AWS Networking Basics: VPC, Subnets & AZs
AWS Networking (ANS-C01 track) AWS console — free tier (GUI + CLI)
مقصدObjectiveObjective
ریجن، ایویلیبلٹی زون، VPC، سب نیٹس اور CIDR کو سمجھ کر اپنا پہلا VPC بنانا۔Region, Availability Zone, VPC, subnets aur CIDR ko samajh kar apna pehla VPC banana.Understand regions, Availability Zones, VPCs, subnets, and CIDR, and build your first VPC.
آسان مثالSimple AnalogySimple Analogy
ریجن ایک شہر ہے، ایویلیبلٹی زون اس کے الگ الگ محلے (ہر ایک میں اپنا ڈیٹا سینٹر)۔ VPC آپ کی اپنی بلڈنگ ہے، سب نیٹ اس کی منزلیں، اور CIDR پتوں کی رینج جیسے کمرے نمبر۔Region ek sheher hai, Availability Zone us ke alag alag mohallay (har ek mein apna data center). VPC aap ki apni building hai, subnet us ki manzilein, aur CIDR paton ki range jaise kamray number.A region is a city, and Availability Zones are its separate districts (each with its own data center). A VPC is your own building, subnets are its floors, and CIDR is the address range — like room numbers.
سیٹ اپLab SetupLab Setup
آپ کو ایک AWS فری ٹیئر اکاؤنٹ چاہیے۔ ہم ایک ریجن (مثلاً ap-south-1 ممبئی) میں 10.0.0.0/16 رینج والا ایک VPC اور دو ایویلیبلٹی زونز میں سب نیٹس بنائیں گے۔Aap ko ek AWS free tier account chahiye. Hum ek region (masalan ap-south-1 Mumbai) mein 10.0.0.0/16 range wala ek VPC aur do Availability Zones mein subnets banayenge.You need an AWS free tier account. We will create a VPC with the 10.0.0.0/16 range in one region (e.g. ap-south-1 Mumbai) and subnets across two Availability Zones.
اقداماتStepsSteps
Step 1
AWS کنسول میں اپنا ریجن منتخب کریں (اوپر دائیں کونے سے)۔ ریجن وہ جغرافیائی علاقہ ہے جہاں آپ کے وسائل چلیں گے۔AWS console mein apna region select karein (uper right corner se). Region woh geographic area hai jahan aap ke resources chalenge.Pick your region in the AWS console (top-right corner). A region is the geographic area where your resources will run.
🖱️ کنسول ہیڈر > ریجن ڈراپ ڈاؤن > مثلاً Asia Pacific (Mumbai) ap-south-1Console header > Region dropdown > masalan Asia Pacific (Mumbai) ap-south-1Console header > Region dropdown > e.g. Asia Pacific (Mumbai) ap-south-1
Step 2
اب VPC بنائیں۔ VPC آپ کا اپنا الگ ورچوئل نیٹ ورک ہے۔ CIDR بلاک 10.0.0.0/16 دیں — اس میں 65,536 IP پتوں کی گنجائش ہے۔Ab VPC banayein. VPC aap ka apna isolated virtual network hai. CIDR block 10.0.0.0/16 dein — is mein 65,536 IP addresses ki gunjaish hai.Now create the VPC. A VPC is your own isolated virtual network. Give it the CIDR block 10.0.0.0/16 — it holds 65,536 IP addresses.
aws ec2 create-vpc --cidr-block 10.0.0.0/16 --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=LabVPC}]'🖱️ VPC > Your VPCs > Create VPC > نام LabVPC، IPv4 CIDR 10.0.0.0/16 > CreateVPC > Your VPCs > Create VPC > Name LabVPC, IPv4 CIDR 10.0.0.0/16 > CreateVPC > Your VPCs > Create VPC > name LabVPC, IPv4 CIDR 10.0.0.0/16 > Create
Step 3
VPC پر DNS hostnames آن کریں تاکہ EC2 انسٹنسز کو DNS نام مل سکیں۔ ہر AWS ریجن میں کم از کم 2 ایویلیبلٹی زونز ہوتے ہیں۔VPC par DNS hostnames on karein taake EC2 instances ko DNS name mil sakein. Har AWS region mein kam az kam 2 Availability Zones hotay hain.Enable DNS hostnames on the VPC so EC2 instances get DNS names. Every AWS region has at least 2 Availability Zones.
