Courses / Hands-on Cloud for Freshers

Session 5 of 8

Your own network: VPC basics

Overview

Unit 5 — Your Own Network: VPC Basics

Course: Hands-on Cloud for Freshers

Prerequisites: You have an AWS account with a budget alert and an everyday administrator identity (Unit 1). You can sign in to the AWS CLI with short-lived credentials and run a command against your account (Unit 2). You have launched an EC2 instance in the default VPC, connected to it with EC2 Instance Connect, served a web page through a security group rule, and terminated it (Unit 4). No prior networking knowledge is assumed beyond knowing that a computer on a network has an IP address.

What the reader can do after this unit:

  • Build, by hand, a virtual private cloud with one public subnet — the VPC, the subnet, an internet gateway, a route table with a route to it, and a security group — and say what each piece contributes to a request reaching a server.
  • Diagnose why a server inside a network you built cannot be reached, by checking its address, its route, its subnet’s network ACL, its security group and the server itself in that order, and fixing the one that fails.
  • Tear the network down in dependency order and prove, with commands whose output you can read, that nothing billable is left behind — no instance, no public IPv4 address, no NAT gateway.

Core question this unit answers: When a server sits inside a network you built yourself, what has to be true at each layer for a request from your browser to reach it and for the reply to come back?

Connections:

  • Builds on: Unit 4, where the default VPC quietly supplied an internet gateway, a route and a public IPv4 address for you. This unit builds each of those by hand, so you know what the default was doing.
  • Leads into: Unit 6, which stores data in DynamoDB — a managed service you reach through an AWS API rather than through a subnet you own. Seeing what a network is makes it clear what that service is saving you from.

Your answers are scored

This unit is assessed. The quiz is marked against a key held separately from your materials. Its first eight questions are multiple choice. Its last two ask you to write a short answer — a CIDR block and a set of firewall rules — in a format the question states exactly.

Two consequences worth knowing before you start:

  • Each written answer is marked by fixed checks, not by opinion. The question tells you every requirement your answer must meet; a grader runs the same checks on every submission, so an answer that meets the requirements scores, whatever it looks like.
  • Style is not marked. Spacing, rule order and capitalisation of the protocol name do not change the score. What is marked is whether your answer does what the question requires.

Notes

Hands-on Cloud for Freshers — Unit 5: Your Own Network: VPC Basics

Before you start

You need the account, budget alert and administrator identity from Unit 1, and the AWS CLI signed in as in Unit 2.

If you are starting here, without those:

  1. Create the account. Open the Sign up for AWS page, https://signin.aws.amazon.com/signup?request_type=register. You need an email address you can receive mail at (it becomes the root user’s sign-in name), a phone number that can receive an SMS, and a valid payment method; you choose an account plan during sign-up. Wait for the email confirming that the account is activated before you sign in (Sign up for AWS (advanced)).
  2. Protect the root user and set a budget. Sign in at https://console.aws.amazon.com/ as Root user and turn on MFA (multi-factor authentication: a one-time code from a device you hold, asked for at each console sign-in). The IAM User Guide’s advice is not to use the root user for daily tasks (Setting up your AWS account). While still signed in as root, open the Billing and Cost Management console, choose Budgets → Create budget → Use a template (simplified), pick Zero spend budget — “a budget that notifies you after your spending exceeds AWS Free Tier limits” — fill in the settings the template asks for, and choose Create budget (Using a budget template (simplified)).
  3. Create the everyday administrator. Still as root, open the IAM console and choose Users → Create user. Enter a user name such as hoc-admin, tick Provide user access to the AWS Management Console and choose I want to create an IAM user, and set a password. On Set permissions choose Add user to group → Create group, name the group hoc-admins, select the AWS managed policy AdministratorAccess, choose Create user group, select the new group, then Next and Create user (Create an IAM user for emergency access shows these screens). Sign out of root and sign in at https://<your-account-id>.signin.aws.amazon.com/console as hoc-admin (How IAM users sign in to AWS).
  4. Sign in the AWS CLI. Install the AWS CLI version 2 (Installing or updating to the latest version of the AWS CLI). The sign-in command, aws login, needs version 2.32.0 or later, so check with aws --version first. Run aws login, enter ap-south-1 when it asks for a Region, and sign in as hoc-admin in the browser it opens; the CLI receives temporary credentials and no access key is stored. An IAM identity needs the SignInLocalDevelopmentAccess managed policy or equivalent permissions, which AdministratorAccess covers because it allows every action (Sign in with aws login; AdministratorAccess). aws sts get-caller-identity then prints your account ID.

Every example uses the Asia Pacific (Mumbai) Region, ap-south-1; if you work in another Region, change the Region code wherever it appears, including inside the EC2 Instance Connect prefix-list name. Tag everything you create with project = hands-on-cloud, as in earlier units, so that the teardown at the end can find it.

What costs money here, and what does not. Read this before you build anything.

Thing you create Charge, per the AWS documentation
VPC, subnet, route table The VPC pricing page lists charges only for features such as NAT gateways and IP addresses, not for the VPC itself
Internet gateway “There is no charge for an internet gateway, but there are data transfer charges for EC2 instances that use internet gateways”
Security group “There is no additional charge for using security groups”
Network ACL “There is no additional charge for using network ACLs”
Public IPv4 address Charged. “AWS charges for all public IPv4 addresses, including public IPv4 addresses associated with running instances and Elastic IP addresses.” The VPC pricing page lists USD 0.005 per hour for an in-use address and the same for an idle one
NAT gateway Charged “for each hour that your NAT gateway is available and each gigabyte of data that it processes.” This unit never creates one
EC2 instance Charged while running. For an account created on or after July 15, 2025, the instance types marked Free tier eligible — t3.micro among them — are covered by your Free Tier credits

On the Free account plan these charges are drawn from your credits rather than billed, but credits are finite, so the habit to build is the same either way: create what you need, prove it works, and remove it. The project’s last task is that removal, and it is not optional.

Summary

In Unit 4 you launched a server into the default VPC and it was reachable at once, because AWS had already built the network around it: an internet gateway, a route to that gateway, and a public IPv4 address handed to every instance. This unit removes that safety net. You build a network from nothing, launch a server into it, and watch it fail to answer until each missing piece is supplied. A request reaches a web page only when five things are true together — the instance has a public address, its subnet has a route to the internet gateway, the subnet’s network ACL lets the traffic through in both directions, the instance’s security group allows the port, and the server itself is listening on that port with nothing on the instance, such as an operating-system firewall, blocking it — and when one of the network conditions is missing, nothing reports an error: the request simply times out. Knowing the conditions, and checking them in order, is what turns a silent timeout into a quick, certain fix.

Key concepts

Term Definition
VPC (virtual private cloud) A virtual network dedicated to your AWS account, logically isolated from other virtual networks. You choose its IP address range and add subnets, gateways and security groups to it
CIDR block A way of writing an IP address range as a starting address and a prefix length, such as 10.0.0.0/16. The smaller the number after the slash, the larger the range
Subnet A range of IP addresses inside a VPC, placed in one Availability Zone. You launch instances into a subnet
Default VPC The ready-made VPC AWS creates in each Region of a new account, with an internet gateway, a route to it, and public IPv4 addresses for instances launched into its default subnets
Route table A set of rules, called routes, that decide where traffic leaving a subnet is sent. Each route has a destination range and a target
Main route table The route table that comes with the VPC. It controls every subnet not explicitly associated with another route table
Local route The route present in every route table that lets resources inside the VPC reach each other. You cannot remove it
Internet gateway The VPC component that connects the VPC to the internet. It is a target in a route table, and it does nothing until a route points at it
Public subnet A subnet whose route table has a route to an internet gateway. A subnet without such a route is a private subnet
Public IPv4 address An address reachable from the internet, mapped to the instance’s private address by the internet gateway. Every one is charged
Security group A virtual firewall attached to an instance. Allow rules only; stateful, so replies to allowed traffic are allowed automatically
Network ACL A firewall at the subnet boundary. Numbered allow and deny rules, checked lowest number first; stateless, so replies must be allowed by their own rule
Ephemeral ports The high-numbered ports a client picks for its side of a connection. A reply to a web request goes back to one of them, so a stateless firewall must allow that range
NAT gateway A managed device that lets instances in a private subnet start connections to the internet without being reachable from it. Charged by the hour and by the gigabyte

Explanations

The failure, before the explanation

Suppose you create a VPC with the range 10.0.0.0/16, add a subnet 10.0.1.0/24, and launch an instance into it with a security group that allows HTTP on port 80 from anywhere — the same rule that worked in Unit 4. You open the instance’s page in a browser and wait. The browser spins and then gives up. EC2 Instance Connect fails too. No error appears anywhere in the console: the instance reads running, its status checks pass, and the security group rule is exactly the one that worked before.

The instance is not broken. It is unreachable, and the AWS documentation states why in one table. For a VPC you create yourself — a nondefault VPC — none of these exist unless you add them:

Component Default VPC VPC you create
Internet gateway Yes No
Route table with a route to the internet gateway for IPv4 traffic (0.0.0.0/0) Yes No
Public IPv4 address automatically assigned to an instance launched into the subnet Yes No

Three of the network conditions for reachability were missing, and the security group — the one you checked — was the only part that was right. That is the shape of most networking faults: the part you look at is fine, and the part you did not know existed is absent.

