Capstone: Public/Private VPC with Security
AWS Networking (ANS-C01 track) AWS console — free tier (GUI + CLI)
مقصدObjectiveObjective
اس کیپ اسٹون میں آپ AWS میں production-style VPC بنائیں گے — پبلک اور پرائیویٹ سب نیٹس، آگے ALB، سیکیورٹی گروپس اور NACLs، اور Flow Logs — سخت cost hygiene کے ساتھ۔Is capstone mein aap AWS mein production-style VPC banayenge — public aur private subnets, aage ALB, security groups aur NACLs, aur Flow Logs — sakht cost hygiene ke saath.In this capstone you will build a production-style AWS VPC with public and private subnets, an ALB in front, security groups and NACLs, and Flow Logs — with strict cost hygiene.
آسان مثالSimple AnalogySimple Analogy
یہ ایسے ہے جیسے ایک دکان ہو جس میں کھلا شوروم اور بند گودام ہو: گاہک شوروم (public subnets) میں آزادانہ آ سکتے ہیں، لیکن اسٹاک روم (private subnets) تک صرف اسٹاف والے راستے (NAT گیٹ وے) سے پہنچا جا سکتا ہے۔Yeh aisa hai jaise ek dukan ho jis mein khula showroom aur band godam ho: gahak showroom (public subnets) mein aazadana aa sakte hain, lekin stock room (private subnets) tak sirf staff wale raaste (NAT gateway) se pahuncha ja sakta hai.This is like a shop with a public showroom and a locked warehouse: customers enter the showroom (public subnets) freely, but the stock room (private subnets) is reached only through a staff-only corridor (NAT gateway).
سیٹ اپLab SetupLab Setup
آپ کو AWS فری ٹیئر کا اکاؤنٹ اور ایک ریجن (us-east-1 استعمال کریں) درکار ہے۔ نیچے تمام IDs subnet-0123456789abcdef0 طرز کی مثالی IDs ہیں — اپنے کنسول آؤٹ پٹ سے اصلی IDs کاپی کریں۔Aap ko AWS free tier ka account aur ek region (us-east-1 istemal karein) darkar hai. Neeche tamam IDs subnet-0123456789abcdef0 tarz ki misali IDs hain — apne console output se asli IDs copy karein.You need an AWS free-tier account and one region (use us-east-1). All IDs below are examples in the style subnet-0123456789abcdef0 — copy real IDs from your own console output.
اقداماتStepsSteps
Step 1
VPC (10.10.0.0/16) بنائیں جس میں دو AZs میں دو پبلک سب نیٹس اور انہی AZs میں دو پرائیویٹ سب نیٹس ہوں۔ دو AZs آپ کو محفوظ رکھتے ہیں اگر ایک زون فیل ہو جائے۔VPC (10.10.0.0/16) banayen jis mein do AZs mein do public subnets aur unhi AZs mein do private subnets hon. Do AZs aap ko mehfooz rakhte hain agar ek zone fail ho jaye.Create the VPC (10.10.0.0/16) with two public subnets in two AZs and two private subnets in the same AZs. Two AZs keep you resilient if one zone fails.
aws ec2 create-vpc --cidr-block 10.10.0.0/16 --tag-specifications 'ResourceType=vpc,Tags=[{Key=Name,Value=netsec-vpc}]'
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.10.1.0/24 --availability-zone us-east-1a --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=public-a}]'
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.10.2.0/24 --availability-zone us-east-1b --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=public-b}]'
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.10.11.0/24 --availability-zone us-east-1a --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=private-a}]'
aws ec2 create-subnet --vpc-id vpc-0123456789abcdef0 --cidr-block 10.10.12.0/24 --availability-zone us-east-1b --tag-specifications 'ResourceType=subnet,Tags=[{Key=Name,Value=private-b}]'🖱️ کنسول میں جائیںConsole mein jayenVPC > Your VPCs > Create VPC
Step 2
VPC کے ساتھ ایک Internet Gateway attach کریں اور پبلک روٹ ٹیبل کے default route (0.0.0.0/0) کو اسی کی طرف موڑیں۔ یہ روٹ صرف پبلک سب نیٹس کو ملتا ہے — پرائیویٹ سب نیٹس پوشیدہ رہتے ہیں۔VPC ke saath ek Internet Gateway attach karein aur public route table ke default route (0.0.0.0/0) ko isi ki taraf morhen. Yeh route sirf public subnets ko milta hai — private subnets poshida rehte hain.Attach an Internet Gateway to the VPC and point the public route table's default route (0.0.0.0/0) at it. Only the public subnets get this route — the private ones stay hidden.
