Cloud Networking (AWS) ยท Cloud 1

Cloud networking from zero: regions, VPCs and the AWS CLI

What a cloud network is and what it is not. Regions and Availability Zones, the VPC as your own private address space, the shared-responsibility line, then the skill everything else builds on: driving the cloud from the AWS CLI, with credentials, regions, filters and --query.

30 min read5 chapters2 labs5 quiz

This first module is free: read the lesson and take the quiz. Create a free account to run up to 3 hands-on labs.

Log inStart free
Jump to chapter (5)
01

A cloud network is the same networking, rented by the hour

Nothing about IP, routing or firewalls changes in the cloud. What changes is who owns the boxes and how you configure them: not a console cable but an API. Every network object is a resource with an ID that you create, tag, change and delete from a CLI, a console or code.

  • Region: a geographic area with its own independent set of services (ap-south-1 is Mumbai). Resources live in exactly one region.
  • Availability Zone (AZ): one or more data centres inside a region (ap-south-1a, 1b, 1c). Spread across AZs to survive a building failure.
  • VPC: your private, isolated network inside a region, with an address range you choose (for example 10.0.0.0/16).
  • Shared responsibility: the provider runs the physical network and the hypervisor; you own the addressing, routes, security groups, ACLs and what runs on your instances.
02

Pick the VPC range like you will have to peer it one day

  • A VPC takes a CIDR between /16 and /28. Use RFC 1918 space (10/8, 172.16/12, 192.168/16).
  • Never overlap ranges you may connect later (peering, Transit Gateway, VPN to the office). Overlapping CIDRs cannot be peered. Plan one address plan for the whole company.
  • AWS reserves 5 addresses in every subnet (network, router, DNS, future use, broadcast). A /24 gives 251 usable, not 254.
  • A subnet lives in one AZ; a VPC spans all AZs of its region.
03

Drive the cloud from the CLI: credentials, region, output

aws configure set aws_access_key_id AKIA...
aws configure set aws_secret_access_key ...
aws configure set region ap-south-1
aws sts get-caller-identity          # who am I, which account?

The CLI reads ~/.aws/credentials and ~/.aws/config. Two errors every beginner meets: Unable to locate credentials and You must specify a region. In real life use short-lived role credentials, never a long-lived key in a script.

04

Find things: --filters, --query and --output text

aws ec2 describe-vpcs                                          # full JSON
aws ec2 describe-vpcs --query 'Vpcs[].[VpcId,CidrBlock]' --output table
aws ec2 describe-subnets --filters Name=vpc-id,Values=vpc-0abc --query 'Subnets[].CidrBlock' --output text
aws ec2 describe-vpcs --region us-east-1                      # another region = another world
  • --filters is evaluated by the service (fast, server side); --query is a JMESPath expression run on the result on your side.
  • --output text gives clean values for shell variables: VPC=$(aws ec2 create-vpc ... --query Vpc.VpcId --output text).
  • Resources are per region. A VPC you cannot see is often in another region.
05

Tag everything: Name tags make IDs readable

IDs like vpc-0b9e5ea8bb7b203bd mean nothing to a human. Give every resource a Name tag at creation time with --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=prod}]' or afterwards with aws ec2 create-tags --resources vpc-0abc --tags Key=Name,Value=prod. Tags also drive cost reports and access control, so teams add Environment, Owner and CostCentre too.

๐ŸŽ“ For educational purposes only โ€” all devices are simulationsTerms of UsePrivacy Policyยฉ 2026 Network Kings
CONFIG by Network Kings โ€” an educational IT simulation platform for learning purposes only. It is not Cisco IOS, Junos, FortiOS or PAN-OS and contains no Cisco, Juniper, Fortinet or Palo Alto Networks software. Cisco, IOS, CCNA, CCNP, Juniper, JNCIA, JNCIS, JNCIP, Fortinet, FortiGate, FortiOS, NSE, Palo Alto Networks, PAN-OS and PCNSE are trademarks of their respective owners. Network Kings is not affiliated with or endorsed by Cisco Systems, Inc., Juniper Networks, Inc., Fortinet, Inc. or Palo Alto Networks, Inc.