
Understanding Networking in AWS Cloud
Part of my journey through AWS Cloud Practitioner Essentials, I recently completed Module 5: Networking.
This module helped me understand one of the most important foundations of cloud computing: how AWS resources communicate with each other and with the outside world.
Before learning networking in AWS, concepts like VPCs, subnets, gateways, VPNs, and Direct Connect can seem like a collection of complicated terms. After going through this module, I started seeing them as different components of one larger networking architecture.
Amazon VPC – My Private Network in AWS
The first major concept I learned was Amazon Virtual Private Cloud (Amazon VPC).
A VPC can be thought of as an isolated virtual network that I define within AWS. It gives me control over the networking environment in which my AWS resources operate.
For example, I can define an IP address range for my VPC and place resources such as Amazon EC2 instances inside it.
A simplified structure looks like this:
1
2
3
4
5
6
7
AWS
└── VPC
├── Public Subnet
│ └── Web Server
│
└── Private Subnet
└── Backend / DatabaseOne important benefit of a VPC is isolation. Instead of putting every resource into one unrestricted network, I can organize resources and control how they communicate.
Subnets – Organizing Resources
Inside a VPC, I can create subnets.
A subnet is a smaller section of the VPC's IP address range. Subnets allow me to organize resources based on their purpose and networking requirements.
For example, a typical application might have:
- A public subnet for internet-facing resources
- A private subnet for backend services
- Another private subnet for databases
This separation helps create a more controlled and secure architecture.
One important point I learned is that simply calling a subnet "public" does not make it public. Its routing configuration and associated networking components determine whether it has a path to the internet.
Internet Gateway – Connecting to the Internet
If resources in a VPC need to communicate with the public internet, an Internet Gateway (IGW) can be attached to the VPC.
I found the simplest way to visualize it as a door between the VPC and the internet:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
User
│
▼
Internet
│
▼
Internet Gateway
│
▼
VPC
│
▼
Public Subnet
│
▼
ApplicationHowever, attaching an Internet Gateway alone does not automatically make every resource publicly accessible. Appropriate routing, addressing, and security configuration are also required.
Virtual Private Gateway and VPN
The next concept was Virtual Private Gateway and how it relates to a VPN connection.
Organizations often have existing infrastructure in an on-premises data center or corporate network. They may want to connect that private environment to AWS.
A VPN can create an encrypted connection over an underlying network such as the internet.
A simplified view is:
1
2
3
4
5
6
7
8
On-Premises Network
│
│ Encrypted VPN
▼
Virtual Private Gateway
│
▼
VPCThe distinction between the terms is important:
- VPC → The virtual network in AWS
- VPN → The encrypted network connection
- Virtual Private Gateway → The AWS-side gateway used for VPN connectivity to a VPC
This is useful when an organization wants private connectivity between its existing infrastructure and AWS.
AWS Direct Connect – Dedicated Connectivity
Another interesting concept from this module was AWS Direct Connect.
While a VPN can provide an encrypted connection over the internet, some organizations require a more consistent and dedicated network connection to AWS.
That's where Direct Connect comes in.
1
2
3
4
5
6
7
8
9
10
11
Company Data Center
│
│ Dedicated connection
▼
AWS Direct Connect
│
▼
AWS
│
▼
VPCDirect Connect provides a dedicated network connection between an organization's network and AWS through a Direct Connect location.
This can be useful when organizations need:
- More consistent network performance
- Predictable bandwidth
- Private connectivity
- Support for certain compliance or regulatory requirements
An important distinction I learned is that dedicated connectivity and encryption are not the same thing. Direct Connect provides dedicated connectivity; encryption needs to be considered separately depending on the architecture and requirements.
Public vs Private Resources
One of the biggest takeaways from this module was understanding the difference between public and private resources.
A typical cloud application shouldn't expose everything to the internet.
For example:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
Internet
│
▼
Internet Gateway
│
▼
Public Subnet
│
Load Balancer
│
▼
Private Subnet
│
Backend
│
▼
DatabaseThe public-facing layer can receive requests from users, while backend services and databases can remain in private networking environments.
This separation reduces unnecessary exposure and is an important part of designing secure cloud architectures.
Putting Everything Together
After completing this module, I think about AWS networking using a simple model:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
INTERNET
│
▼
Internet Gateway
│
┌──────────────┴──────────────┐
│ VPC │
│ │
│ Public Subnet │
│ └── Load Balancer │
│ │
│ Private Subnet │
│ └── Backend │
│ └── Database │
│ │
└─────────────────────────────┘
▲
│
VPN / VGW
│
Corporate Network
Company Network
│
│ Dedicated connection
▼
AWS Direct Connect
│
▼
AWSKey Takeaways
The concepts I am taking away from Module 5 are:
VPC → Creates an isolated virtual network in AWS.
Subnet → Divides a VPC into smaller network sections.
Internet Gateway → Provides a path between a VPC and the public internet.
VPN → Creates an encrypted connection over an underlying network.
Virtual Private Gateway → Provides the AWS-side endpoint for VPN connectivity to a VPC.
AWS Direct Connect → Provides dedicated connectivity between an organization's network and AWS.
More importantly, I learned that AWS networking is not just about connecting resources. It is about controlling connectivity, separating workloads, reducing unnecessary exposure, and designing reliable architectures.
What's Next?
Module 5 gave me a better foundation for understanding how AWS resources communicate.
My next step is to go deeper into concepts such as routing, route tables, security groups, network ACLs, and how traffic actually flows through a VPC.
The more I learn about AWS networking, the clearer it becomes that cloud architecture is essentially about making deliberate decisions about where resources live, who can reach them, and how they communicate.
#AWS #AWSCloud #AWSCloudPractitioner #AmazonVPC #CloudComputing #Networking #AWSLearning #CloudArchitecture #100DaysOfCloud #AWSCommunity
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article