Demystifying AWS Networking: A Beginner’s Guide for Developers
As software developers, we spend most of our time writing code, building APIs, and optimizing database queries. But when it comes time to deploy our applications to the cloud, AWS networking can quickly feel overwhelming. Concepts like VPCs, Subnets, CIDR blocks, Internet Gateways, Route Tables, and Security Groups sound like standard infrastructure setup, but understanding how they fit together is essential for any modern programmer.
This blog post breaks down the core concepts from Travis Media’s hands-on tutorial, “AWS Networking Basics For Programmers”, guiding you step-by-step through building a custom, secure AWS network from scratch.
💡 The Core Blueprint: AWS Networking Architecture
Before opening the AWS console, let’s look at the logical structure of a standard, production-ready cloud network:
+-------------------------------------------------------------------+
| AWS Region / Custom VPC |
| CIDR Block: 10.0.0.0/16 |
| |
| +--------------------------+ +--------------------------+ |
| | Public Subnet | | Private Subnet | |
| | 10.0.1.0/24 | | 10.0.2.0/24 | |
| | | | | |
| | +--------------------+ | | +--------------------+ | |
| | | Web Server (EC2) | | | | Database (RDS/EC2) | | |
| | | (Public + Priv IP) | | | | (Private IP Only) | | |
| | +---------+----------+ | | +---------^----------+ | |
| +------------|-------------+ +------------|-------------+ |
| | | |
| Route Table Route Table |
| (0.0.0.0/0 -> IGW) (Internal Only) |
| | | |
+----------------|--------------------------------|-----------------+
| |
v |
[Internet Gateway] | (Inbound allowed
| | from Web Server)
+================================+
|
[ INTERNET ]
1. Virtual Private Cloud (VPC)
Think of an Amazon VPC (Virtual Private Cloud) as your own private virtual data center inside AWS. It provides complete isolation from other networks on AWS, allowing you to define your IP address ranges, subnets, and security configurations.
- Default VPC: AWS gives every account a default VPC with pre-configured public subnets in every Availability Zone.
- Custom VPC: For real-world production projects, you should build a custom VPC to ensure maximum control over security boundaries.
IP Addressing & CIDR Notation
When defining a VPC network range, you specify a Classless Inter-Domain Routing (CIDR) block.
- Example:
10.0.0.0/16 - The
/16prefix masks the first 16 bits, giving you 65,536 available private IP addresses (10.0.0.0through10.0.255.255).
2. Subnets: Segmenting Your Network
A Subnet (sub-network) is a range of IP addresses within your VPC. Splitting your network into subnets allows you to organize resources based on security and operational needs.
A. Public Subnet
- Purpose: For resources that must be directly accessible from the internet (e.g., Web Servers, Load Balancers, API Gateways).
- CIDR Example:
10.0.1.0/24(256 IP addresses). - Key Requirement: Must route outbound traffic through an Internet Gateway.
B. Private Subnet
- Purpose: For backend resources that should never be directly exposed to the public internet (e.g., Databases, Internal APIs, Application Logic).
- CIDR Example:
10.0.2.0/24(256 IP addresses). - Key Requirement: No direct route to the Internet Gateway. Access is restricted to internal VPC traffic or via controlled proxies/NAT Gateways.
3. Connecting to the World: Internet Gateway & Route Tables
Creating a VPC and a subnet is not enough to get online. By default, resources inside a custom VPC cannot talk to the outside world.
Internet Gateway (IGW)
An Internet Gateway is a horizontally scaled, redundant VPC component that enables communication between instances in your VPC and the internet.
- Create an Internet Gateway.
- Attach it to your custom VPC.
Route Tables
A Route Table contains a set of rules (called routes) that determine where network traffic is directed.
- Main Route Table: Created automatically with the VPC. It defaults to routing local traffic only (
10.0.0.0/16 -> local). - Custom Public Route Table:
- Add a route sending all internet-bound traffic (
0.0.0.0/0) to your Internet Gateway. - Associate this route table with your Public Subnet.
- Add a route sending all internet-bound traffic (
4. Hands-On Walkthrough: Step-by-Step Implementation
Here is a practical guide to setting up your own AWS network:
Step 1: Create the Custom VPC
- Navigate to AWS Console > VPC Dashboard.
- Click Create VPC.
- Select VPC only.
- Name:
My-Dev-VPC - IPv4 CIDR block:
10.0.0.0/16 - Click Create VPC.
Step 2: Create Public and Private Subnets
- Go to Subnets > Create subnet.
- Select
My-Dev-VPC. - Public Subnet Settings:
- Subnet name:
Public-Subnet-1 - Availability Zone: Select any (e.g.,
us-east-1a). - IPv4 CIDR block:
10.0.1.0/24
- Subnet name:
- Click Add new subnet to add the private one in the same workflow:
- Subnet name:
Private-Subnet-1 - Availability Zone: Select the same or another zone.
- IPv4 CIDR block:
10.0.2.0/24
- Subnet name:
- Click Create subnets.
- Select
Public-Subnet-1> Actions > Edit subnet settings > Check Enable auto-assign public IPv4 address and save.
Step 3: Attach an Internet Gateway
- Go to Internet Gateways > Create internet gateway.
- Name:
My-Dev-IGW - Click Create internet gateway.
- Click Actions > Attach to VPC and select
My-Dev-VPC.
Step 4: Configure Route Tables
- Go to Route Tables > Create route table.
- Name:
Public-Route-Table - VPC: Select
My-Dev-VPCand create. - Open the new
Public-Route-Table:- Go to Routes > Edit routes > Add route.
- Destination:
0.0.0.0/0 - Target: Internet Gateway (
My-Dev-IGW). - Save changes.
- Go to Subnet Associations > Edit subnet associations.
- Select
Public-Subnet-1and save.
- Select
5. Controlling Access: Security Groups vs. Network ACLs
AWS provides two layers of firewalls to secure your instances:
| Feature | Security Groups | Network ACLs (NACLs) |
|---|---|---|
| Level | Instance Level (EC2) | Subnet Level |
| Statefulness | Stateful (Return traffic automatically allowed) | Stateless (Must explicitly allow inbound & outbound) |
| Rules | Evaluate all rules before deciding | Processed in numbered order |
| Action | Allow rules only (default deny) | Allow and Deny rules |
Setting Up a Security Group for Web Traffic:
- Go to EC2 > Security Groups > Create Security Group.
- Inbound Rules:
- Allow HTTP (Port 80) from
0.0.0.0/0 - Allow SSH (Port 22) from your specific IP address (
My IP).
- Allow HTTP (Port 80) from
- Attach this Security Group to any EC2 instances deployed in the public subnet.
Key Takeaways for Developers
- Isolation is Key: Keep database servers in private subnets and application entry points in public subnets.
- Explicit Routing: A subnet is only “public” if its route table explicitly routes
0.0.0.0/0to an attached Internet Gateway. - Stateful Firewalling: Security Groups track connections. If you open inbound port
80, the outbound response is permitted automatically.
📺 Video Resource
For the full hands-on demonstration and visual walkthrough, check out the original video:
- Title: AWS Networking Basics For Programmers | Hands On
- Creator: Travis Media