aws ec2 create-internet-gateway --tag-specifications 'ResourceType=internet-gateway,Tags=[{Key=Name,Value=netsec-igw}]'
aws ec2 attach-internet-gateway --vpc-id vpc-0123456789abcdef0 --internet-gateway-id igw-0123456789abcdef0
aws ec2 create-route-table --vpc-id vpc-0123456789abcdef0 --tag-specifications 'ResourceType=route-table,Tags=[{Key=Name,Value=public-rt}]'
aws ec2 create-route --route-table-id rtb-0123456789abcdef0 --destination-cidr-block 0.0.0.0/0 --gateway-id igw-0123456789abcdef0
aws ec2 associate-route-table --route-table-id rtb-0123456789abcdef0 --subnet-id subnet-0123456789abcdef0🖱️ کنسول میں جائیںConsole mein jayenVPC > Internet gateways > Create internet gateway
Step 3
ایک پبلک سب نیٹ میں NAT گیٹ وے بنائیں تاکہ پرائیویٹ ورک لوڈز اپ ڈیٹس کے لیے انٹرنیٹ تک پہنچ سکیں لیکن خود انٹرنیٹ سے پوشیدہ رہیں۔ COST WARNING: NAT گیٹ وے ہر گھنٹے اور ڈیٹا کی قیمت لیتا ہے — اس لیب کے فوراً بعد اسے ڈیلیٹ کر دیں۔Ek public subnet mein NAT gateway banayen taake private workloads updates ke liye internet tak pahunch saken lekin khud internet se poshida rahen. COST WARNING: NAT gateway har ghante aur data ki qeemat leta hai — is lab ke foran baad ise delete kar dein.Create a NAT gateway in a public subnet so private workloads can reach the internet for updates without being reachable themselves. COST WARNING: the NAT gateway is billed per hour plus data — delete it right after this lab.
aws ec2 allocate-address --domain vpc
aws ec2 create-nat-gateway --subnet-id subnet-0123456789abcdef0 --allocation-id eipalloc-0123456789abcdef0 --tag-specifications 'ResourceType=natgateway,Tags=[{Key=Name,Value=netsec-nat}]'
aws ec2 create-route-table --vpc-id vpc-0123456789abcdef0 --tag-specifications 'ResourceType=route-table,Tags=[{Key=Name,Value=private-rt}]'
aws ec2 create-route --route-table-id rtb-0123456789abcdef1 --destination-cidr-block 0.0.0.0/0 --nat-gateway-id nat-0123456789abcdef0🖱️ کنسول میں جائیںConsole mein jayenVPC > NAT gateways > Create NAT gateway
Step 4
سیکیورٹی گروپس بنائیں: web-sg کہیں سے بھی HTTPS کی اجازت دیتا ہے، app-sg صرف web-sg سے ٹریفک کی اجازت دیتا ہے۔ پھر پبلک سب نیٹس کے لیے ایک NACL بنائیں۔ دفاع کی دو پرتیں — دربان اور turnstile دونوں۔Security groups banayen: web-sg kahin se bhi HTTPS ki ijazat deta hai, app-sg sirf web-sg se traffic ki ijazat deta hai. Phir public subnets ke liye ek NACL banayen. Difa ki do paraten — darban aur turnstile dono.Create security groups: web-sg allows HTTPS from anywhere, app-sg allows traffic only from web-sg. Then create a NACL for the public subnets. Two layers of defence — the bouncer and the turnstile.
aws ec2 create-security-group --group-name web-sg --description 'web tier' --vpc-id vpc-0123456789abcdef0
aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef0 --protocol tcp --port 443 --cidr 0.0.0.0/0
aws ec2 create-security-group --group-name app-sg --description 'app tier' --vpc-id vpc-0123456789abcdef0
aws ec2 authorize-security-group-ingress --group-id sg-0123456789abcdef1 --protocol tcp --port 8080 --source-group sg-0123456789abcdef0
aws ec2 create-network-acl --vpc-id vpc-0123456789abcdef0 --tag-specifications 'ResourceType=network-acl,Tags=[{Key=Name,Value=public-nacl}]'🖱️ کنسول میں جائیںConsole mein jayenVPC > Security groups > Create security group
Step 5
دونوں پبلک سب نیٹس میں web-sg کے ساتھ ایک Application Load Balancer بنائیں۔ نوٹ: ALB بھی ہر گھنٹے کی قیمت لیتا ہے — اسے ٹیسٹ کریں، پھر آخر میں NAT گیٹ وے کے ساتھ ڈیلیٹ کر دیں۔Dono public subnets mein web-sg ke saath ek Application Load Balancer banayen. Note: ALB bhi har ghante ki qeemat leta hai — ise test karein, phir aakhir mein NAT gateway ke saath delete kar dein.Create an Application Load Balancer across both public subnets with web-sg attached. Note: the ALB is also billed per hour — test it, then delete it with the NAT gateway at the end.
