What Is a VPC in Cloud Computing?
SkillVeris Team
Cloud & Security Team

A VPC (Virtual Private Cloud) is a logically isolated section of a public cloud where you launch resources into a network you fully control.
In this guide, you'll learn:
- You define the IP address range with CIDR notation, then carve it into public and private subnets across multiple availability zones.
- Route tables, internet gateways, and NAT gateways decide which subnets can reach the internet and which stay private.
- Security groups act as stateful firewalls on each resource, while network ACLs filter traffic at the subnet boundary.
- A VPC is the foundation of cloud security — most breaches trace back to a misconfigured network, not a broken application.
1What Is a VPC?
A VPC (Virtual Private Cloud) is a logically isolated virtual network that you provision inside a public cloud provider like AWS, Azure, or Google Cloud. Even though the underlying hardware is shared with other customers, your VPC behaves like a private data center: you choose the IP address range, create subnets, and control exactly what can talk to what.
Think of the public cloud as a giant apartment building. A VPC is your own locked apartment inside it. You decide which rooms connect, which doors face the street, and who gets a key. Nothing enters or leaves without passing rules you defined.
2Why VPCs Matter
Without a VPC, every server you launch would sit on a flat, open network — a security nightmare. The VPC gives you the isolation and control needed to run production workloads safely.
- Isolation: your resources are invisible to other cloud tenants by default.
- Segmentation: separate public web servers from private databases so a compromised front end can't reach your data directly.
- Control: define routing, firewall rules, and internet access down to the individual resource.
- Compliance: many regulations require network isolation, audit logging, and controlled egress — a VPC provides all three.
- Hybrid connectivity: link your VPC to an on-premises data center over VPN or a dedicated line.
🔑Key Idea
A VPC is the single most important security boundary in the cloud. Most real-world breaches come from an exposed subnet or an over-permissive security group — not from clever exploits.
3The Core Building Blocks
A working VPC is assembled from a handful of components that fit together predictably. Learn these five and the rest is detail.
- CIDR block: the VPC's private IP range, e.g. 10.0.0.0/16 gives you 65,536 addresses.
- Subnets: smaller slices of the CIDR range, each tied to one availability zone.
- Route tables: rules that decide where traffic goes based on its destination.
- Internet gateway: the door that lets a public subnet reach the internet.
- NAT gateway: lets private subnets make outbound calls without being reachable from outside.
Public vs Private Subnets
A subnet is public if its route table sends internet-bound traffic to an internet gateway. It is private if it has no such route. Web servers and load balancers live in public subnets; databases, caches, and application servers live in private ones.
4How Traffic Flows Through a VPC
Traffic in a VPC follows route tables the way mail follows postal codes. When a resource sends a packet, the subnet's route table checks the destination and forwards it accordingly — to another subnet, to the internet gateway, or to a NAT gateway.
A typical setup places a load balancer in the public subnet. It accepts requests from the internet, then forwards them to application servers in the private subnet. Those servers query a database in a second private subnet. The database can pull software updates through a NAT gateway but can never be reached from the internet directly.
💡Pro Tip
Spread subnets across at least two availability zones. If one zone fails, your load balancer keeps routing to healthy servers in the other — high availability comes almost for free.
5Security Groups vs Network ACLs
A VPC gives you two firewall layers, and knowing the difference prevents confusing outages. Both filter traffic, but they operate at different levels and behave differently.
Security Groups
Security groups attach to individual resources such as a server or database. They are stateful, meaning if you allow an inbound request, the response is automatically allowed back out. You typically only write allow rules — anything not permitted is denied.
Allow inbound 443 from 0.0.0.0/0 # public HTTPS
Allow inbound 5432 from the app security group # database only from app tier
Stateful: return traffic is automaticNetwork ACLs
Network ACLs sit at the subnet boundary and are stateless — you must write both inbound and outbound rules. They are evaluated in numbered order and support explicit deny rules, which makes them useful for blocking known-bad IP ranges across an entire subnet.
6Connecting VPCs and On-Premises Networks
Real architectures rarely live in a single VPC. You often need to connect several networks together while keeping traffic private and controlled.
- VPC peering: a direct private link between two VPCs, ideal for small numbers of connections.
- Transit gateway: a hub that connects many VPCs and on-premises networks without a mesh of peerings.
- VPN gateway: an encrypted tunnel over the public internet to your own data center.
- PrivateLink / private endpoints: reach a cloud service privately without traffic ever touching the internet.
7The Same Idea Across Clouds
The VPC concept is universal, though each provider names the pieces differently. Learning it on one cloud transfers almost entirely to the others.
- AWS: VPC, subnets, security groups, internet gateway, NAT gateway.
- Azure: Virtual Network (VNet), subnets, network security groups (NSGs), and Azure NAT.
- Google Cloud: VPC network (global by default), subnets, firewall rules, and Cloud NAT.
- The mental model — private range, subnets, routing, firewalls — is identical everywhere.
8Common Mistakes to Avoid
Most VPC problems come from a few predictable missteps. Watch for these before they cause an outage or a breach.
- Choosing overlapping CIDR ranges, which makes future VPC peering or VPN connections impossible.
- Putting databases in public subnets — a database should almost never have a route to the internet gateway.
- Opening security groups to 0.0.0.0/0 on ports like 22 or 3389, exposing SSH or RDP to the whole internet.
- Forgetting a NAT gateway, so private servers cannot download updates or reach external APIs.
- Using a single availability zone, which turns one zone failure into a full outage.
⚠️Watch Out
A CIDR block that is too small can't be resized easily. Start with a /16 for the VPC and hand out /24 subnets — it costs nothing and leaves room to grow.
9Key Takeaways
The essentials of a VPC come down to a handful of durable ideas.
- A VPC is your own isolated, private network inside a shared public cloud.
- You define the IP range with CIDR, then split it into public and private subnets.
- Route tables plus internet and NAT gateways control what reaches the internet.
- Security groups (stateful, per-resource) and network ACLs (stateless, per-subnet) are your two firewall layers.
- The same design applies across AWS, Azure, and Google Cloud under different names.
10Frequently Asked Questions
Q: What is the difference between a VPC and a subnet? A: A VPC is the whole private network with a large IP range; a subnet is a smaller slice of that range tied to one availability zone. A VPC contains many subnets, and each subnet is where you actually launch resources.
Q: Do I need a VPC for a simple website? A: In most modern clouds you get a default VPC automatically, so yes — even a simple site runs inside one. For anything with a database or private data, defining your own VPC with public and private subnets is strongly recommended.
Q: Is a VPC free? A: The VPC itself, subnets, route tables, and security groups cost nothing. You pay for components like NAT gateways, VPN connections, and data transfer, so those are the line items to watch on your bill.
Q: What is the difference between a security group and a network ACL? A: A security group is stateful and attaches to individual resources, so return traffic is allowed automatically. A network ACL is stateless, applies to an entire subnet, and requires you to define both inbound and outbound rules explicitly.
Related Reading
Get The Print Version
Download a PDF of this article for offline reading.
About the Publisher
SkillVeris Team
Cloud & Security Team
Our cloud and security experts break down complex infrastructure topics into practical, beginner-friendly guides.
View all postsRelated Posts
Never miss an update
Get the latest tutorials and guides delivered to your inbox.
No spam. Unsubscribe anytime.