Two ways to picture a VPC

As a gated housing colony. The VPC is the colony, with its own internal house numbers that mean nothing outside its walls. Each subnet is a lane inside the colony. The internet gateway is the colony’s main gate onto the public road. A route table is the signboard at the end of a lane saying which way to walk for which destinations — “anything inside the colony: stay on the internal roads” is the local route, and “anything else: go to the main gate” is the route to the internet gateway. A public IPv4 address is a postal address that the outside world can write on an envelope. Without it, no letter from outside can be addressed to the house at all, however open the gate is.

The two guards fit the same picture. The network ACL is a checkpoint at the entrance to the lane: it checks everyone going in and everyone coming out against a numbered list, and it has no memory, so a visitor who was let in must also match a rule to be let back out. The security group is the guard at the house’s own door: it has only a guest list of who may come in, and it remembers its visitors, so anyone it let in is let back out without being checked again.

As a checklist that a packet has to pass. Follow one request from your laptop to the server:

  1. Your browser sends it to a public IPv4 address. No public address, no destination.
  2. It arrives at the internet gateway, which translates the public address to the instance’s private one. The gateway must be attached to the VPC.
  3. It passes the subnet’s network ACL, inbound, on port 80.
  4. It passes the instance’s security group, inbound, on port 80.
  5. It reaches the server itself: a web server process must be listening on port 80, and nothing on the instance, such as an operating-system firewall, may drop the request. Only then does the server answer.
  6. The reply leaves through the network ACL outbound, to the ephemeral port your browser chose.
  7. The reply follows the subnet’s route table: a route for 0.0.0.0/0 must point at the internet gateway, or the reply has nowhere to go.

In the colony picture, the last check is whether anyone is home: a house with an open gate, a postal address and a friendly guard still sends no reply if nobody answers the door. Either picture gives you the same diagnosis order: address, route, subnet guard, door guard, then the server itself.

Address ranges: what /16 and /24 mean

A CIDR block is a starting address and a count of fixed leading bits. 10.0.0.0/16 fixes the first 16 bits, 10.0, and leaves 16 bits free, so it covers 65,536 addresses, from 10.0.0.0 to 10.0.255.255. A subnet takes a slice of that range: 10.0.1.0/24 fixes 24 bits and covers the 256 addresses from 10.0.1.0 to 10.0.1.255.

Three rules from the AWS documentation govern the slices:

  • A subnet’s IPv4 block must be between a /28 and a /16 in size.
  • Subnets in one VPC may not overlap.
  • AWS keeps five addresses in every subnet: the first four and the last. In 10.0.1.0/24 those are 10.0.1.0 (the network address), 10.0.1.1 (the VPC router), 10.0.1.2 (the DNS server), 10.0.1.3 (reserved for future use) and 10.0.1.255 (the broadcast address). So a /24 gives you 251 usable addresses, not 256.

The failure this prevents is small and confusing: a script that assigns 10.0.1.1 to an instance is refused, because that address is the router’s.

Route tables decide public and private

A subnet is public or private because of its route table, and for no other reason. The documentation’s definition is exact: if a subnet’s route table has a route to an internet gateway, it is a public subnet; if not, it is private. A subnet named public, or one whose security group allows the whole internet, is still private if its route table has no such route.

Every route table starts with the local route, which covers the VPC’s own range and lets resources inside the VPC reach each other. To make a subnet public, you add a second route: destination 0.0.0.0/0 — “every IPv4 address not already covered” — with the internet gateway as the target. A new subnet uses the main route table unless you explicitly associate it with another one. The usual practice, and the one the project follows, is to leave the main route table private and create a custom route table for the public subnet, so that a subnet added later is private until you decide otherwise.

The public address is a separate decision

A route to the internet gateway is necessary but not enough: the instance also needs a public IPv4 address. Instances launched into a subnet you created get no public IPv4 address by default. You can change that in two places:

  • on the subnet, with Actions → Edit subnet settings → Enable auto-assign public IPv4 address, which applies to every instance launched there afterwards; or
  • at launch, in the launch wizard’s Network settings, by setting Auto-assign public IP to Enable, which overrides the subnet setting for that one instance.

Turning on the subnet setting does not reach back and give an address to an instance that is already running. That is the second thing the timeout scenario above would teach you the hard way.

Every public IPv4 address is charged while it exists, whether the instance is busy or idle. That is the reason to set auto-assign on purpose, for the one subnet that needs it, rather than everywhere.

Two firewalls, two different rules

Security group Network ACL
Works at the instance the subnet boundary
Rule types allow only allow and deny
How rules are read all rules are evaluated before deciding in number order, lowest first; the first match decides
Reply traffic allowed automatically (stateful) must be allowed by its own rule (stateless)
Default you start with a VPC’s default security group does not allow inbound SSH; a new group allows no inbound traffic until you add rules, and allows all outbound the VPC’s default network ACL allows all traffic in and out; a custom one denies everything until you add rules

The difference that catches people is stateful versus stateless, and it is worth seeing fail. Imagine you replace the subnet’s default network ACL with a custom one and add a single inbound rule: allow TCP port 80 from 0.0.0.0/0. You add no outbound rule. A browser connects, the request passes the ACL inbound, passes the security group, and the web server answers — and the answer is dropped at the ACL on the way out, because the ACL has no memory that a request came in and no outbound rule allows a packet to the browser’s ephemeral port. The page times out exactly as if port 80 were closed.

The fix is an outbound rule that allows the reply’s destination ports. The client chooses that range, and it varies by operating system: many Linux kernels use 32768–61000, Windows Server 2008 and later use 49152–65535, and the AWS documentation notes that to cover the different clients that may reach a public-facing instance “you can open ephemeral ports 1024-65535”. A security group needs no such rule, because it remembers the request and lets the reply out.

The practical guidance from the AWS documentation is to use security groups as the primary control and network ACLs, when you need them, as a coarse second layer. In the project you leave the default network ACL in place, which allows everything, and do all filtering in the security group.

Letting EC2 Instance Connect in, and only it

In Unit 4 the launch wizard created a security group whose inbound rule allowed SSH from any IP address. The AWS documentation says such a rule is acceptable only for a briefly launched test instance, and unsafe otherwise.

When you connect from the EC2 console with EC2 Instance Connect, the connection does not come from your laptop; it comes from the EC2 Instance Connect service, whose addresses AWS publishes as a managed prefix list. For IPv4 the list is named com.amazonaws.<region>.ec2-instance-connect — in this unit’s Region, com.amazonaws.ap-south-1.ec2-instance-connect. An inbound rule allowing TCP port 22 from that prefix list lets the console connect while refusing SSH from everyone else. The instance also needs a public IPv4 address and a route to the internet, and an AMI with EC2 Instance Connect installed; the AL2023 standard AMI (Amazon Linux 2023) has it pre-installed.

The money traps: NAT gateways and public addresses

The console’s Create VPC page offers two choices under Resources to create: VPC only and VPC and more. The second can create subnets, route tables and gateways in one step, and one of its fields is NAT gateways. The documentation notes that “there is a cost associated with NAT gateways”: they are charged for every hour they exist and every gigabyte they process. A NAT gateway exists to let instances in a private subnet start outbound connections. This unit has no private subnet that needs the internet, so it never needs one. Building with VPC only and adding each piece by hand is how this unit avoids creating one by accident, and it is also how you learn what each piece does.

The second trap is quieter. A public IPv4 address is charged whether or not anything is using it, so an address you forget about keeps costing. Terminating the instance releases an automatically assigned public address. An Elastic IP address — an address you allocate to your account on purpose — stays, and keeps being charged, until you release it. This unit does not allocate one, and the teardown checks that none exists.

Tearing down in the right order

Resources depend on each other, and AWS refuses to delete a thing while something still depends on it. The Delete your VPC page states the rule plainly: “you must terminate your EC2 instances and delete your load balancers, NAT gateways, transit gateway VPC attachments, and interface VPC endpoints” before the VPC can be deleted.

So the order is:

  1. Terminate the instance. It holds a network interface inside the subnet, and while it exists the subnet and VPC cannot go.
  2. Delete the VPC from the VPC console (Your VPCs → select it → Actions → Delete VPC). The console lists anything that still blocks deletion; if nothing does, it lists what it will delete along with the VPC and asks you to type delete. Per the documentation, deleting a VPC from the console also deletes its subnets, route tables, internet gateways, security groups and network ACLs.

If you delete with the AWS CLI instead, nothing is deleted for you, and the documented order is: security groups, network ACLs, subnets, custom route tables, then detach the internet gateway, delete it, and finally delete the VPC. You never delete the default security group, the main route table or the default network ACL yourself; they go with the VPC.

The proof that teardown worked is not that the console stopped complaining. It is a set of commands whose output is empty: no instance tagged for the project, no VPC tagged for the project, no NAT gateway, no Elastic IP address. The project’s last task asks for exactly that output.

Flashcards

Say the answer aloud before revealing it. Speaking it is what exposes the gaps that reading past a written answer hides.

What makes a subnet public?

Its route table has a route to an internet gateway. Not its name, not its security group, not whether instances in it have public addresses.

Name the five conditions for a browser to load a web page from a server in your own VPC.

The instance has a public IPv4 address; the subnet’s route table sends 0.0.0.0/0 to an attached internet gateway; the subnet’s network ACL allows the request in and the reply out; the instance’s security group allows the port inbound; and the server itself is listening on that port, with nothing on the instance such as an operating-system firewall blocking it.

How many usable addresses are in a `/24` subnet, and why not 256?
  1. AWS reserves the first four addresses (network, router, DNS, future use) and the last one (broadcast).
What is the local route?

The route every route table carries for the VPC’s own range, so resources inside the VPC can reach each other. It cannot be removed.

You enable auto-assign public IPv4 on a subnet. Does an instance already running there get an address?

No. The setting applies to instances launched afterwards; an already-running instance keeps the addressing it was launched with.

Why does a custom network ACL with only an inbound port 80 rule break a website?

Network ACLs are stateless. The reply to the browser leaves on an ephemeral port, and with no outbound rule allowing it, the custom ACL’s final deny rule drops it.

Why does a security group need no rule for that reply?

It is stateful: it tracks the allowed request and lets the response out regardless of the outbound rules.

What source do you use to allow EC2 Instance Connect from the console, and only it?

The managed prefix list com.amazonaws.<region>.ec2-instance-connect, on TCP port 22, instead of 0.0.0.0/0.

Which two things in a network build cost money even when idle?

A NAT gateway, charged per hour it exists plus per gigabyte, and a public IPv4 address, charged per hour whether in use or idle.

Why does Delete VPC refuse while an instance still runs in it?

Its network interface still sits in the subnet, and the Delete your VPC page requires EC2 instances in the VPC to be terminated before the VPC can be deleted.

When you delete a VPC from the console, what goes with it?

Its subnets, route tables, internet gateways, security groups and network ACLs, among others. Instances and NAT gateways do not; you remove those first.

Which comes first from the CLI: detaching the internet gateway or deleting the VPC?

Detaching, then deleting the gateway, then deleting the VPC. A VPC with an attached gateway cannot be deleted.

Model answer

The question: “You launched a web server into a VPC you built yourself and the page times out. Walk me through how you find the cause.”

There are six beats, and they come in this order. Missing any one of them is a failure state rather than a stylistic gap: each of the first five is one of the conditions a request has to pass, the sixth is the step that proves the fix, and an answer that skips one has not located the fault.

  1. Address — the instance has a public IPv4 address.
  2. Route — the route table associated with the subnet sends 0.0.0.0/0 to an attached internet gateway.
  3. Subnet guard — the network ACL allows the port inbound and the reply’s ephemeral ports outbound.
  4. Door guard — the security group allows the port inbound from where you are testing.
  5. Server — a web server is listening on the port and nothing on the instance blocks it.
  6. Proof — change one thing, test again from outside, and remove anything you opened only to diagnose.

Spoken, the answer sounds like this:

“A timeout with no error usually means the request never reached anything that could refuse it, so I walk the path in order. First, the address: does the instance actually have a public IPv4 address? If it was launched into a subnet without auto-assign, it has none, and nothing else matters yet. Second, the route: I open the route table associated with that subnet — not the main one by assumption — and look for 0.0.0.0/0 pointing at an internet gateway attached to this VPC. Third, the subnet guard: the network ACL is stateless, so I check port 80 inbound and the ephemeral ports outbound for the reply. Fourth, the door guard: the security group needs an inbound rule for port 80 from where I am testing. Fifth, the server: I connect with EC2 Instance Connect and check that the web server is running and listening on port 80, and that no firewall on the instance drops the request. Finally, the proof: I change exactly one thing, test again from outside, say what changed, and remove anything I opened just to diagnose, such as SSH from anywhere.”

Beat six is the one most answers drop. Without it, a fix is a guess that happened to coincide with the page loading, and a diagnostic rule left open is a new problem you created while solving the old one.

Why this matters

  • “It works in the default VPC but not in ours.” Teams move a service from the default VPC into a network built for production, and it stops answering. The conditions, checked in order, find the gap in minutes rather than an afternoon.
  • A database that is reachable from the internet. Someone puts a database in a subnet whose route table sends 0.0.0.0/0 to an internet gateway, and opens its port “temporarily”. Knowing that the route table, not the subnet’s name, makes a subnet public is how you spot this in a review.
  • A bill for a network nobody is using. A practice VPC built with the VPC and more option left a NAT gateway running; a forgotten Elastic IP address kept being charged after its instance was gone. Both are invisible in day-to-day use and obvious in a teardown checklist.
  • A firewall change that breaks replies. Someone tightens a network ACL with an inbound allow rule and no outbound rule. Requests arrive and replies are dropped. Knowing stateless from stateful turns this from a mystery into a one-line fix.

After this unit

The project for this unit is A Network You Can Build, Prove and Remove (project.md). You build hoc-vpc by hand, launch a web server into its public subnet, break and repair one condition at a time while recording what each failure looked like, and finish by tearing everything down and capturing the empty command output that proves nothing is left.

Unit 6 stores data in Amazon DynamoDB. You will not need a VPC for it: your code reaches DynamoDB through an AWS API, and who may use the table is decided by IAM permissions rather than by a subnet and a firewall. Having built a network by hand, you will see clearly what that managed service takes off your hands.

Sources

Every AWS behaviour, console label, default and price in these notes was checked against the pages below.

Project

Hands-on Project — A Network You Can Build, Prove and Remove

Objective

Build a VPC with one public subnet by hand, put a web server in it, break each of the conditions for reachability one at a time and record what each failure looks like, then tear the whole network down and capture the output that proves nothing is left running. The point is not the network. The point is that you finish holding a diagnosis order you have watched work, and a teardown you can prove — the same order the model answer in the notes walks through.

What you need: an AWS account with a budget alert, an everyday administrator sign-in that is not the root user, and the AWS CLI version 2 signed in with short-lived credentials (aws sts get-caller-identity must print your account ID). Units 1 and 2 set these up. If you are starting here, follow If you are starting here under Before you start in this unit’s notes: it creates the account, the budget and the administrator identity, then signs the CLI in with aws login, which needs AWS CLI version 2.32.0 or later (Sign in with aws login).

What costs money. An instance is charged while it is running, and AWS charges for every public IPv4 address, in use or idle (Amazon VPC pricing). On the Free account plan, instance types marked Free tier eligible are covered by your Free Tier credits (Track your Free Tier usage for Amazon EC2). The VPC, subnet, route table, internet gateway and security group carry no charge of their own (Enable internet access for a VPC using an internet gateway; Control traffic to your AWS resources using security groups). Nothing in this project creates a NAT gateway or an Elastic IP address. Task 3 creates nothing new.

Conventions for every task:

  • Region ap-south-1, Availability Zone ap-south-1a.
  • Every resource carries the tag project = hands-on-cloud, plus a Name tag as listed.
  • Every output file is plain text in the shape given. Where a shape is given, follow it exactly.

Task 1 — Build the network by hand

Scope: one VPC, one subnet, one internet gateway, one custom route table, one security group. Use the VPC only option. Do not use VPC and more, which can add NAT gateways.

  1. VPC. In the VPC console choose Create VPC, then VPC only. Name tag hoc-vpc, IPv4 CIDR block 10.0.0.0/16 (manual input), no IPv6, tenancy Default. Add the project tag.

  2. Subnet. Subnets → Create subnet. VPC hoc-vpc, subnet name hoc-public-a, Availability Zone ap-south-1a, IPv4 subnet CIDR block 10.0.1.0/24. Then select it and choose Actions → Edit subnet settings → Enable auto-assign public IPv4 address, and save.

  3. Internet gateway. Internet gateways → Create internet gateway, name hoc-igw. Then Actions → Attach to VPC and choose hoc-vpc.

  4. Route table. Route tables → Create route table, name hoc-public-rt, VPC hoc-vpc. On its Routes tab choose Edit routes → Add route: destination 0.0.0.0/0, target the internet gateway hoc-igw. Save. On its Subnet associations tab, associate hoc-public-a. Leave the main route table untouched, so that it stays private.

  5. Security group. Security groups → Create security group, name hoc-web-sg, description web server for hands-on cloud, VPC hoc-vpc. Inbound rules:

    • type HTTP, port 80, source 0.0.0.0/0;
    • type SSH, port 22, source the prefix list com.amazonaws.ap-south-1.ec2-instance-connect.

    Leave the outbound rule as created. Do not add SSH from 0.0.0.0/0.

Record the IDs the console shows you in a file called network.txt, one per line, in this shape:

vpc: vpc-...
subnet: subnet-...
igw: igw-...
route-table: rtb-...
security-group: sg-...

Check your work by printing the route table’s routes from the CLI and confirming there are exactly two — the local route for 10.0.0.0/16, and 0.0.0.0/0 to your internet gateway:

aws ec2 describe-route-tables --route-table-ids <your rtb id> --query "RouteTables[].Routes[]" --output table

Time budget: 45 minutes

Output: network.txt with five lines in the shape above, and the route table output showing the two routes.


Task 2 — Put a web server in it

Scope: one instance, one page. Stop once the page loads from your own browser.

  1. In the EC2 console choose Launch instance. Name hoc-web; add the project tag. AMI: the Amazon Linux 2023 AMI under Quick Start marked Free tier eligible. Instance type: one marked Free tier eligible, such as t3.micro. Key pair: Proceed without key pair (Not recommended) is acceptable here, because you will connect only through the EC2 console with EC2 Instance Connect.

  2. Under Network settings choose Edit: VPC hoc-vpc, subnet hoc-public-a, Auto-assign public IP Enable, Select existing security group hoc-web-sg.

  3. Under Advanced details → User data, paste:

    #cloud-config
    packages:
    - httpd
    runcmd:
    - systemctl start httpd
    - systemctl enable httpd
    - [ sh, -c, 'echo "<h1>hoc-web is inside hoc-vpc</h1>" > /var/www/html/index.html' ]

    This is the cloud-init form the EC2 documentation uses for Amazon Linux 2023. User data runs once, at first boot, as root.

  4. Launch. When the instance is running and its status checks pass, open http://<public IPv4 address>/ in your browser. If the page does not load, connect with EC2 Instance Connect and read /var/log/cloud-init-output.log: until cloud-init has finished installing and starting httpd, nothing is listening on port 80.

  5. From your own computer, confirm with:

    curl -s http://<public IPv4 address>/

Time budget: 30 minutes

Output: the curl output showing the <h1> line, and one added line in network.txt: instance: i-....


Task 3 — Break it one condition at a time

Scope: three breaks, each undone before the next. Stop once all three rows are filled.

For each row, make exactly the change described, test from your computer with the curl command from Task 2 (add --max-time 10 so a timeout ends), record what you saw, then undo the change and confirm the page loads again before moving on.

# Break How to undo it
1 In hoc-public-rt, delete the 0.0.0.0/0 route Add the route back, target hoc-igw
2 In hoc-web-sg, delete the HTTP inbound rule Add it back: HTTP, port 80, 0.0.0.0/0
3 Disassociate hoc-public-a from hoc-public-rt (it falls back to the main route table) Associate it with hoc-public-rt again

Write breaks.txt with exactly four lines. The first three record the breaks, one per row, in this shape:

<row> | <result> | <check> | restored: yes
  • <row> is 1, 2 or 3.
  • <result> is exactly one of: page, timeout, refused, error — what curl did during the break. page means the <h1> line printed; timeout means curl gave up after --max-time 10; refused means curl reported the connection was refused; error means anything else.
  • <check> is exactly one of: address, route, subnet-guard, door-guard, server — the step in the notes’ diagnosis order that would have found this break.

The fourth line names the rows whose <result> was the same, in this shape:

same-result: <row>,<row>[,<row>]

or same-result: none if all three differed.

Time budget: 30 minutes

Output: breaks.txt with four lines in the shape above.


Task 4 — Tear it down and prove it

Scope: everything from Tasks 1 and 2, removed, and four empty outputs. This task is not optional.

  1. In the EC2 console, select hoc-web and choose Instance state → Terminate instance. Wait until its state is terminated.

  2. In the VPC console, choose Your VPCs, select hoc-vpc, and choose Actions → Delete VPC. Read the list the console shows: if it names anything that must be removed first, remove it and try again. When it lists only what it will delete with the VPC — the subnet, route table, internet gateway and security group — type delete and confirm.

  3. Run these four commands in ap-south-1. Each one looks only at resources tagged project = hands-on-cloud, so resources that belong to anything else in your account are never listed. Each must print nothing:

    aws ec2 describe-instances --filters "Name=tag:project,Values=hands-on-cloud" "Name=instance-state-name,Values=pending,running,stopping,stopped" --query "Reservations[*].Instances[*].[InstanceId]" --output text
    aws ec2 describe-vpcs --filters "Name=tag:project,Values=hands-on-cloud" --query "Vpcs[*].[VpcId]" --output text
    aws ec2 describe-nat-gateways --filter "Name=tag:project,Values=hands-on-cloud" "Name=state,Values=pending,available" --query "NatGateways[*].[NatGatewayId]" --output text
    aws ec2 describe-addresses --filters "Name=tag:project,Values=hands-on-cloud" --query "Addresses[*].[PublicIp]" --output text

    Note the spelling: describe-nat-gateways takes --filter; the other three take --filters. If a command prints an ID or an address, it is a resource you tagged for this course: remove that resource, then run all four again.

Teardown checklist — tick each before you stop:

  • hoc-web is terminated
  • hoc-vpc is deleted, and with it hoc-public-a, hoc-public-rt, hoc-igw and hoc-web-sg
  • No NAT gateway tagged project = hands-on-cloud is pending or available
  • No Elastic IP address tagged project = hands-on-cloud is allocated
  • All four commands above printed nothing

Time budget: 15 minutes

Output: teardown.txt containing the four commands and, under each, its (empty) output, plus the ticked checklist.


What this feeds

Keep teardown.txt. Every remaining unit ends with the same kind of proof, and Unit 8 ends the course with one that covers everything at once. Unit 6 starts with a service that needs no network of your own at all — a DynamoDB table — so the first thing to notice there is which of the five resources you built today it does not ask you for.


Sources

Quiz

Online marking is not open yet. Work through the questions and check the written ones against the criteria printed with each question. The answer key is kept back for now.

Quiz — Unit 5: Your Own Network: VPC Basics

Instructions: Ten questions in two parts, and both parts are scored.

  • Questions 1–8 are multiple choice. Pick one option per question. They are marked by comparing your letter against the key.
  • Questions 9–10 ask you to write a short answer in a stated format. Each is marked by a grader that runs fixed checks on what you submit; the checks and the marking rubric are held in the answer key, not here.

Work closed-book on the whole quiz. Submit plain text exactly in the format each question states.

Every question uses the network from this unit: VPC hoc-vpc with range 10.0.0.0/16, public subnet hoc-public-a with range 10.0.1.0/24, internet gateway hoc-igw, route table hoc-public-rt, security group hoc-web-sg, and a web server hoc-web, all in Region ap-south-1.


1. What makes a subnet a public subnet?

a) Auto-assign public IPv4 is enabled on it, so that every new instance launched there is given an address b) Its security group has an inbound rule from 0.0.0.0/0, so traffic from any internet address can arrive c) The route table associated with it has a route whose target is an internet gateway attached to the VPC d) Its Name tag contains the word public, which the console reads when it decides where gateway routes go


2. You launched hoc-web into hoc-public-a before turning on auto-assign public IPv4 for the subnet. The route table and the security group are both correct, but the page times out. Which action fixes it?

a) Launch a new instance into the subnet with Auto-assign public IP set to Enable, then terminate the old one b) Add a route to the subnet’s route table that sends 10.0.0.0/16 traffic to the internet gateway as well c) Turn on auto-assign public IPv4 for the subnet now, which gives the running instance an address at once d) Attach another internet gateway to the VPC, so that this instance gets a path to the internet of its own


3. hoc-web-sg allows inbound HTTP on port 80 from 0.0.0.0/0. You delete every outbound rule from it. What happens when a browser requests the page?

a) The request is dropped on arrival, because a security group needs an outbound rule before it accepts traffic b) The request arrives but the reply is dropped, because no outbound rule allows the browser’s ephemeral port c) The request is refused with an error page, because the web server detects that it cannot send traffic out d) The page still loads, because the security group tracks the allowed request and lets its reply out again


4. You replace the subnet’s network ACL with a custom one whose only added rule is inbound rule 100: allow TCP port 80 from 0.0.0.0/0. The outbound side has only the default deny. What does a browser see?

a) The page loads, because the network ACL remembers the inbound request and lets the reply leave the subnet b) The page times out, because the reply to the browser’s ephemeral port matches no outbound rule and is denied c) The page loads, because a security group that allows port 80 overrides the subnet’s network ACL for it d) An error page from the gateway, because a custom network ACL cannot be associated with a public subnet


5. How many addresses in the subnet 10.0.1.0/24 can be assigned to your instances?

a) 256, because a /24 leaves eight bits free and every combination of them is an address you may use b) 254, because only the network address and the broadcast address are held back, as on most networks c) 255, because AWS keeps only the first address of the range for the VPC router and leaves you the rest d) 251, because AWS reserves the first four addresses and the last address in every subnet you create


6. You finish practising and leave some resources behind. Which one keeps being charged even though nothing is using it?

a) The internet gateway, because it is billed for every hour that it stays attached to a VPC of yours b) The custom route table, because each route pointing at a gateway is billed as a resource of its own c) An Elastic IP address, because every public IPv4 address is charged whether it is in use or idle d) The security group, because rules allowing traffic from 0.0.0.0/0 are billed as internet access


7. You choose Delete VPC for hoc-vpc while hoc-web is still running in it. What happens?

a) The console lists the instance as something to terminate first, since it holds a network interface there b) The VPC is deleted and the instance keeps running, since an instance is independent of the network it uses c) The VPC and the instance are both deleted, since deleting a VPC from the console removes all inside it d) The deletion goes through once you detach the gateway, since the gateway is all that a VPC depends on


8. The VPC and more option on the Create VPC page offers NAT gateways. Why does this unit’s build leave that setting at None?

a) A NAT gateway is required for a public subnet, so choosing None would stop the web server reaching the internet b) A NAT gateway is charged for every hour it exists, and this build has no private subnet that needs outbound access c) A NAT gateway replaces the internet gateway, so choosing one would remove the route that makes the subnet public d) A NAT gateway lets the internet start connections to private instances, so choosing one would expose the server


Part 2 — Constructed response

Submit plain text exactly in the format each question states, with no surrounding quotes and no extra commentary.


9. You want a second subnet in hoc-vpc, named hoc-public-b. Write one IPv4 CIDR block for it that meets all of these requirements:

  • AWS would accept it as a subnet of hoc-vpc;
  • it does not overlap hoc-public-a;
  • it leaves at least 100 addresses that can be assigned to instances.

Format: one CIDR block on one line, in the form a.b.c.d/n.


10. Write the complete set of inbound rules for hoc-web-sg so that:

  • anyone on the internet can load the web page over HTTP;
  • you can open a terminal on hoc-web with EC2 Instance Connect from the console in ap-south-1;
  • no other inbound connection to the instance is allowed.

Format: one rule per line, each in the form

tcp <port> <source>

where <source> is either an IPv4 CIDR block or the name of an AWS-managed prefix list.


Sources

The AWS behaviour these questions test is taught in this unit’s notes, from these pages:

TechEazy Consulting training material — not affiliated with or endorsed by Amazon Web Services (AWS).