SAA-C03 Intermediate 40 min

Build a VPC with Public and Private Subnets

Design and build a production-ready 2-tier VPC across 2 AZs with proper routing, NAT Gateway, and security controls.

Amazon VPCIGWNAT GatewayRoute TablesSecurity Groups
Progress: 0 / 7 steps
Step 1
Create Custom VPC

1. VPC Console → Your VPCs → Create VPC
2. Name: lab-vpc
3. IPv4 CIDR: 10.0.0.0/16
4. Tenancy: Default
5. Create VPC

Note: This gives you 65,536 IP addresses.

Tip: Plan your CIDR carefully. Never overlap with on-premises or other VPCs you will peer with.
Step 2
Create 4 Subnets

Create these 4 subnets in lab-vpc:

1. public-1a: CIDR 10.0.1.0/24, AZ: us-east-1a
2. public-1b: CIDR 10.0.2.0/24, AZ: us-east-1b
3. private-1a: CIDR 10.0.10.0/24, AZ: us-east-1a
4. private-1b: CIDR 10.0.20.0/24, AZ: us-east-1b

For each public subnet: Edit subnet settings → Enable auto-assign public IPv4

Tip: AWS reserves 5 IPs per subnet: .0 (network), .1 (VPC router), .2 (DNS), .3 (future), .255 (broadcast).
Step 3
Create and Attach Internet Gateway

1. VPC → Internet Gateways → Create
2. Name: lab-igw → Create
3. Actions → Attach to VPC → lab-vpc → Attach

Status changes to: Attached

Tip: One IGW per VPC. IGW is horizontally scaled, redundant, and HA by default. No bandwidth limits.
Step 4
Create Route Tables

Public Route Table:
1. Create route table: public-rt, lab-vpc
2. Routes → Edit → Add: 0.0.0.0/0 → lab-igw
3. Subnet associations → Add public-1a + public-1b

Private Route Table:
1. Create: private-rt, lab-vpc
2. Associate private-1a + private-1b
(No internet route yet)

Tip: The main route table default allows only local (10.0.0.0/16) traffic. Custom route tables needed for internet.
Step 5
Create NAT Gateway

1. VPC → NAT Gateways → Create
2. Subnet: public-1a (MUST be PUBLIC subnet!)
3. Connectivity: Public
4. Elastic IP: Allocate
5. Create → Wait for Status: Available (~2 min)

Tip: NAT Gateway costs ~$0.045/hr + $0.045/GB. Always delete after labs to avoid charges!
Step 6
Add NAT Route to Private Subnets

1. Select private-rt
2. Routes → Edit routes → Add route
3. Destination: 0.0.0.0/0 → Target: NAT Gateway → your NAT GW
4. Save changes

Verify architecture:
- public-1a/1b → route to IGW (bi-directional internet)
- private-1a/1b → route via NAT GW (outbound only)

Tip: Private instances can now do: yum update, call APIs, download packages. But internet cannot reach them inbound.
Step 7
Clean Up (in order!)

Delete in this order:
1. NAT Gateway → wait ~1 min for deletion
2. Release Elastic IP (VPC → Elastic IPs)
3. Delete subnets (all 4)
4. Detach Internet Gateway → Delete IGW
5. Delete route tables (public-rt, private-rt)
6. Delete VPC

Tip: Order matters. Deleting VPC before NAT Gateway/IGW will fail. Always NAT GW first.