Lesson 013 · AWS Learning Path

AWS 013: IP addresses, CIDR and subnetting

· Published · 5 min read

A large network address space is divided into organized non-overlapping subnet blocks

The problem

A team builds overlapping networks, chooses subnets too small for scaling, treats private addresses as security controls, and cannot explain which addresses belong to a CIDR block.

CIDR planning is an architecture skill, not an AWS Console field to guess.

Learning outcomes

You will be able to:

  1. explain what the private range 10.0.0.0/8 represents;
  2. trace an address plan from 10.0.0.0/8 to a /16 VPC and /20 subnets;
  3. explain IPv4 and IPv6 address length;
  4. interpret CIDR prefix notation;
  5. calculate IPv4 block size, range, and subnet boundaries;
  6. distinguish public, private, and routable behavior;
  7. create non-overlapping subnet ranges with room for growth;
  8. account for AWS-reserved subnet addresses.

Addresses and routes

An IP address identifies a network interface in an IP context. A route decides where a packet for a destination prefix should go.

IPv4 uses 32 bits, commonly written as four decimal octets:

10.20.1.25

IPv6 uses 128 bits, written in hexadecimal groups:

2001:db8:1234:1::25

IPv6 zero compression can replace one consecutive run of zero groups with ::. It can be used only once in an address.

Start with 10.0.0.0/8

RFC 1918 reserves this range for private IPv4 networks:

10.0.0.0/8

The /8 means that the first 8 of the 32 IPv4 bits identify the network. The remaining 24 bits provide this address space:

First address:  10.0.0.0
Last address:   10.255.255.255
Total:          2^(32 - 8) = 16,777,216 addresses

Treat 10.0.0.0/8 as a private address-planning pool. Do not enter it as the CIDR of the course VPC. An Amazon VPC IPv4 CIDR must currently be between /16 and /28, so the course selects a smaller, non-overlapping /16 allocation from the private pool.

The address hierarchy used in this program is:

10.0.0.0/8          RFC 1918 private planning pool
└── 10.20.0.0/16    selected course VPC allocation
    ├── 10.20.0.0/20
    ├── 10.20.16.0/20
    ├── 10.20.32.0/20
    └── additional /20 subnet blocks

The /8 range is private, but it is not globally unique. Many companies use parts of it. Before connecting a VPC to an office, data center, partner, peered VPC, or transit network, coordinate the allocation and check for overlap.

Understand CIDR notation

CIDR writes an address followed by the number of network-prefix bits:

10.0.0.0/8

For IPv4:

host bits = 32 - prefix length
block size = 2 ^ host bits

Examples:

CIDRHost bitsTotal IPv4 addresses
/82416,777,216
/161665,536
/20124,096
/248256
/28416

A larger prefix number creates a smaller block. /28 is smaller than /24.

Do not use class A, B, and C thinking for modern network design. Use CIDR.

Calculate subnet boundaries

First, select 10.20.0.0/16 from the larger 10.0.0.0/8 planning pool.

Moving from /8 to /16 adds 8 network bits, so the /8 contains:

2^(16 - 8) = 256 possible /16 blocks

Examples include 10.0.0.0/16, 10.1.0.0/16, and 10.20.0.0/16. Selecting one block does not mean every other block is available to your organization. The address plan must record allocations and connected-network ranges.

Next, split the selected 10.20.0.0/16 into /20 blocks.

A /20 contains 4,096 addresses. Its third octet advances by 16:

10.20.0.0/20    10.20.0.0   through 10.20.15.255
10.20.16.0/20   10.20.16.0  through 10.20.31.255
10.20.32.0/20   10.20.32.0  through 10.20.47.255
10.20.48.0/20   10.20.48.0  through 10.20.63.255

The blocks do not overlap.

Private is not the same as secure

RFC 1918 defines private IPv4 ranges:

10.0.0.0/8
172.16.0.0/12
192.168.0.0/16

These are not globally routed on the public internet. They can still be reachable through connected private networks, VPN, peering, transit, or a compromised host.

