AWS Networking Basics
Updated 2026-09-06
AWS BASIC · 01

AWS Networking Basics

Why use the cloud, and what its network looks like inside
Icon-Architecture-Group/32/Private-subnet_32
Why the cloudHow it differs from on-premises
AWS infrastructureData centers, Availability Zones, Regions
How to draw itCarve VPCs and subnets with CIDR.
01

On-premises

You buy the servers yourself

  • You pay up front for all you bought, used or not.
  • Run short, and you order more and wait for delivery.
02

Cloud

You rent the servers

  • Pay only for what you use.
  • Start with one server; scale up and down as needed.

What's different

—On-premisesCloud
CostLarge up-front spend (CapEx)Pay as you go (OpEx)
CapacityFixed at purchaseChange it when needed
Lead timeOrder · ship · installMinutes
UpkeepPower, cooling, repairs — all yoursAWS runs buildings and hardware
Going globalShip hardware into that countryJust pick a Region
© 2026 tiaz tiaz.dev 1/15
AWS Networking BasicsOn-premises — what hurts
03

Idle servers

Idle Capacity

  • On quiet days, the capacity you bought stays the same.
  • You can't shrink capacity you've bought.
  • Every unused bit is pure cost.
04

Peak days

Unmet Demand

  • Demand can exceed the capacity you bought.
  • Requests over that limit go unserved.
  • Ordering more still means waiting for delivery and install.

Paid up frontbefore a single server boots

Equipment
Servers, storage and network gear, bought in advance
Facilities
Rack space, power, cooling and lines cost extra
People
Installs, replacements, 3 a.m. outages — your job
Time
The wait from running short until new gear arrives

When on-premises still makes sense

  • When regulation dictates locationSome industries must keep data inside specific buildings.
  • Specialized hardwareSome work needs gear the cloud doesn't rent out.
  • Hardware you already ownServers not yet fully depreciated may be cheaper to keep.
© 2026 tiaz tiaz.dev 2/15
AWS Networking BasicsCloud — why use it
05

Elasticity

Growing and shrinking to follow demand

  • Elasticity means scaling up and back down.
  • No more guessing capacity in advance.

Six advantages of the cloudExam point

  • Trade fixed expense for variable expense
  • Benefit from massive economies of scale
  • Stop guessing capacity
  • Increase speed and agility
  • Stop spending money running data centers
  • Go global in minutes

Cloud isn't all-or-nothing. There are three deployment models: cloud runs everything in the cloud, hybrid works alongside existing hardware, and on-premises (private cloud) runs on your own gear only.

The cloud doesn't always cost less

  • Left running, it keeps billingYou pay for whatever is on, used or not.
  • Data transfer costsData coming in is mostly free; data going out is charged.
  • Moving as-is saves nothingMoved as-is, idle servers stay idle. You need the right architecture and ops.

Who handles whatExam point

—AWS's partYour part
NameSecurity of the cloudSecurity in the cloud
ProtectsFacilities · hardware · Regions · AZs · virtualizationGuest OS, patches · apps · data
NetworkPhysical links and everything belowSecurity groups · routing · what's open
© 2026 tiaz tiaz.dev 3/15
AWS Networking BasicsBottom up — server to Region
06

Data Center

One building packed with hundreds of servers

  • The cloud is still physical servers racked somewhere.
  • Each building has its own power, cooling and network.
07

Availability Zone

A group of nearby data centers

  • Designed with disasters in mind
  • Far enough apart that a power cut in one spares the rest (within 100 km of each other).
  • Yet close enough that latency goes unnoticed.
08

Region

A group of Availability Zones

  • Each Region has three or more AZs.
  • 39 Regions · 124 AZs worldwide (2026).
  • And still growing

How it stacks up

ServerOne physical machineData centerOne buildingAvailability ZoneAZ · within 100 kmRegion3+ AZs

All of this is built by AWS. What you build starts once you pick a Region.

© 2026 tiaz tiaz.dev 4/15
AWS Networking BasicsRegions — how to choose

Reading Region codesarea · direction · number

ap-northeast-1     Tokyo
ap-northeast-2     Seoul
ap-northeast-3     Osaka
us-east-1          N. Virginia

Area (ap · us · eu), then direction, then opening order in that area. Seoul is 2: Tokyo opened first.

