---
title: "Networking and hybrid connectivity"
chapter: "04"
---

# Networking and hybrid connectivity

A VPC is your private network boundary in one AWS Region.

## The building blocks

- **Subnet:** an IP range in one AZ. A public subnet has a route to an internet
  gateway; a private subnet does not expose workloads directly.
- **Route table:** where network traffic should go.
- **Security group:** stateful firewall attached to a resource.
- **Network ACL:** stateless subnet-level rules; use as coarse guardrails.
- **NAT Gateway:** lets private IPv4 resources initiate internet connections.
- **VPC endpoint / PrivateLink:** private access to supported services without
  traversing the public internet.
- **Transit Gateway:** hub that connects many VPCs and on-premises networks.
- **Route 53:** DNS and health-aware routing.
- **CloudFront:** global content delivery and edge protection.

## Connecting the enterprise

Use Site-to-Site VPN for encrypted connectivity over the internet and as a fast
starting point or backup. Use Direct Connect for private, more predictable
network connectivity. Direct Connect is not encryption by itself; add the
appropriate encryption where required.

For many VPCs, use a hub-and-spoke design with Transit Gateway or Cloud WAN.
Keep routing domains and responsibilities clear. Inspect traffic centrally only
when the compliance value justifies the cost and dependency.

## Design questions

- Can CIDR ranges overlap with acquisitions or partner networks?
- Which flows are actually required?
- Where does DNS resolve for hybrid systems?
- What happens if one link or AZ fails?
- Which egress paths are allowed and logged?
- Is latency suitable for chatty SAP or database protocols?

## Common trap

A private subnet is not automatically secure. It still needs least-privilege
security groups, controlled egress, patching, logging, and protected identities.
