What the exam asks
- Plan CIDR ranges and subnet sizes that will not collide or run out.
- Choose between VPC peering, Transit Gateway, PrivateLink and VPC sharing to connect VPCs.
- Design Direct Connect for bandwidth, resilience and encryption, and choose Site-to-Site VPN as a primary link or as a backup.
- Reach several Regions and many VPCs from one on-premises connection.
- Place resources in the right Region, AZ or subnet for latency and data residency.
Core ideas
IP addressing
- A VPC’s IPv4 CIDR can be from /16 to /28. AWS reserves 5 addresses in every subnet (the first four and the last), so usable addresses = 2^(32 − prefix) − 5.
| Prefix | Addresses | Usable |
|---|---|---|
| /28 | 16 | 11 |
| /27 | 32 | 27 |
| /26 | 64 | 59 |
| /25 | 128 | 123 |
| /24 | 256 | 251 |
- You cannot resize a VPC’s primary CIDR or an existing subnet. To grow, add a secondary CIDR block and create new subnets, or add IPv6.
- IPv6: a /56 per VPC and /64 subnets. The addresses are globally unique, so use an egress-only internet gateway for outbound-only IPv6 access.
- Plan non-overlapping ranges across all VPCs and on-premises networks from day one. Peering, Transit Gateway routing and VPN routing all fail with overlapping CIDRs. Amazon VPC IP Address Manager (IPAM) can allocate ranges across an organisation.
Connecting VPCs
| Option | Use when | Key limits |
|---|---|---|
| VPC peering | A few VPCs, the lowest cost, same or different Region and account | No overlapping CIDRs. No edge-to-edge routing (a peer cannot use your IGW, NAT, VPN, Direct Connect or gateway endpoint). Full mesh grows as n(n−1)/2 |