# Creating own Custom Virtual Private Cloud (VPC) in AWS

> **VPC**

AWS VPC allows users to define a logically isolated virtual network in the AWS cloud. This virtual network closely resembles a traditional network that you might operate in your own data center, with the benefits of using scalable AWS infrastructure. Within a VPC, you can deploy AWS resources such as EC2 instances, RDS databases, and more, ensuring they are securely isolated and can communicate with each other.

> **Steps on how to set up an Amazon VPC :**

Go to the AWS Management Console ([https://aws.amazon.com/](https://aws.amazon.com/)) and sign in to your account.

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722363035273/604f2e7c-3bf7-4340-8772-9303d8d3acf7.png align="center")

In the AWS Management Console, search for and select "VPC" or find it under "Networking & Content Delivery."

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722363131427/bf942d54-3d66-4601-89e9-e411a133b835.png align="center")

**<mark>Step 1 : Click "Create VPC"</mark>**

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722363261580/309e7b07-dbdf-4dd3-8ecf-6ac1fe1a8a46.png align="center")

Define a name for VPC and specify the IPv4 CIDR block (10.0.0.0/16)

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722367570478/68f230b0-07a0-40e9-a2af-5679de765bae.png align="center")

I have used 10.0.0.0/16 CIDR Block for VPC, Now We have 65,536 ip address

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722367634349/a9b1c390-bb61-43c4-b04f-85ce777e526a.png align="center")

We have two options in tenancy (default and dedicated). Dedicated cost is too high. So, I have chosen Default.

Then, Click Create VPC

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722367748638/466b90b5-9df0-4fd3-ac7a-32c1fcd74329.png align="center")

**<mark>Step 2 : Create a Public &amp; Private subnet for different Available AZs by assigning different CIDR blocks</mark>**

For, Public subnet i need 256 ip address

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722367877747/c1d011ad-8187-4482-b8de-4374a14440f3.png align="center")

For, Private subnet i need 256 ip address

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722367949424/9c96b019-dcb6-4d83-b870-5b31603198b0.png align="center")

In the left side menu click subnet & Click Create subnet

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722365328820/795ff0e3-0eba-4b2f-9c6a-88c46fc97545.png align="center")

Select existing VPC "MY\_VPC"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368028014/0c34bcf9-849f-4b9d-9a8b-f0a687860753.png align="center")

Enter Subnet name for "Public Subnet"

Choose AZ for "Public Subnet"

Enter IPV4 with CIDR block for "Public Subnet"

Click Create subnet

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368161468/85f84a64-330e-46f7-b161-5fde0d2b149f.png align="center")

Now, Successfully public subnet created.

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368223968/d849d017-d49f-41de-8d7d-f83cbbf5ecd0.png align="center")

Now, Need to create Private Subnet

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368383485/1b5afc7e-3e06-4aa0-b2ff-9fc77db4ec41.png align="center")

Successfully created Public & Private subnet

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368479175/a63baaa9-33df-4c72-ace9-9bb0c9a7d300.png align="center")

**<mark>Step 3 : Create Internet Gateway &amp; Attach it to the VPC</mark>**

Click create internet gateway

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368641099/456d547d-87a8-4094-94c4-e2fefb32f2e4.png align="center")

Set Name & Click "Create internet gateway"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368750368/eaa28e6e-ac8e-4872-b577-a8c96d3cb9df.png align="center")

Internet Gateway successfully created

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368913656/437f5d8a-3031-4aaf-9d2a-72553bb4ecac.png align="center")

Now, it is showing detached mode, Need to attach Internet Gateway to VPC

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722368996177/50fd192c-96a5-48d5-b47f-8cf895e5c1e9.png align="center")

Select available VPC and Click "Attach internet gateway"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722369026719/fac690ed-ced2-4283-932a-2467bce6607a.png align="center")

Now, Successfully attached

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722369116642/8c8e32d0-f184-455c-beee-302ea3cc8994.png align="center")

**<mark>Step 4 : Create Routing table for One as Public &amp; One as private by associating the appropriate subnet to it</mark>**

Enter Route table name for "Public", Select VPC & Select "Create route table"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722369935451/408a2c57-e60a-46ad-97c8-f2da2c281a49.png align="center")

Enter Route table name for "Private", Select VPC & Select "Create route table"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722370232112/a663286b-19d0-47c8-88b8-397032efaeb3.png align="center")

Now, successfully created Public, Private route table

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722370389093/0219b75b-25f7-424b-97aa-1af7c2cf7145.png align="center")

