Sunday, 4 October 2026

Subnets are Routing Boundaries not Security Boundaries

AWS, as well as other cloud providers, use subnets to partition virtual networks (e.g. in AWS VPC - Virtual Private Cloud).  

These subnets divide up the IP address space into separate compartments for routing traffic.

In AWS, another way of saying this is "each subnet is a slice of your VPC's CIDR block".

Each subnet block in AWS is tied to a particular AZ, or Availability Zone. Subnets cannot span AZs and this preserves the availability pattern (e.g. one private subnet per AZ).

There are many types of subnet in AWS.  Examples are:
  • Public subnet - subnet has a direct route to an internet gateway. Resources in the public subnet can access the public internet.
  • Private subnet - subnet has NO direct route to an internet gateway. Resources in the subnet require a NAT device to access the public internet
  • VPN-only subnet - the subnet has a route to a Site-to-Site VPN connection through virtual private gateway. The subnet has no route to an internet gateway
  • Isolated subnet - not connected to the internet - in fact, no routes to destination outside its VPC
  • EVS subnet - a type of subnet created by Amazon EVS (very specific to VMware)
(Sidebar: internet gateway - bridge ("network bridge","network component")  between private network and the internet,enabling traffic routing, protocol translation, NAT, DHCP and security filtering)


No comments: