AWS Builder Center
Your EC2 Doesn't Need a Public IP: Understanding Public vs Private Subnets

Your EC2 Doesn't Need a Public IP: Understanding Public vs Private Subnets

Public or private? Understanding AWS subnets is the first step toward building secure cloud architectures. Learn where your EC2, applications, and databases should live — and why not everything needs to be public.

When you first learn AWS networking, two terms appear everywhere:
Public Subnet
Private Subnet
But what actually makes a subnet public or private?
The answer is simpler than it sounds.

1. A Public Subnet Can Have a Route to the Internet

A subnet is considered public when its route table has a route to an Internet Gateway.
For example:
0.0.0.0/0 → Internet Gateway
Resources in that subnet can potentially communicate with the public internet, provided the rest of the configuration also allows it.
A common example:
Application Load Balancer → Public Subnet

2. A Private Subnet Doesn't Have a Direct Internet Gateway Route

A private subnet doesn't have a direct route to an Internet Gateway.
For example:
0.0.0.0/0 → NAT Gateway
This allows resources in the private subnet to initiate outbound internet connections through the NAT Gateway, without allowing unsolicited inbound connections from the internet.
A common example:
Application Server → Private Subnet

3. Why Not Put Everything in a Public Subnet?

You might think:
"If public access is easier, why not make everything public?"
Because not every resource needs to be directly reachable from the internet.
A common architecture looks like this:
Internet
↓
Load Balancer
↓
Private Application Servers
↓
Private Database
This reduces the number of resources that need direct internet exposure.
AWS documentation provides production-oriented examples using public subnets for load balancers and private subnets for application servers.

4. Private Doesn't Mean "No Internet"

This is a common beginner misconception.
A private EC2 instance can still download updates or access external services when its subnet is configured to use a NAT Gateway.
The traffic can flow like:
Private EC2
↓
NAT Gateway
↓
Internet Gateway
↓
Internet
The important difference is that the private instance doesn't have a direct route to the Internet Gateway.

5. NAT Gateway Isn't a Firewall

Another important point:
A NAT Gateway provides network address translation and allows private resources to initiate outbound connections.
It should not be treated as a replacement for security groups or other network security controls.
Think of the responsibilities separately:
Route Table → Where should traffic go?
NAT Gateway → How can private resources reach outside networks?
Security Group → What traffic is allowed to the resource?

A Simple AWS Architecture

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
INTERNET
|
v
Internet Gateway
|
+----------+----------+
| |
v v
PUBLIC SUBNET PRIVATE SUBNET
| |
Load Balancer EC2 / App
| |
| NAT Gateway
| |
+-----------> Internet

|
v
DATABASE
PRIVATE SUBNET
This basic pattern appears in many AWS architectures.

Beginner Rule to Remember

Don't ask:
"Should I make this public or private?"
Ask:
"Does this resource actually need to be directly reachable from the internet?"
If the answer is no, consider keeping it private.
That single question can help you design safer AWS networks.

Final Takeaway

Remember these three ideas:
Public subnet → direct route to Internet Gateway
Private subnet → no direct route to Internet Gateway
NAT Gateway → allows private resources to initiate outbound internet connections
Once you understand these three concepts, AWS VPC networking becomes much easier to understand.
Any opinions in this article are those of the individual author and may not reflect the opinions of AWS.
Enjoyed reading this content? Let the author know!

Your likes, comments, shares, and saves help creators reach more builders.

Loading recommendations

Loading article