Now need to associate to Public subnet & Private subnet

Click Subnet associations & Click "edit subnet associations"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722370611952/4b85865e-821a-4657-9c8f-2a2a0b61a1d5.png align="center")

Now, click public subnet and Click "save associations"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722370744650/91841fbb-ec86-4b05-be66-d480dd25db9b.png align="center")

click private subnet and Click "save associations"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722370865528/f6c61ca2-a0a0-4b93-80f2-51a5087a1348.png align="center")

Now, Routing table successfully associate to Public & Private subnet

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722370990345/970dc68a-730d-4110-bc2a-a162c36a006a.png align="center")

**<mark>Step 5 : Edit the route table's Route alone and Map the IGW, not the Private and leave it as it is.</mark>**

Note: I will give internet connection to "Public route table" Only.

Go to Route table, Select public route table, Click "Route", Click "Edit route"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722371305833/c597df7f-b56b-42e8-abc7-18a10ebb8496.png align="center")

Click "add route"

Select "Internet gateway" in empty box

Select "igw" choose "internet gateway" default

Select destination box, Select "0.0.0.0/0"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722371553677/be1cfeb6-03e3-465d-bf38-0b61b61fd8e4.png align="center")

**<mark>Step 6 : Create two security group,</mark>**

one for public (Edit the inbound rule with RDP, HTTP/HTTPS, SSH and map 0.0.0.0/0 in the source)

one for private (Edit the inbound rule and map the "Security Group" of public in the source)

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722372381931/708e755f-141d-480b-a9ab-e455a262ccb7.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722372493688/befe1974-f8b8-4b31-9a1c-accb0f4cd813.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722372638266/aac1946b-5fc1-4020-b055-894d49632248.png align="center")

Now, Successfully "Public Security Group" Created

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722372722555/cebd19e1-960c-4bdd-8145-3741b3abcde4.png align="center")

Now, Need to create Private secruity group

Copy the Public security group id ( sg-0d6808a8ed83081fb )

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722372909816/32f8a9fb-211d-4ee5-8b30-d353429ec937.png align="center")

Create security group for private subnet

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722373158079/e254fab4-054b-4fb8-9844-6e7d7facf5c5.png align="center")

Note : To access private subnet ip from Public Subnet IP , add public subnet ip with CIDR block or public security group id in private security group

In this scenario, i have added public security group id in private security group

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722373864275/b1d29eb3-1d1e-4d39-8fa4-51dfb307d5fe.png align="center")

Click "Create security group"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722374013755/a5880d9d-131c-4e8a-a1cc-c19722dd3ebf.png align="center")

Now successfully created "Private sec group"

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722374122375/09e11c12-5195-4a95-bfe8-c61203d6a0df.png align="center")

**<mark>Step 7 : Create two EC2 instances, one for Public subnet and another one Private subnet with proper security group</mark>**

1st instance :

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722375062244/0ede6095-aca0-4431-b708-bf87b183634a.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722375333563/4bbf351b-f009-4ff1-91ca-c5b745f7ff61.png align="center")

2nd instane

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722375708316/28885a58-90ef-4865-acd3-948fb7896555.png align="center")

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722375775430/0fe97ccd-6d38-4daa-a245-57d7662c08cf.png align="center")

Now, Open the Public machine, Copy the Public IP address

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722375891161/d5080443-a8c0-4b3c-b6f0-dc984d533682.png align="center")

Enter the credentials

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722376097963/7b42b293-a941-47e6-baa4-b65e5cc4bd61.png align="center")

now, we can access Public machine

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722376383250/e5ef096a-2086-4766-9453-f6c4677dacd4.png align="center")

Copy the private machine ip address

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722376547025/c5f8b38f-d6ec-4505-abf8-2cd1cad3a09b.png align="center")

There is no public ip address, So, we can't open that machine

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722376617306/ee949c37-f24e-40ea-a911-57cadb878abd.png align="center")

We need to access that private ip address only from public ip machine

Open RDP in inside public machine, Enter private ip & Username, password

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722376672823/68efe66e-3192-4515-bc44-995df3f9b791.png align="center")

Now, We can access private ip machine

Note : This connectivity called JumpBox / Bastion Host

![](https://cdn.hashnode.com/res/hashnode/image/upload/v1722377478557/c5ec362b-38a2-41df-a8d2-a84a5352b5b3.png align="center")

**Conclusion :**

AWS VPC is a fundamental building block for designing and deploying scalable and secure cloud applications on AWS. By understanding its core concepts and features, you can leverage AWS VPC to create flexible and reliable network architectures that meet your organization's specific needs.

Start exploring AWS VPC today and discover how it can empower your cloud infrastructure with enhanced security, scalability, and connectivity.
