --> Logs
Security Themes
- VPCs provide isolation, but connected VPCs and hybrid links extend the blast radius.
- Subnets provide structure and AZ placement, not complete isolation by themselves.
- Route tables decide where packets go after they leave the local subnet.
- Security groups are stateful controls attached to elastic network interfaces.
- Network ACLs are stateless controls attached at subnet boundaries.
- Flow Logs provide packet metadata for investigation, but not payloads.
- Traffic Mirroring supports packet inspection when metadata is not enough.