The Virtual Private Cloud (VPC)
A VPC is a logically isolated, software-defined network inside a cloud provider. You control its private IP range (a CIDR block), carve it into subnets, define routing, and attach gateways. Everything else — VMs, load balancers, databases — lives inside the VPC's address space.
A subtle but important difference: AWS and Azure VPCs/VNets are regional and subnets are zonal (AZ-scoped), while a GCP VPC is global with regional subnets. This shapes how you design multi-region networks.
| Concept | AWS | Azure | GCP |
|---|---|---|---|
| Network | VPC (regional) | VNet (regional) | VPC (global) |
| Stateful firewall | Security Group | NSG | Firewall rules |
| Stateless ACL | Network ACL | NSG rules | Hierarchical policy |
| Outbound NAT | NAT Gateway | NAT Gateway | Cloud NAT |
| Private link | PrivateLink | Private Endpoint | Private Service Connect |
Subnets & CIDR Planning
Subnets divide the VPC CIDR into smaller ranges, typically split into public (route to an internet gateway) and private (no direct inbound from the internet). Plan CIDRs so ranges never overlap — overlapping ranges make peering and VPN impossible later.
# AWS: create a VPC and two subnets
aws ec2 create-vpc --cidr-block 10.0.0.0/16
aws ec2 create-subnet --vpc-id vpc-abc --cidr-block 10.0.1.0/24 \
--availability-zone us-east-1a # public
aws ec2 create-subnet --vpc-id vpc-abc --cidr-block 10.0.2.0/24 \
--availability-zone us-east-1b # private
# GCP: custom-mode VPC with a regional subnet
gcloud compute networks create prod-vpc --subnet-mode=custom
gcloud compute networks subnets create web-subnet \
--network=prod-vpc --range=10.10.0.0/24 --region=us-central1
CIDR Sizing
A /24 yields 256 addresses, but the cloud reserves a few per subnet (AWS reserves 5, so a /24 gives 251 usable). Leave room to grow — resizing a live subnet is painful.
Routing & Internet Access
A route table decides where packets go for a destination CIDR. Public subnets route 0.0.0.0/0 to an internet gateway. Private subnets send outbound traffic through a NAT gateway so instances get updates without being reachable from the internet.
# AWS: internet gateway + default route for the public subnet
aws ec2 create-internet-gateway
aws ec2 attach-internet-gateway --vpc-id vpc-abc --internet-gateway-id igw-123
aws ec2 create-route --route-table-id rtb-pub \
--destination-cidr-block 0.0.0.0/0 --gateway-id igw-123
# NAT for private egress
aws ec2 create-nat-gateway --subnet-id subnet-public --allocation-id eipalloc-1
aws ec2 create-route --route-table-id rtb-priv \
--destination-cidr-block 0.0.0.0/0 --nat-gateway-id nat-123
Security Groups vs Network ACLs
These two layers are frequently confused. Both filter traffic, but at different scopes and with different behavior.
| Property | Security Group | Network ACL |
|---|---|---|
| Scope | Instance / ENI | Subnet |
| State | Stateful (return allowed) | Stateless (both directions) |
| Rules | Allow only | Allow and deny |
| Evaluation | All rules together | Ordered by rule number |
# AWS security group allowing HTTPS from anywhere, SSH from an office IP
aws ec2 create-security-group --group-name web-sg --vpc-id vpc-abc
aws ec2 authorize-security-group-ingress --group-id sg-1 \
--protocol tcp --port 443 --cidr 0.0.0.0/0
aws ec2 authorize-security-group-ingress --group-id sg-1 \
--protocol tcp --port 22 --cidr 203.0.113.10/32
Load Balancing
Load balancers spread traffic across healthy backends. Choose by OSI layer: Layer 7 (HTTP/HTTPS, path- and host-based routing, TLS termination) or Layer 4 (TCP/UDP, ultra-low latency, preserves client IP).
| Type | AWS | GCP |
|---|---|---|
| L7 / HTTP | Application LB (ALB) | Global External Application LB |
| L4 / TCP | Network LB (NLB) | Network LB |
# GCP: health check backing a load balancer backend
gcloud compute health-checks create http hc-web \
--port=80 --request-path=/healthz \
--check-interval=5s --unhealthy-threshold=3
Connecting Networks
Real architectures span multiple VPCs, accounts, and on-prem sites. The main options:
- VPC Peering — private routing between two VPCs; non-transitive, needs non-overlapping CIDRs.
- Transit hub — AWS Transit Gateway / Azure Virtual WAN / GCP Network Connectivity Center for hub-and-spoke at scale.
- Site-to-site VPN — encrypted IPsec tunnels over the internet to on-prem.
- Dedicated interconnect — Direct Connect / ExpressRoute / Cloud Interconnect for private, high-bandwidth links.
- Private endpoints — PrivateLink / Private Service Connect to reach a managed service without traversing the internet.
# GCP VPC peering between two networks (must be created on both sides)
gcloud compute networks peerings create prod-to-shared \
--network=prod-vpc --peer-network=shared-vpc \
--export-custom-routes --import-custom-routes
Peering Is Not Transitive
If A peers with B and B peers with C, A still cannot reach C. For any-to-any connectivity across many VPCs, use a transit gateway / hub instead of a mesh of peerings.
DNS & Private Resolution
Cloud DNS services (Route 53, Azure DNS, Cloud DNS) host public zones and private zones resolvable only inside your VPC. Private zones let internal services use friendly names like db.internal.example.com without exposing them publicly.
Practice Exercises
- Design a
10.0.0.0/16VPC with two public and two private/24subnets across two AZs, with no overlap. - Attach an internet gateway to the public subnets and a NAT gateway so private instances can reach the internet outbound only.
- Write security group rules that allow HTTPS from the internet to a web tier, but only allow the web tier to reach the database port.
- Stand up a Layer 7 load balancer with a health check on
/healthzin front of two backend instances. - Peer two VPCs with non-overlapping ranges and verify a VM in one can ping a VM in the other, then confirm peering is non-transitive with a third VPC.
- Create a private DNS zone and resolve an internal hostname from inside the VPC but confirm it is not resolvable publicly.