Why Does Networking Matter?
You can create servers and databases in AWS, but if they cannot communicate with each other or connect to the outside world, they are useless. Networking defines how every AWS service talks to each other and to the internet.
Understanding VPC answers questions like "Why can't this server connect to the internet?" and "Why can't this database be reached from outside?"
---
Using an Apartment Complex as an Analogy
The easiest way to understand AWS networking is through a building analogy.
VPC = the entire gated apartment complex. It is your own territory, separated from everything outside. Subnets = individual buildings inside the complex. Some buildings allow outside visitors (public), others are residents-only (private). Internet Gateway = the main entrance of the complex. The only way in and out connecting to the outside road. NAT Gateway = a back exit for private building residents. They can go out, but outsiders cannot come in through this exit. Security Groups = the door lock on each individual apartment. Only allowed people can enter. NACLs = the access control gate at the building entrance. Rules apply to the entire building at once.
---
What is a VPC (Virtual Private Cloud)?
A VPC is your own isolated network space inside AWS. Think of it as carving out a dedicated zone for yourself inside the AWS data center.
Inside a VPC, you define the IP address range, create subnets, and control how traffic flows in and out. By default, nothing from outside can reach what is inside your VPC.
---
Public Subnets vs Private Subnets
Subnets divide the IP address space inside a VPC. There are two kinds.
A public subnet is connected to an Internet Gateway, which means it can be reached directly from the internet. Put web servers and other resources that need to accept outside connections here.
A private subnet has no connection to an Internet Gateway, so it cannot be reached from the internet. Put databases and other resources that should never be publicly exposed here.
When a server in a private subnet needs to reach the internet for something like software updates, it uses a NAT Gateway. The NAT Gateway allows outgoing requests but blocks incoming connections from outside.
---
Security Groups vs NACLs
Both control traffic like a firewall, but they work differently.
| Feature | Security Group | NACL | |---------|---------------|------| | Applies to | Individual EC2 instances | Entire subnet | | State | Stateful | Stateless | | Rule types | Allow rules only | Allow and Deny rules | | Default behavior | Block all inbound traffic | Allow all traffic |
Stateful means that if a Security Group allows an inbound request, the response going back out is automatically allowed. You do not need to write a separate outbound rule.
Stateless means NACLs require you to write separate inbound and outbound rules for every type of traffic.
---
Exam Quick Reference
"Instance-level firewall, allow rules only" — Security Groups "Subnet-level firewall, allow and deny rules" — NACLs "Stateful" — Security Groups "Stateless" — NACLs "Gateway connecting VPC to the internet" — Internet Gateway "Let a private subnet reach the internet" — NAT Gateway "Subnet that can be reached directly from the internet" — Public Subnet "Where to put databases that must not be publicly exposed" — Private Subnet The difference between Security Groups and NACLs is a very common exam topic. Both are firewalls but differ in scope and state management.