VPC Flashcards
Simply put, subnets exist to :
Allow routes to make routing decisions for a group of resources with the same logic
What are the two parts of each ip address?
The network address (aka server address) and the host address (aka client address)
A subnet mask does what?
Splits the ip address into two sections, the network address and the host address
What does a gateway do?
Connects local devices in a network to other networks
Default subnet mask of Class A networks
255.0.0.0
Default subnet masks of Class B networks
255.255.0.0
Default subnet mask for class C networks
255.255.0
IANA stands for
Internet Assigned Numbers Authority
IGW vs NAT gateway
Internet Gateway (IGW) allows instances with public IPs to access the internet. NAT Gateway (NGW) allows instances with no public IPs to access the internet.
how to enable traffic to or from instances in a subnet in a VPC
1) Create an internet gateway and attach it to your VPC.
2) Add a route to your subnet’s route table that directs internet-bound traffic to the internet gateway.
3) Ensure that instances in your subnet have a globally unique IP address (public IPv4 address, Elastic IP address, or IPv6 address).
4) Ensure that your network access control lists and security group rules allow the relevant traffic to flow to and from your instance.
ROUTE table differences between PUBLIC, PRIVATE, ISOLATED
PUBLIC: route table has a 0/0 igw entry
PRIVATE: route table has a 0/0 ngw entry
ISOLATED: route table has no 0/0 entry
Is there ANY way for an isolated subnet to still communicate w/ a device on a different network (e.g. on the public internet?)
im pretty sure. I think you can just have it communciate wi a device that is reachable on it’s route table and still within say the vpc, but then that device reachable to it is in a different subnet B in the vpc, and that different subnet B has a 0/0 igw or ngw entry
are s3 buckets in a vpc?
no they live out of any VPC, but you can make make it accessible only from your VPC with VPC Endpoints if the content you are going to store on S3 musn’t be available from the public Internet
can you change the VPC of an RDS instance?
Yes, but after doing certain things
Can you change the subnet group of an RDS instance within the same VPC?
No, but yes via some workarounds.