Four factors in choosing a RegionExam point

  • Close to your usersDistance is latency. Serving Korea? Pick Seoul.
  • PricingThe same instance costs different amounts per Region.
  • Service availabilityNew services reach each Region at different times.
  • Compliance and data residencySome data must stay in the country.

Other forms of AWS infrastructurebeyond Regions and AZs

Local ZonesA Region extended closer to users. 46 sites
Wavelength ZonesInside carriers' 5G networks. 33 sites
OutpostsAWS hardware installed in your building
Edge locationsWhere CloudFront caches. 750+ sites
© 2026 tiaz tiaz.dev 5/15
AWS Networking BasicsAZs — names, distance, cost

Region and AZ pitfalls

  • Regions are isolatedCheck which Region you created a resource in.
  • a · b · c differ per accountThe physical zone behind us-east-1a is shuffled randomly per account. To line up two accounts, use the AZ ID (use1-az1), not the name.
  • Cross-AZ traffic costs moneyEven within a Region, $0.01/GB is charged in each direction (free within one AZ).
Different accounts, different zones. The AZ ID points to the same place across accounts.AWS docs: “Availability Zone IDs”

Using AZsExam point

  • Spread resources over two or moreIf one AZ goes down entirely, the service survives — the reason AZs exist.
  • One subnet per AZRedundancy starts with how you split subnets.
  • Across accountsThe console shows a·b·c. Use AZ IDs only to match zones with another account.
© 2026 tiaz tiaz.dev 6/15
AWS Networking BasicsTop down — Region to subnet
09

Working down

Pick a Region, create a VPC, split it into subnets

  • A VPC is created in one Region and can't leave it.
  • But it spans all AZs in that Region.
  • A subnet belongs to one AZ.
  • Sizes are assigned with CIDR.

What contains what

Region
3+ Availability Zones
Availability Zone
1+ data centers
VPC
One Region · all of its AZs
Subnet
One AZ · one VPC

Where services liveExam point

ScopeExamplesWhat it means
GlobalIAM · Route 53 · CloudFrontNo Region to pick. Same from every Region
RegionalS3 · VPC · DynamoDB · LambdaSpans all AZs in the Region
ZonalEC2 instances · EBS volumes · subnetsLives in one AZ. Goes down with it
© 2026 tiaz tiaz.dev 7/15
AWS Networking BasicsVPC — your isolated network
10

VPC

Virtual Private Cloud

  • A logically isolated virtual network in your account.
  • No outside traffic gets in until you open a door.

VPC rules

  • One RegionIt stays in the Region you create it in (but spans all its AZs).
  • Pick addresses from private rangesRFC 1918 — 10.0.0.0/8 · 172.16.0.0/12 · 192.168.0.0/16. AWS recommends these.
  • A default VPC already existsEvery account has one per Region, so you can launch instances right away.
  • 5 per RegionDefault quota. Request an increase to go up to hundreds.
  • The VPC itself is freeYou pay for services like NAT gateways, and for public IPv4 addresses.
11

VPC to VPC

Blocked by default

  • VPCs are fully isolated; servers in another VPC are out of reach.
  • To connect them, set up VPC peering or a Transit Gateway.
© 2026 tiaz tiaz.dev 8/15
AWS Networking BasicsSubnets — splitting a VPC
12

Subnet

A slice of the VPC's IP range

  • Carve a 10.0.0.0/16 VPC into pieces like 10.0.0.0/24.
  • Every server sits inside some subnet.

Subnet rulesExam point

  • One AZA subnet belongs to exactly one AZ. It can't span two.
  • Redundancy starts hereThe first step is one subnet in each AZ.
  • 200 per VPCDefault quota. Can be raised on request.
13

Subnet to subnet

Allowed within the same VPC

  • A new VPC's route table gets a local route for its whole range.
  • To block it, use security groups or network ACLs.

Public vs. private subnetsExam point

Public subnet
Its route table has a route to an internet gateway
Private subnet
No route to an internet gateway. Outbound traffic goes through NAT
What decides it
Not a creation option — just whether its route table has an internet gateway route!
© 2026 tiaz tiaz.dev 9/15
AWS Networking BasicsCIDR — reading addresses
14

CIDR

Classless Inter-Domain Routing

  • Notation for taking only what you need, no classes (1993).
  • Classful addressing forced blocks far bigger than needed.
15

Octet

8 bits, so 256 values

  • 8 bits can express 2⁸ = 256 numbers.
  • An IPv4 address is four octets
  • Four dot-separated numbers — four octets
  • 192.168.0.0
16

After the slash

Prefix — how many leading bits are fixed

  • The fixed front is the network; the rest are hosts in it.
  • With /24, the first 24 bits are fixed and the last 8 give 192.168.0.0 ~ 192.168.0.255.

Private IP rangesExam point

BlockRangeExample
10.0.0.0/810.0.0.0 ~ 10.255.255.25510.0.0.0/16
172.16.0.0/12172.16.0.0 ~ 172.31.255.255172.31.0.0/16
192.168.0.0/16192.168.0.0 ~ 192.168.255.255192.168.0.0/20
© 2026 tiaz tiaz.dev 10/15
AWS Networking BasicsCIDR — dividing a network

VPCs and subnets: /16 to /28Exam point

PrefixAddressesUsable IPs
/1665,53665,531
/204,0964,091
/24256251
/281611

Reserved addresses in a subnetfirst four and the last one

10.0.0.0     Network address
10.0.0.1     VPC router
10.0.0.2     DNS
10.0.0.3     Reserved (future use)
10.0.0.255   Broadcast

Before choosing a CIDR

  • Must fall inside the VPC rangeA 10.0.0.0/16 VPC can't hold a 192.168.0.0/24 subnet.
  • Subnets can't overlapEach address belongs to one subnet. Overlapping CIDRs are rejected.
  • Go big from the startSpare addresses cost nothing. /24 is a safe subnet size.

CIDR pitfalls

  • A CIDR can't be resized once setTo grow, add a secondary CIDR (5 per VPC); to shrink, you must create a new VPC.
  • Nothing smaller than /28Only 11 of 16 addresses are usable — already tight in practice.
© 2026 tiaz tiaz.dev 11/15
AWS Networking BasicsVPC addresses — what to pick

Ranges to avoid

  • Rejected outright0.0.0.0/8 · 127.0.0.0/8 · 169.254.0.0/16 · 224.0.0.0/4 can't be used for a VPC.
  • Avoid 172.17.0.0/16Services like Cloud9 and SageMaker use it. Overlap it and you can't connect to them.
A VPC with a secondary CIDR added. Only subnet C uses the new range — added, not resized.AWS docs: “VPC CIDR blocks”

How IPv6 differsyou can't pick the addresses

VPC
One /56 from Amazon. You can't choose which
Subnet
/64 — not split finely like IPv4
Reserved
Five, like IPv4 — first four, last one
Private ranges
None in IPv6. Routing decides what goes out
© 2026 tiaz tiaz.dev 12/15
AWS Networking BasicsRead it? Solve it

Try it!Practice

  1. 1A regulation says data must stay in the country. What is the first step to comply on AWS?

    1. AAvailability Zone
    2. BRegion
    3. CSubnet
    4. DVPC
  2. 2A 10.0.0.0/16 VPC in the Seoul Region gets one subnet in each of two AZs. Which subnet can't be made?

    1. A10.0.0.0/24 — ap-northeast-2a
    2. B10.0.1.0/24 — ap-northeast-2c
    3. C192.168.0.0/24 — ap-northeast-2a
    4. D10.0.2.0/28 — ap-northeast-2c
  3. 3Which two statements about Regions and AZs are true?2 answers

    1. AA subnet can span multiple AZs
    2. BA VPC exists within a single Region
    3. Cus-east-1a is the same physical zone in every account
    4. DRegions are isolated, so resources aren't replicated automatically
    5. EAn AZ is just another name for one data center
  4. 4At most how many EC2 instances fit in one 10.0.0.0/24 subnet?

    1. A256
    2. B255
    3. C254
    4. D251
Answers and explanations
  1. 1BThe Region decides which country the data is in. An AZ is a location inside the chosen Region, so it can't change the country; VPCs and subnets are drawn after the Region is chosen.
  2. 2CA subnet CIDR must sit inside the VPC CIDR. 192.168.0.0/24 is outside 10.0.0.0/16, so it's rejected. The other three are in range and don't overlap, and /28 is the smallest size allowed.
  3. 3B · DA subnet belongs to one AZ only, and the names a·b·c map randomly to physical zones per account (the AZ ID is what stays fixed). An AZ groups one or more data centers.
  4. 4DA /24 has 256 addresses, but AWS takes five in every subnet: the first four (network · VPC router · DNS · reserved) and the last (broadcast). The familiar 254 forgets three of those first four.
© 2026 tiaz tiaz.dev 13/15
AWS Networking BasicsKey points and terms