aws ec2 modify-vpc-attribute --vpc-id vpc-0123456789abcdef0 --enable-dns-hostnames '{"Value":true}'🖱️ VPC > Your VPCs > LabVPC منتخب کریں > Actions > Edit VPC settings > DNS hostnames: Enable > SaveVPC > Your VPCs > LabVPC select karein > Actions > Edit VPC settings > DNS hostnames: Enable > SaveVPC > Your VPCs > select LabVPC > Actions > Edit VPC settings > DNS hostnames: Enable > Save
Step 4
پہلا سب نیٹ بنائیں: پبلک سب نیٹ 10.0.1.0/24 پہلے AZ میں۔ سب نیٹ VPC کی رینج کا ایک حصہ ہے اور ہمیشہ ایک ہی AZ میں رہتا ہے۔Pehla subnet banayein: public subnet 10.0.1.0/24 pehle AZ mein. Subnet VPC ki range ka ek hissa hai aur hamesha ek hi AZ mein rehta hai.Create the first subnet: public subnet 10.0.1.0/24 in the first AZ. A subnet is a slice of the VPC's range and always lives in a single AZ.
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.0.1.0/24 --availability-zone ap-south-1a --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=LabPublicA}]'🖱️ VPC > Subnets > Create subnet > VPC LabVPC، نام LabPublicA، AZ ap-south-1a، CIDR 10.0.1.0/24 > CreateVPC > Subnets > Create subnet > VPC LabVPC, Name LabPublicA, AZ ap-south-1a, CIDR 10.0.1.0/24 > CreateVPC > Subnets > Create subnet > VPC LabVPC, Name LabPublicA, AZ ap-south-1a, CIDR 10.0.1.0/24 > Create
Step 5
پرائیویٹ سب نیٹ بنائیں: 10.0.2.0/24 اسی AZ میں۔ پبلک اور پرائیویٹ سب نیٹ کا فرق ان کے روٹ ٹیبل سے ہوتا ہے، جو اگلے سبق میں دیکھیں گے۔Private subnet banayein: 10.0.2.0/24 usi AZ mein. Public aur private subnet ka farq un ke route table se hota hai, jo aglay lesson mein dekhenge.Create the private subnet: 10.0.2.0/24 in the same AZ. What makes a subnet public or private is its route table, which we cover in the next lesson.
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.0.2.0/24 --availability-zone ap-south-1a --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=LabPrivateA}]'🖱️ VPC > Subnets > Create subnet > نام LabPrivateA، AZ ap-south-1a، CIDR 10.0.2.0/24 > CreateVPC > Subnets > Create subnet > Name LabPrivateA, AZ ap-south-1a, CIDR 10.0.2.0/24 > CreateVPC > Subnets > Create subnet > Name LabPrivateA, AZ ap-south-1a, CIDR 10.0.2.0/24 > Create
Step 6
ہائی ایویلیبلٹی کے لیے دوسرے AZ میں بھی ایک سب نیٹ بنائیں: 10.0.3.0/24 AZ-b میں۔ اگر ایک ڈیٹا سینٹر بند ہو جائے تو دوسرا چلتا رہے۔High availability ke liye doosray AZ mein bhi ek subnet banayein: 10.0.3.0/24 AZ-b mein. Agar ek data center band ho jaye to doosra chalta rahe.Add a subnet in the second AZ for high availability: 10.0.3.0/24 in AZ-b. If one data center fails, the other keeps running.
