Amazon Virtual Private Cloud (Amazon VPC) is the logically isolated virtual network where you configure how many AWS resources are addressed and connected. A VPC spans one AWS Region; you divide it into subnets in individual Availability Zones, then use route tables and gateways to determine where traffic can go. A subnet is not public or private merely because of the resources placed in it: its routes define the relevant network paths.
What Amazon VPC does
A VPC gives you control over network addressing, subnet placement, routing, and connectivity for supported AWS resources. AWS describes it as similar to a traditional network in a data center, but defined in software. It is a network boundary and routing environment—not a guarantee that every resource inside it is secure or unreachable.
You can manage a VPC through the AWS Management Console, command-line interface, SDKs, or Query API. Some AWS services can use a default VPC when one is available, so not every workload requires you to create a VPC manually. See AWS’s Amazon VPC overview.
How Regions, Availability Zones, and subnets fit together
A VPC belongs to a Region and can span that Region’s Availability Zones. A subnet is an IP address range within the VPC, and each subnet resides in exactly one Availability Zone. You place resources in subnets according to the network layout you need; the subnet’s route-table association determines the routes available to them.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →#1 Best Overall
- Your favorite music and content – Play music, audiobooks, and podcasts from Amazon Music, Apple Music, Spotify and others or via Bluetooth throughout your home.
- Alexa is happy to help – Ask Alexa for weather updates and to set hands-free timers, get answers to your questions and even hear jokes. Need a few extra minutes in the morning? Just tap your Echo Dot to snooze your alarm.
- Keep your home comfortable – Control compatible smart home devices with your voice and routines triggered by built-in motion or indoor temperature sensors. Create routines to automatically turn on lights when you walk into a room, or start a fan if the inside temperature goes above your comfort zone.
- Do more with device pairing – Fill your home with music using compatible Echo devices in different rooms, or create a home theatre system with Fire TV.
- Say goodbye to drop-offs and buffering - With eero Built-in, Echo Dot doubles as a mesh wifi extender, adding up to 1,000 sq. ft. of wifi coverage to your existing eero network.
- Region: the geographic AWS area in which the VPC is created.
- Availability Zone: a distinct location within a Region where resources can run.
- VPC: the larger virtual network and address space.
- Subnet: a portion of that address space in one Availability Zone.
This separation lets you distribute resources across Availability Zones while keeping their network configuration within the same VPC. AWS explains these relationships in VPC basics.
How route tables determine public and private paths
A route table contains routes, each with a destination and a target. Every subnet is associated with one route table, either explicitly or by default through the VPC’s main route table. A route table can direct traffic within the VPC or toward a gateway or other target. AWS’s subnet route-table documentation describes the association and routing rules.
Rank #2
- Your favorite music and content – Play music, audiobooks, and podcasts from Amazon Music, Apple Music, Spotify and others or via Bluetooth throughout your home.
- Alexa is happy to help – Ask Alexa for weather updates and to set hands-free timers, get answers to your questions and even hear jokes. Need a few extra minutes in the morning? Just tap your Echo Dot to snooze your alarm.
- Keep your home comfortable – Control compatible smart home devices with your voice and routines triggered by built-in motion or indoor temperature sensors. Create routines to automatically turn on lights when you walk into a room, or start a fan if the inside temperature goes above your comfort zone.
- Do more with device pairing – Fill your home with music using compatible Echo devices in different rooms, or create a home theatre system with Fire TV.
- Say goodbye to drop-offs and buffering - With eero Built-in, Echo Dot doubles as a mesh wifi extender, adding up to 1,000 sq. ft. of wifi coverage to your existing eero network.
A subnet is considered public when its route table has a direct route to an internet gateway. A private subnet has no direct route to an internet gateway. An IP address on a server alone does not make its subnet public.
For example, an IPv4 route with destination 0.0.0.0/0 and an internet gateway as its target sends traffic for all IPv4 destinations toward that gateway. IPv6 uses a separate default route, ::/0; an IPv4 route does not provide IPv6 connectivity.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- MEET ECHO SPOT - A sleek smart alarm clock with Alexa and big vibrant sound. Ready to help you wake up, wind down, and so much more.
- CUSTOMIZABLE SMART CLOCK - See time, weather, and song titles at a glance, control smart home devices, and more. Personalize your display with your favorite clock face and fun colors.
- BIG VIBRANT SOUND - Enjoy rich sound with clear vocals and deep bass. Just ask Alexa to play music, podcasts, and audiobooks. See song titles and touch to control your music.
- EASE INTO THE DAY - Set up an Alexa routine that gently wakes you with music and gradual light. Glance at the time, check reminders, or ask Alexa for weather updates.
- KEEP YOUR HOME COMFORTABLE - Control compatible smart home devices. Just ask Alexa to turn on lights or touch the screen to dim. Create routines that use motion detection to turn down the thermostat as you head out or open the blinds when you walk into a room.
Each VPC includes a main route table. A subnet without an explicit route-table association uses that main table. A newly created nondefault VPC’s main table contains a local route by default. AWS documents leaving the main table in its original state and explicitly associating subnets with custom route tables as one way to manage routing deliberately.