Security depends on routes, identity, security groups, network ACLs, operating-system controls, application authorization, and other layers. A private address alone is not an access-control policy.

AWS subnet behavior

AWS VPC subnet CIDRs must fit inside the VPC CIDR and must not overlap other subnets.

For ordinary Amazon-provided IPv4 subnet ranges, AWS reserves the first four addresses and the last address.

For 10.0.0.0/24, AWS reserves:

10.0.0.0     network address
10.0.0.1     VPC router
10.0.0.2     DNS-related reservation
10.0.0.3     future use
10.0.0.255   reserved; VPC does not support broadcast

So an ordinary /24 has 251 assignable IPv4 addresses in this AWS context, not 254.

AWS currently permits IPv4 VPC subnet sizes from /28 through /16. Verify current documentation when designing.

IPv6 is not large IPv4

IPv6 provides a much larger address space and restores end-to-end addressability principles. A globally unique IPv6 address can be internet-routable, but reachability still requires routing and security policy.

Do not assume:

  • IPv6 is private because no IPv4 public address exists;
  • NAT is a required IPv6 security control;
  • every AWS service supports identical IPv6 behavior;
  • an IPv4-only design can gain IPv6 later without application, DNS, logging, and security changes.

Practical subnet plan

Create:

mkdir -p "$HOME/nitwings-aws/evidence/aws-013"

Begin with the RFC 1918 planning pool 10.0.0.0/8. Select 10.20.0.0/16 as the course VPC allocation, and then plan its subnets across two Availability Zones:

PurposeAZ AAZ B
Public ingress10.20.0.0/2010.20.16.0/20
Private application10.20.32.0/2010.20.48.0/20
Isolated data10.20.64.0/2010.20.80.0/20
Reserved growth10.20.96.0/19 and remaining range

Create subnet-plan.md containing:

  • each CIDR;
  • first and last address;
  • total and AWS-assignable IPv4 count;
  • purpose;
  • failure-domain placement;
  • routing intention;
  • growth reservation;
  • overlap check;
  • on-premises or peer-network overlap risk.
  • an explanation of why 10.0.0.0/8 is a planning pool rather than the CIDR entered for this VPC.

For a /20, subtract five AWS-reserved addresses from 4,096 for ordinary assignable use.

Canonical form

If an address has host bits set, a platform can canonicalize it to the network boundary.

Example:

10.20.18.7/20

belongs to:

10.20.16.0/20

Do not treat the typed host address as the subnet start.

Troubleshooting

SymptomLikely causeCheck
Subnet rejectedOutside VPC, overlap, invalid size, or noncanonical expectationparent range and boundaries
Resource launch says no addressessubnet exhausted or reserved capacityused and available addresses
Hybrid route behaves incorrectlyoverlapping CIDRsall connected address plans
Private host cannot reach internetno valid route or egress designfull packet path
IPv6 host is unexpectedly reachableroute and firewall allow itIPv6 routes and rules

Knowledge check

  1. What range of addresses does 10.0.0.0/8 cover?
  2. How many total addresses are in 10.0.0.0/8?
  3. How many /16 blocks fit inside a /8?
  4. Why should you not enter 10.0.0.0/8 as this course's VPC CIDR?
  5. How many total addresses are in /24?
  6. How many ordinary AWS-assignable addresses remain after five reservations?
  7. Which is larger, /20 or /24?
  8. Does a private IPv4 address prove the host is secure?
  9. What network contains 10.20.18.7/20?

Expected answers: 10.0.0.0 through 10.255.255.255; 16,777,216; 256; AWS VPC IPv4 CIDRs are currently restricted to /16 through /28, and the /8 is the larger planning pool; 256; 251; /20; no; 10.20.16.0/20.

Completion gate

Pass when subnet-plan.md traces 10.0.0.0/8 to the selected 10.20.0.0/16 allocation and then to six non-overlapping /20 subnets. It must contain correct ranges and counts, growth space, two Availability Zones, an overlap-risk statement, and the reason the /8 is not entered as the VPC CIDR.

No AWS resources were created.

Official sources

Advertisement