Numbers to rememberExam point

3Min AZs per RegionUsually more
100kmDistance between AZsKept no farther apart
/16Largest CIDR65,536 addresses
/28Smallest CIDR16 addresses
5Reserved per subnetFirst four and the last one
251Usable IPs in a /24256 − 5
5VPCs per RegionDefault quota, adjustable
200Subnets per VPCDefault quota, adjustable

Glossaryevery term on this sheet, one line each

Region A geographic group of 3+ AZs
Availability Zone (AZ) 1+ data centers, ≤100 km apart
AZ ID Same physical zone in any account (use1-az1)
VPC An isolated virtual network you create in a Region
Subnet A slice of a VPC. Lives in exactly one AZ
Public subnet Has a route to an internet gateway
CIDR Notation giving size after a slash
Prefix The number after the slash: fixed leading bits
Octet 8 bits. An IPv4 address is four octets
Private IP The 3 RFC 1918 ranges; not internet-routed
Elasticity Scaling up with demand, then back down
On-premises Buying servers and running them yourself

Up nextbuilding paths inside a VPC

Route tablesWhere traffic goes; decides public vs. private
Internet gatewayThe VPC's door to the internet
NAT gatewayOutbound-only exit for private subnets
Security groups · NACLsFirewalls in front of instances and of subnets
In one line

Data center → AZ → Region are the physical layers AWS builds; on top, you carve VPC → subnets with CIDR to draw your own network.

Data CenterAZRegionVPCSubnetCIDR
© 2026 tiaz tiaz.dev 14/15
AWS Networking BasicsReferences

Official sourcesAWS docs · standards · videos · articles

  • AWS Global Infrastructure — Regions and AZspp. 4 · 6 Source of 39 Regions · 124 AZs, 3+ AZs, and the 100 km figure aws.amazon.com/about-aws/global-infrastructure/regions_az
  • Six advantages of cloud computingp. 3 The six names, exactly as AWS words them docs.aws.amazon.com/whitepapers/latest/aws-overview/six-advantages-of-cloud-computing.html
  • Shared Responsibility Modelp. 3 The line between security of and in the cloud aws.amazon.com/compliance/shared-responsibility-model
  • Regions and Zones (EC2 User Guide)pp. 6 · 7 Region isolation, AZ codes, Local Zones and Outposts docs.aws.amazon.com/AWSEC2/latest/UserGuide/using-regions-availability-zones.html
  • Availability Zone IDsp. 6 Why a · b · c are shuffled per account, and use1-az1 docs.aws.amazon.com/ram/latest/userguide/working-with-az-ids.html
  • What is Amazon VPC?pp. 8 · 9 Defines VPCs, subnets and routing — and says the VPC itself is free docs.aws.amazon.com/vpc/latest/userguide/what-is-amazon-vpc.html
  • Default VPCsp. 8 What the VPC already in your account comes with docs.aws.amazon.com/vpc/latest/userguide/default-vpc.html
  • VPC CIDR blockspp. 11 · 12 /16 ~ /28, RFC 1918 recommended; no resizing, but a secondary CIDR can be added docs.aws.amazon.com/vpc/latest/userguide/vpc-cidr-blocks.html
  • Subnet CIDR blocksp. 11 The five addresses reserved in each subnet, one by one docs.aws.amazon.com/vpc/latest/userguide/subnet-sizing.html
  • Amazon VPC quotaspp. 8 · 9 5 VPCs per Region; 200 subnets and 5 CIDRs per VPC docs.aws.amazon.com/vpc/latest/userguide/amazon-vpc-limits.html
  • RFC 1918 — private IP rangesp. 12 Where 10 · 172.16 · 192.168 come from. A standard, not an AWS doc datatracker.ietf.org/doc/html/rfc1918
  • Overview of Data Transfer Costs for Common Architecturesp. 6 Diagrams of what is charged across AZs and Regions aws.amazon.com/blogs/architecture/overview-of-data-transfer-costs-for-common-architectures
  • Networking basics every AWS user must knowpp. 4 · 8 Same scope as this sheet, in Korean. Official AWS Korea channel www.youtube.com/watch?v=vCNexbgYmQ8
  • AWS Networking Fundamentals (re:Invent 2025)p. 14 Official one-hour session on the next steps (in English) www.youtube.com/watch?v=nXBqxnp5ybY
© 2026 tiaz tiaz.dev 15/15