contentintech
Learn/cloud/Cloud Networking
Advanced~20 min read

Cloud Networking

VPC design, subnets, routing, security groups, load balancing, VPN, peering, and private connectivity across clouds.

VPCSubnetsLoad BalancingPeering

The Virtual Private Cloud (VPC)

A VPC is a logically isolated, software-defined network inside a cloud provider. You control its private IP range (a CIDR block), carve it into subnets, define routing, and attach gateways. Everything else — VMs, load balancers, databases — lives inside the VPC's address space.

A subtle but important difference: AWS and Azure VPCs/VNets are regional and subnets are zonal (AZ-scoped), while a GCP VPC is global with regional subnets. This shapes how you design multi-region networks.

ConceptAWSAzureGCP
NetworkVPC (regional)VNet (regional)VPC (global)
Stateful firewallSecurity GroupNSGFirewall rules
Stateless ACLNetwork ACLNSG rulesHierarchical policy
Outbound NATNAT GatewayNAT GatewayCloud NAT
Private linkPrivateLinkPrivate EndpointPrivate Service Connect

Subnets & CIDR Planning

Subnets divide the VPC CIDR into smaller ranges, typically split into public (route to an internet gateway) and private (no direct inbound from the internet). Plan CIDRs so ranges never overlap — overlapping ranges make peering and VPN impossible later.

bash
# AWS: create a VPC and two subnets
aws ec2 create-vpc --cidr-block 10.0.0.0/16
aws ec2 create-subnet --vpc-id vpc-abc --cidr-block 10.0.1.0/24 \
  --availability-zone us-east-1a           # public
aws ec2 create-subnet --vpc-id vpc-abc --cidr-block 10.0.2.0/24 \
  --availability-zone us-east-1b           # private

# GCP: custom-mode VPC with a regional subnet
gcloud compute networks create prod-vpc --subnet-mode=custom
gcloud compute networks subnets create web-subnet \
  --network=prod-vpc --range=10.10.0.0/24 --region=us-central1

CIDR Sizing

A /24 yields 256 addresses, but the cloud reserves a few per subnet (AWS reserves 5, so a /24 gives 251 usable). Leave room to grow — resizing a live subnet is painful.

Routing & Internet Access

A route table decides where packets go for a destination CIDR. Public subnets route 0.0.0.0/0 to an internet gateway. Private subnets send outbound traffic through a NAT gateway so instances get updates without being reachable from the internet.

bash
# AWS: internet gateway + default route for the public subnet
aws ec2 create-internet-gateway
aws ec2 attach-internet-gateway --vpc-id vpc-abc --internet-gateway-id igw-123
aws ec2 create-route --route-table-id rtb-pub \
  --destination-cidr-block 0.0.0.0/0 --gateway-id igw-123

# NAT for private egress
aws ec2 create-nat-gateway --subnet-id subnet-public --allocation-id eipalloc-1
aws ec2 create-route --route-table-id rtb-priv \
  --destination-cidr-block 0.0.0.0/0 --nat-gateway-id nat-123

Security Groups vs Network ACLs

These two layers are frequently confused. Both filter traffic, but at different scopes and with different behavior.

PropertySecurity GroupNetwork ACL
ScopeInstance / ENISubnet
StateStateful (return allowed)Stateless (both directions)
RulesAllow onlyAllow and deny
EvaluationAll rules togetherOrdered by rule number
bash
# AWS security group allowing HTTPS from anywhere, SSH from an office IP
aws ec2 create-security-group --group-name web-sg --vpc-id vpc-abc
aws ec2 authorize-security-group-ingress --group-id sg-1 \
  --protocol tcp --port 443 --cidr 0.0.0.0/0
aws ec2 authorize-security-group-ingress --group-id sg-1 \
  --protocol tcp --port 22 --cidr 203.0.113.10/32

Load Balancing

Load balancers spread traffic across healthy backends. Choose by OSI layer: Layer 7 (HTTP/HTTPS, path- and host-based routing, TLS termination) or Layer 4 (TCP/UDP, ultra-low latency, preserves client IP).

TypeAWSGCP
L7 / HTTPApplication LB (ALB)Global External Application LB
L4 / TCPNetwork LB (NLB)Network LB
bash
# GCP: health check backing a load balancer backend
gcloud compute health-checks create http hc-web \
  --port=80 --request-path=/healthz \
  --check-interval=5s --unhealthy-threshold=3

Connecting Networks

Real architectures span multiple VPCs, accounts, and on-prem sites. The main options:

  • VPC Peering — private routing between two VPCs; non-transitive, needs non-overlapping CIDRs.
  • Transit hub — AWS Transit Gateway / Azure Virtual WAN / GCP Network Connectivity Center for hub-and-spoke at scale.
  • Site-to-site VPN — encrypted IPsec tunnels over the internet to on-prem.
  • Dedicated interconnect — Direct Connect / ExpressRoute / Cloud Interconnect for private, high-bandwidth links.
  • Private endpoints — PrivateLink / Private Service Connect to reach a managed service without traversing the internet.
bash
# GCP VPC peering between two networks (must be created on both sides)
gcloud compute networks peerings create prod-to-shared \
  --network=prod-vpc --peer-network=shared-vpc \
  --export-custom-routes --import-custom-routes

Peering Is Not Transitive

If A peers with B and B peers with C, A still cannot reach C. For any-to-any connectivity across many VPCs, use a transit gateway / hub instead of a mesh of peerings.

DNS & Private Resolution

Cloud DNS services (Route 53, Azure DNS, Cloud DNS) host public zones and private zones resolvable only inside your VPC. Private zones let internal services use friendly names like db.internal.example.com without exposing them publicly.

Practice Exercises

  1. Design a 10.0.0.0/16 VPC with two public and two private /24 subnets across two AZs, with no overlap.
  2. Attach an internet gateway to the public subnets and a NAT gateway so private instances can reach the internet outbound only.
  3. Write security group rules that allow HTTPS from the internet to a web tier, but only allow the web tier to reach the database port.
  4. Stand up a Layer 7 load balancer with a health check on /healthz in front of two backend instances.
  5. Peer two VPCs with non-overlapping ranges and verify a VM in one can ping a VM in the other, then confirm peering is non-transitive with a third VPC.
  6. Create a private DNS zone and resolve an internal hostname from inside the VPC but confirm it is not resolvable publicly.

Section navigation