Instiq
Chapter 1 · Network Design Fundamentals·v2.1.0·Updated 6/28/2026·~11 min

What's changed: In-scope coverage: added service mesh/discovery/device VPN (App Mesh/Cloud Map/Client VPN)

1.2Subnet and Routing Design

Key points

Understand traffic paths—public/private subnets, route tables, internet gateway, and NAT gateway. The route table decides whether a subnet is public.

Whether a subnet is "public" or "private" is decided by its route table—specifically where the route to the internet points.

1.2.1Public vs private

Diagram of subnets and routing: a public subnet routes 0.0.0.0/0 to the internet gateway (IGW), has public IPs, and hosts ALB/NAT; a private subnet routes 0.0.0.0/0 to a NAT gateway, is egress-only, and receives no inbound from the internet. The NAT gateway itself lives in the public subnet.
Subnets and routing
  • Public subnet: route 0.0.0.0/0 → IGW (internet gateway). Host ALB and NAT gateway here.
  • Private subnet: route 0.0.0.0/0 → NAT gateway. Egress only; no inbound from the internet.
  • NAT gateway: relays egress for private subnets. The NAT itself sits in a public subnet.
  • One subnet = one route table: each subnet has one associated route table (the main one if not explicit).
Exam point

Common on ANS-C01: a route to IGW makes a subnet public, private egress uses a NAT gateway (the NAT sits in a public subnet), and NAT does not allow inbound. You cannot give a private subnet direct internet inbound via an IGW.

Note

For IPv6 egress-only traffic, use an "egress-only internet gateway," not NAT. NAT gateways are for IPv4.

ANS-C01 routing design precisely probes "route table evaluation and gateway roles." Routes are chosen by longest-prefix match, preferring more specific routes. A subnet associates with one route table, defaulting to the main route table if not explicit. An internet gateway (IGW) is a horizontally scaled, redundant component attached to the VPC, enabling bidirectional internet for resources with public IPs/EIPs. A NAT gateway is managed and per-AZ (place one per AZ for HA), egress-only with no inbound initiation, for IPv4 (preferred over a self-managed NAT instance). IPv6 egress-only uses an Egress-Only IGW. For traffic within the VPC, VPC endpoints (gateway type = S3/DynamoDB, added to route tables via a prefix list / interface type = ENI, PrivateLink, resolved by DNS) reach AWS services without the internet. Route targets can be IGW/NAT/peering connection/TGW attachment/VPC endpoint/Gateway Load Balancer endpoint (inline inspection), and middlebox routing (edge association) can divert IGW-inbound traffic to an inspection appliance. The key is to nail "route to IGW = public," "NAT is egress-only, one per AZ," "longest-prefix match," and "AWS services via VPC endpoints."

Gateway/routeRoleKey point
IGWBidirectional internetPublic IP/EIP; redundant; scales
NAT gatewayIPv4 egress-onlyOne per AZ; no inbound initiation
Egress-Only IGWIPv6 egress-onlyNAT-equivalent for IPv6
VPC endpointPrivate to AWS servicesGateway (S3/DDB)/interface type
Note

Scenario: Hundreds of instances in private subnets need OS patches and S3 access—balance availability with cost/performance. → For general egress, place a NAT gateway per AZ (survives AZ failure, reduces cross-AZ transfer cost) and point each subnet’s route to the same-AZ NAT. For S3, use a gateway VPC endpoint (free; prefix list in the route table) to avoid the internet and NAT, improving transfer cost and security.

Note

FAQ: Is one NAT gateway enough? It works functionally, but a single-AZ NAT halts egress for other AZs if that AZ fails, and traffic from other AZs incurs cross-AZ data transfer charges. For HA and cost, the best practice is one NAT gateway per AZ, routing each subnet to the NAT in its own AZ.

Warning

Exam trap: Using a NAT gateway to give private-subnet instances "internet inbound" is wrong—NAT is egress-only and cannot initiate inbound. For internet inbound, use a public subnet + IGW (or via an ALB). Also, placing the NAT in a private subnet is wrong—the NAT goes in a public subnet with a route to the IGW.

1.2.2Section summary

  • Public-ness = does the route point to IGW
  • Private egress = NAT gateway (placed in public subnet)

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. What is the decisive condition that makes a subnet a "public subnet"?

Q2. A private-subnet instance must fetch OS patches from the internet (egress) but accept no inbound. What?

Q3. In which subnet do you place a NAT gateway?

Check your understandingPractice questions for Chapter 1: Network Design Fundamentals

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.