Choosing internet and AWS-service connectivity
The right path depends on whether resources need inbound internet reachability, outbound internet access, access to AWS services, or no external connectivity. An internet gateway and a NAT gateway serve different purposes; VPC endpoints provide another option for certain AWS-service connections.
Rank #4
- Your favorite music and content – Play music, audiobooks, and podcasts from Amazon Music, Apple Music, Spotify and others or via Bluetooth throughout your home.
- Alexa is happy to help – Ask Alexa for weather updates and to set hands-free timers, get answers to your questions and even hear jokes. Need a few extra minutes in the morning? Just tap your Echo Dot to snooze your alarm.
- Keep your home comfortable – Control compatible smart home devices with your voice and routines triggered by built-in motion or indoor temperature sensors. Create routines to automatically turn on lights when you walk into a room, or start a fan if the inside temperature goes above your comfort zone.
- Do more with device pairing – Fill your home with music using compatible Echo devices in different rooms, or create a home theatre system with Fire TV.
- Say goodbye to drop-offs and buffering - With eero Built-in, Echo Dot doubles as a mesh wifi extender, adding up to 1,000 sq. ft. of wifi coverage to your existing eero network.
| Option | What it provides | Design consideration |
|---|---|---|
| Internet gateway | Connects a VPC to the internet. A subnet needs a route to it to qualify as public. | A route is a network path, not by itself a complete security policy. |
| NAT gateway | Allows instances in a private subnet to send outbound traffic to the internet while preventing internet-originated connections to those instances. | NAT gateways have charges. AWS recommends a NAT gateway in each active Availability Zone for production deployments; consider availability needs and cost when applying that guidance. |
| VPC endpoint | Connects privately to supported AWS services without an internet gateway or NAT device. | Useful when the required destination is an AWS service reachable through an endpoint. |
AWS outlines NAT and other topology choices in VPC configuration options. For connections beyond a single VPC, VPC peering connects two VPCs, while a transit gateway can act as a hub among VPCs and VPN or Direct Connect connections. VPC Flow Logs capture information about IP traffic to and from network interfaces.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Routing is not the same as security control
Route tables choose paths for traffic. Security groups and network ACLs are separate VPC security controls. Having a route to a destination does not, on its own, mean traffic is permitted by every applicable control; conversely, controls do not create a route where none exists. Plan routing and security configuration as distinct parts of the network design.
Best Value
- Alexa can show you more - Echo Show 5 includes a 5.5” display so you can see news and weather at a glance, make video calls, view compatible cameras, stream music and shows, and more.
- Small size, bigger sound – Stream your favorite music, shows, podcasts, and more from providers like Amazon Music, Spotify, and Prime Video—now with deeper bass and clearer vocals. Includes a 5.5" display so you can view shows, song titles, and more at a glance.
- Keep your home comfortable – Control compatible smart devices like lights and thermostats, even while you're away.
- See more with the built-in camera – Check in on your family, pets, and more using the built-in camera. Drop in on your home when you're out or view the front door from your Echo Show 5 with compatible video doorbells.
- See your photos on display – When not in use, set the background to a rotating slideshow of your favorite photos. Invite family and friends to share photos to your Echo Show. Prime members also get unlimited cloud photo storage.
Default VPC or custom VPC?
A default VPC in a Region offers a convenient starting point for resources and services that can use it. A custom VPC gives you more control over addressing, subnet layout, routes, and network separation. Neither choice is automatically secure: the result depends on the routes and controls you configure.
What Amazon VPC costs—and what may incur charges
Using a VPC itself has no additional charge, but some connected features and address use can. AWS lists NAT gateways, IP Address Manager, traffic mirroring, Reachability Analyzer, Network Access Analyzer, and public IPv4 addresses among chargeable items or cases. Rates depend on factors such as Region and usage, so check AWS’s current VPC documentation and linked pricing information for the configuration you plan to use rather than relying on a rate quoted elsewhere.
Service quotas to know when planning
AWS’s quota documentation, accessed in 2026, gives the following default quotas. They are service limits rather than recommended design targets; AWS says quotas are per Region unless noted otherwise, and several can be raised. Check the live Amazon VPC quotas page before planning against them.
Quick Recap
| Resource or control | Default quota | Qualification |
|---|---|---|
| VPCs | 5 per Region | Adjustable. |
| Subnets | 200 per VPC | Adjustable. |
| Route tables | 200 per VPC | A subnet can be associated with only one route table. |
| Security-group rules | 60 inbound and 60 outbound per security group | Inbound and outbound quotas are enforced separately. |
| Network ACL rules | 20 inbound and 20 outbound per network ACL | Can be increased up to 40 each, with a possible performance impact. |
A practical way to think about a VPC
- Choose the Region where the workload will run.
- Plan the VPC address space and divide it into subnet ranges for the resources and Availability Zones you need.
- Decide which subnets need external paths. Associate route tables that provide only the routes each subnet requires.
- Select gateways or endpoints based on the destinations resources must reach and whether access should be internet-facing or private.
- Configure security controls separately from routing, and account for availability and charges when using components such as NAT gateways or public IPv4 addresses.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.