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.0.3.0/24 --availability-zone ap-south-1b --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=LabPublicB}]'🖱️ VPC > Subnets > Create subnet > نام LabPublicB، AZ ap-south-1b، CIDR 10.0.3.0/24 > CreateVPC > Subnets > Create subnet > Name LabPublicB, AZ ap-south-1b, CIDR 10.0.3.0/24 > CreateVPC > Subnets > Create subnet > Name LabPublicB, AZ ap-south-1b, CIDR 10.0.3.0/24 > Create
تصدیقVerifyVerify
VPC کنسول میں LabVPC نظر آئے جس کا CIDR 10.0.0.0/16 ہو، اور Subnets صفحے پر تینوں سب نیٹس درست CIDR اور AZ کے ساتھ Available حالت میں ہوں۔VPC console mein LabVPC nazar aaye jis ka CIDR 10.0.0.0/16 ho, aur Subnets page par teeno subnets durust CIDR aur AZ ke saath Available state mein hon.In the VPC console you see LabVPC with CIDR 10.0.0.0/16, and on the Subnets page all three subnets are Available with the correct CIDRs and AZs.
aws ec2 describe-vpcs --filters Name=tag:Name,Values=LabVPC --query 'Vpcs[*].[VpcId,CidrBlock,State]' --output table aws ec2 describe-subnets --filters Name=vpc-id,Values=vpc-0123456789abcdef0 --query 'Subnets[*].[Tags[?Key==`Name`].Value|[0],CidrBlock,AvailabilityZone,State]' --output table
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ سب نیٹ بناتے وقت 'CIDR overlaps' کی خرابی آتی ہے۔Subnet banatay waqt 'CIDR overlaps' ki error aati hai.You get a 'CIDR overlaps' error when creating a subnet.
✅ نئی CIDR رینج VPC کی رینج کے اندر ہونی چاہیے اور موجودہ سب نیٹس سے ٹکرا نہیں سکتی۔ مثلاً 10.0.1.0/24 کے بعد 10.0.2.0/24 استعمال کریں۔Nayi CIDR range VPC ki range ke andar honi chahiye aur maujooda subnets se takra nahi sakti. Masalan 10.0.1.0/24 ke baad 10.0.2.0/24 use karein.The new CIDR must be inside the VPC range and must not overlap existing subnets. For example, use 10.0.2.0/24 after 10.0.1.0/24.
⚠️ وسائل غلط AZ میں بن گئے۔Resources ghalat AZ mein ban gaye.Resources were created in the wrong AZ.
✅ سب نیٹ بناتے وقت AZ واضح طور پر منتخب کریں۔ ایک بار بننے کے بعد سب نیٹ کا AZ تبدیل نہیں ہو سکتا — نیا سب نیٹ بنانا پڑے گا۔Subnet banatay waqt AZ wazeh taur par select karein. Ek dafa banne ke baad subnet ka AZ tabdeel nahi ho sakta — naya subnet banana paray ga.Select the AZ explicitly when creating the subnet. A subnet's AZ cannot be changed after creation — you must create a new one.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ ریجن اور ایویلیبلٹی زون میں کیا فرق ہے؟Region aur Availability Zone mein kya farq hai?What is the difference between a region and an Availability Zone?
ریجن ایک جغرافیائی علاقہ ہے (جیسے ممبئی)۔ ایویلیبلٹی زون اسی ریجن کے اندر الگ الگ ڈیٹا سینٹرز ہیں، جو ایک دوسرے سے آئسولیٹڈ مگر تیز لنک سے جڑے ہوتے ہیں۔Region ek geographic area hai (jaise Mumbai). Availability Zone usi region ke andar alag alag data centers hain, jo ek doosray se isolated magar fast link se juray hotay hain.A region is a geographic area (like Mumbai). Availability Zones are separate data centers inside that region — isolated from each other but connected by fast links.
❓ ڈیفالٹ VPC اور کسٹم VPC میں کیا فرق ہے؟Default VPC aur custom VPC mein kya farq hai?What is the difference between a default VPC and a custom VPC?
ڈیفالٹ VPC ہر ریجن میں پہلے سے بنا ہوتا ہے، اس میں انٹرنیٹ گیٹ وے اور پبلک سب نیٹس ہوتے ہیں۔ کسٹم VPC آپ خود بناتے ہیں اور CIDR، سب نیٹس اور روٹس پر مکمل کنٹرول رکھتے ہیں۔Default VPC har region mein pehle se bana hota hai, is mein internet gateway aur public subnets hotay hain. Custom VPC aap khud banatay hain aur CIDR, subnets aur routes par mukammal control rakhtay hain.A default VPC comes pre-built in every region with an internet gateway and public subnets. A custom VPC is one you build yourself, with full control over CIDR, subnets, and routes.