Demystifying AWS Networking: A Beginner’s Guide for Developers


As software developers, we spend most of our time writing code, building APIs, and optimizing database queries. But when it comes time to deploy our applications to the cloud, AWS networking can quickly feel overwhelming. Concepts like VPCs, Subnets, CIDR blocks, Internet Gateways, Route Tables, and Security Groups sound like standard infrastructure setup, but understanding how they fit together is essential for any modern programmer.

This blog post breaks down the core concepts from Travis Media’s hands-on tutorial, “AWS Networking Basics For Programmers”, guiding you step-by-step through building a custom, secure AWS network from scratch.


💡 The Core Blueprint: AWS Networking Architecture

Before opening the AWS console, let’s look at the logical structure of a standard, production-ready cloud network:

+-------------------------------------------------------------------+
|                        AWS Region / Custom VPC                    |
|                        CIDR Block: 10.0.0.0/16                    |
|                                                                   |
|   +--------------------------+     +--------------------------+   |
|   |      Public Subnet       |     |      Private Subnet      |   |
|   |      10.0.1.0/24         |     |      10.0.2.0/24         |   |
|   |                          |     |                          |   |
|   |  +--------------------+  |     |  +--------------------+  |   |
|   |  | Web Server (EC2)   |  |     |  | Database (RDS/EC2) |  |   |
|   |  | (Public + Priv IP) |  |     |  | (Private IP Only)  |  |   |
|   |  +---------+----------+  |     |  +---------^----------+  |   |
|   +------------|-------------+     +------------|-------------+   |
|                |                                |                 |
|          Route Table                      Route Table             |
|        (0.0.0.0/0 -> IGW)               (Internal Only)           |
|                |                                |                 |
+----------------|--------------------------------|-----------------+
                 |                                |
                 v                                |
         [Internet Gateway]                       | (Inbound allowed 
                 |                                |  from Web Server)
                 +================================+
                                 |
                            [ INTERNET ]

1. Virtual Private Cloud (VPC)

Think of an Amazon VPC (Virtual Private Cloud) as your own private virtual data center inside AWS. It provides complete isolation from other networks on AWS, allowing you to define your IP address ranges, subnets, and security configurations.

  • Default VPC: AWS gives every account a default VPC with pre-configured public subnets in every Availability Zone.
  • Custom VPC: For real-world production projects, you should build a custom VPC to ensure maximum control over security boundaries.

IP Addressing & CIDR Notation

When defining a VPC network range, you specify a Classless Inter-Domain Routing (CIDR) block.

  • Example: 10.0.0.0/16
  • The /16 prefix masks the first 16 bits, giving you 65,536 available private IP addresses (10.0.0.0 through 10.0.255.255).

2. Subnets: Segmenting Your Network

A Subnet (sub-network) is a range of IP addresses within your VPC. Splitting your network into subnets allows you to organize resources based on security and operational needs.

A. Public Subnet

  • Purpose: For resources that must be directly accessible from the internet (e.g., Web Servers, Load Balancers, API Gateways).
  • CIDR Example: 10.0.1.0/24 (256 IP addresses).
  • Key Requirement: Must route outbound traffic through an Internet Gateway.

B. Private Subnet

  • Purpose: For backend resources that should never be directly exposed to the public internet (e.g., Databases, Internal APIs, Application Logic).
  • CIDR Example: 10.0.2.0/24 (256 IP addresses).
  • Key Requirement: No direct route to the Internet Gateway. Access is restricted to internal VPC traffic or via controlled proxies/NAT Gateways.

3. Connecting to the World: Internet Gateway & Route Tables

Creating a VPC and a subnet is not enough to get online. By default, resources inside a custom VPC cannot talk to the outside world.

Internet Gateway (IGW)

An Internet Gateway is a horizontally scaled, redundant VPC component that enables communication between instances in your VPC and the internet.

  1. Create an Internet Gateway.
  2. Attach it to your custom VPC.

Route Tables

A Route Table contains a set of rules (called routes) that determine where network traffic is directed.

  • Main Route Table: Created automatically with the VPC. It defaults to routing local traffic only (10.0.0.0/16 -> local).
  • Custom Public Route Table:
    • Add a route sending all internet-bound traffic (0.0.0.0/0) to your Internet Gateway.
    • Associate this route table with your Public Subnet.

4. Hands-On Walkthrough: Step-by-Step Implementation

Here is a practical guide to setting up your own AWS network:

Step 1: Create the Custom VPC

  1. Navigate to AWS Console > VPC Dashboard.
  2. Click Create VPC.
  3. Select VPC only.
  4. Name: My-Dev-VPC
  5. IPv4 CIDR block: 10.0.0.0/16
  6. Click Create VPC.

Step 2: Create Public and Private Subnets

  1. Go to Subnets > Create subnet.
  2. Select My-Dev-VPC.
  3. Public Subnet Settings:
    • Subnet name: Public-Subnet-1
    • Availability Zone: Select any (e.g., us-east-1a).
    • IPv4 CIDR block: 10.0.1.0/24
  4. Click Add new subnet to add the private one in the same workflow:
    • Subnet name: Private-Subnet-1
    • Availability Zone: Select the same or another zone.
    • IPv4 CIDR block: 10.0.2.0/24
  5. Click Create subnets.
  6. Select Public-Subnet-1 > Actions > Edit subnet settings > Check Enable auto-assign public IPv4 address and save.

Step 3: Attach an Internet Gateway

  1. Go to Internet Gateways > Create internet gateway.
  2. Name: My-Dev-IGW
  3. Click Create internet gateway.
  4. Click Actions > Attach to VPC and select My-Dev-VPC.

Step 4: Configure Route Tables

  1. Go to Route Tables > Create route table.
  2. Name: Public-Route-Table
  3. VPC: Select My-Dev-VPC and create.
  4. Open the new Public-Route-Table:
    • Go to Routes > Edit routes > Add route.
    • Destination: 0.0.0.0/0
    • Target: Internet Gateway (My-Dev-IGW).
    • Save changes.
  5. Go to Subnet Associations > Edit subnet associations.
    • Select Public-Subnet-1 and save.

5. Controlling Access: Security Groups vs. Network ACLs

AWS provides two layers of firewalls to secure your instances:

FeatureSecurity GroupsNetwork ACLs (NACLs)
LevelInstance Level (EC2)Subnet Level
StatefulnessStateful (Return traffic automatically allowed)Stateless (Must explicitly allow inbound & outbound)
RulesEvaluate all rules before decidingProcessed in numbered order
ActionAllow rules only (default deny)Allow and Deny rules

Setting Up a Security Group for Web Traffic:

  1. Go to EC2 > Security Groups > Create Security Group.
  2. Inbound Rules:
    • Allow HTTP (Port 80) from 0.0.0.0/0
    • Allow SSH (Port 22) from your specific IP address (My IP).
  3. Attach this Security Group to any EC2 instances deployed in the public subnet.

Key Takeaways for Developers

  1. Isolation is Key: Keep database servers in private subnets and application entry points in public subnets.
  2. Explicit Routing: A subnet is only “public” if its route table explicitly routes 0.0.0.0/0 to an attached Internet Gateway.
  3. Stateful Firewalling: Security Groups track connections. If you open inbound port 80, the outbound response is permitted automatically.

📺 Video Resource

For the full hands-on demonstration and visual walkthrough, check out the original video: