Build a VPC with Public and Private Subnets
Design and build a production-ready 2-tier VPC across 2 AZs with proper routing, NAT Gateway, and security controls.
1. VPC Console → Your VPCs → Create VPC
2. Name: lab-vpc
3. IPv4 CIDR: 10.0.0.0/16
4. Tenancy: Default
5. Create VPC
Note: This gives you 65,536 IP addresses.
Create these 4 subnets in lab-vpc:
1. public-1a: CIDR 10.0.1.0/24, AZ: us-east-1a
2. public-1b: CIDR 10.0.2.0/24, AZ: us-east-1b
3. private-1a: CIDR 10.0.10.0/24, AZ: us-east-1a
4. private-1b: CIDR 10.0.20.0/24, AZ: us-east-1b
For each public subnet: Edit subnet settings → Enable auto-assign public IPv4
1. VPC → Internet Gateways → Create
2. Name: lab-igw → Create
3. Actions → Attach to VPC → lab-vpc → Attach
Status changes to: Attached
Public Route Table:
1. Create route table: public-rt, lab-vpc
2. Routes → Edit → Add: 0.0.0.0/0 → lab-igw
3. Subnet associations → Add public-1a + public-1b
Private Route Table:
1. Create: private-rt, lab-vpc
2. Associate private-1a + private-1b
(No internet route yet)
1. VPC → NAT Gateways → Create
2. Subnet: public-1a (MUST be PUBLIC subnet!)
3. Connectivity: Public
4. Elastic IP: Allocate
5. Create → Wait for Status: Available (~2 min)
1. Select private-rt
2. Routes → Edit routes → Add route
3. Destination: 0.0.0.0/0 → Target: NAT Gateway → your NAT GW
4. Save changes
Verify architecture:
- public-1a/1b → route to IGW (bi-directional internet)
- private-1a/1b → route via NAT GW (outbound only)
Delete in this order:
1. NAT Gateway → wait ~1 min for deletion
2. Release Elastic IP (VPC → Elastic IPs)
3. Delete subnets (all 4)
4. Detach Internet Gateway → Delete IGW
5. Delete route tables (public-rt, private-rt)
6. Delete VPC