Quick reference for VPC/subnet CLI, firewall rules, routing, load balancers, peering, and connectivity options.
VPCSubnetsLoad BalancingPeering
VPC & Subnets
# AWS
aws ec2 create-vpc --cidr-block 10.0.0.0/16
aws ec2 create-subnet --vpc-id vpc-abc \
--cidr-block 10.0.1.0/24 --availability-zone us-east-1a
# GCP (custom mode)
gcloud compute networks create prod-vpc --subnet-mode=custom
gcloud compute networks subnets create web-subnet \
--network=prod-vpc --range=10.10.0.0/24 --region=us-central1
CIDR Quick Sizes
| CIDR | Addresses |
| /16 | 65,536 |
| /20 | 4,096 |
| /24 | 256 (251 usable on AWS) |
| /28 | 16 |
Routing & NAT
# Internet gateway + default route (public)
aws ec2 attach-internet-gateway --vpc-id vpc-abc --internet-gateway-id igw-1
aws ec2 create-route --route-table-id rtb-pub \
--destination-cidr-block 0.0.0.0/0 --gateway-id igw-1
# NAT for private egress
aws ec2 create-route --route-table-id rtb-priv \
--destination-cidr-block 0.0.0.0/0 --nat-gateway-id nat-1
Firewall
# AWS security group ingress
aws ec2 authorize-security-group-ingress --group-id sg-1 \
--protocol tcp --port 443 --cidr 0.0.0.0/0
# GCP firewall rule
gcloud compute firewall-rules create allow-https \
--network=prod-vpc --allow=tcp:443 --source-ranges=0.0.0.0/0
SG vs NACL
| Security Group | NACL |
| Scope | Instance | Subnet |
| State | Stateful | Stateless |
| Rules | Allow only | Allow + deny |
Load Balancing
# GCP health check
gcloud compute health-checks create http hc-web \
--port=80 --request-path=/healthz \
--check-interval=5s --unhealthy-threshold=3
| Layer | Use |
| L7 (HTTP) | Path/host routing, TLS termination |
| L4 (TCP/UDP) | Low latency, preserves client IP |
Connectivity
| Option | Use for |
| VPC Peering | 2 VPCs, non-transitive |
| Transit GW / Hub | Any-to-any at scale |
| Site-to-site VPN | Encrypted link to on-prem |
| Interconnect | Dedicated private bandwidth |
| PrivateLink / PSC | Reach a service privately |
# GCP peering (create on both sides)
gcloud compute networks peerings create a-to-b \
--network=vpc-a --peer-network=vpc-b
Cross-Cloud Map
| AWS | Azure | GCP |
| VPC | VNet | VPC (global) |
| NAT Gateway | NAT Gateway | Cloud NAT |
| Transit Gateway | Virtual WAN | Network Connectivity Center |
| Direct Connect | ExpressRoute | Cloud Interconnect |
| Route 53 | Azure DNS | Cloud DNS |