aws elbv2 create-load-balancer --name netsec-alb --subnets subnet-0123456789abcdef0 subnet-0123456789abcdef1 --security-groups sg-0123456789abcdef0 aws elbv2 create-target-group --name netsec-tg --protocol HTTP --port 80 --vpc-id vpc-0123456789abcdef0
🖱️ کنسول میں جائیںConsole mein jayenEC2 > Load Balancers > Create load balancer
Step 6
CloudWatch تک VPC Flow Logs فعال کریں تاکہ آپ ہر allowed اور rejected packet دیکھ سکیں۔ یہ آپ کی CCTV فوٹیج ہے — اس کے بغیر آپ اندھوں کی طرح troubleshooting کریں گے۔CloudWatch tak VPC Flow Logs fa-aal karein taake aap har allowed aur rejected packet dekh saken. Yeh aap ki CCTV footage hai — is ke baghair aap andhon ki tarah troubleshooting karenge.Enable VPC Flow Logs to CloudWatch so you can see every allowed and rejected packet. This is your CCTV footage — without it you are troubleshooting blind.
aws logs create-log-group --log-group-name netsec-flowlogs aws ec2 create-flow-logs --resource-type VPC --resource-ids vpc-0123456789abcdef0 --traffic-type ALL --log-destination-type cloud-watch-logs --log-group-name netsec-flowlogs --deliver-logs-permission-arn arn:aws:iam::123456789012:role/flowlogs-role
🖱️ کنسول میں جائیںConsole mein jayenVPC > Your VPCs > select VPC > Flow Logs tab > Create flow log
Step 7
صفائی: ALB ڈیلیٹ کریں، NAT گیٹ وے ڈیلیٹ کریں اور Elastic IP ریلیز کریں، پھر VPC ڈیلیٹ کر دیں۔ فری ٹیئر بھولے ہوئے billed ریسورسز کو معاف نہیں کرتا۔Safai: ALB delete karein, NAT gateway delete karein aur Elastic IP release karein, phir VPC delete kar dein. Free tier bhoole hue billed resources ko maaf nahi karta.Clean up: delete the ALB, the NAT gateway and release the Elastic IP, then delete the VPC. Free tier does not forgive forgotten billed resources.
aws elbv2 delete-load-balancer --load-balancer-arn arn:aws:elasticloadbalancing:us-east-1:123456789012:loadbalancer/app/netsec-alb/0123456789abcdef aws ec2 delete-nat-gateway --nat-gateway-id nat-0123456789abcdef0 aws ec2 release-address --allocation-id eipalloc-0123456789abcdef0
🖱️ کنسول میں جائیںConsole mein jayenVPC > Your VPCs > select VPC > Delete VPC
تصدیقVerifyVerify
ALB کے DNS نام پر curl کریں اور بیک اینڈ سے جواب حاصل کریں، پھر netsec-flowlogs کے نیچے CloudWatch Logs میں اپنے ٹیسٹ ٹریفک کے ACCEPT اور REJECT اندراجات دیکھیں۔ALB ke DNS name par curl karein aur backend se jawab hasil karein, phir netsec-flowlogs ke neeche CloudWatch Logs mein apne test traffic ke ACCEPT aur REJECT entries dekhen.Curl the ALB DNS name and get a response from the backend, then check CloudWatch Logs under netsec-flowlogs to see the ACCEPT and REJECT entries for your test traffic.
aws ec2 describe-flow-logs --filter Name=resource-id,Values=vpc-0123456789abcdef0 aws elbv2 describe-target-health --target-group-arn arn:aws:elasticloadbalancing:us-east-1:123456789012:targetgroup/netsec-tg/0123456789abcdef
خرابی دور کرناTroubleshootingTroubleshooting
⚠️ پرائیویٹ سب نیٹ میں EC2 انسٹینس انٹرنیٹ تک نہیں پہنچ پا رہا۔Private subnet mein EC2 instance internet tak nahi pahunch pa raha.An EC2 instance in the private subnet cannot reach the internet.
✅ پرائیویٹ روٹ ٹیبل چیک کریں: 0.0.0.0/0 کا روٹ NAT گیٹ وے کی طرف ہونا چاہیے، اور NAT گیٹ وے خود ایک پبلک سب نیٹ میں ہو جس کا روٹ Internet Gateway کی طرف ہو۔Private route table check karein: 0.0.0.0/0 ka route NAT gateway ki taraf hona chahiye, aur NAT gateway khud ek public subnet mein ho jis ka route Internet Gateway ki taraf ho.Check the private route table: 0.0.0.0/0 must point to the NAT gateway, and the NAT gateway itself must be in a public subnet with a route to the Internet Gateway.
⚠️ ALB 503 Service Unavailable دے رہا ہے۔ALB 503 Service Unavailable de raha hai.The ALB returns 503 Service Unavailable.
✅ ٹارگٹ ہیلتھ چیک کریں: ٹارگٹس کے سیکیورٹی گروپ میں ALB کے سیکیورٹی گروپ سے ٹریفک کی اجازت ہونی چاہیے، اور health-check path 200 واپس کرے۔Target health check karein: targets ke security group mein ALB ke security group se traffic ki ijazat honi chahiye, aur health-check path 200 wapas kare.Check target health: the targets' security group must allow traffic from the ALB's security group, and the health-check path must return 200.
⚠️ NAT گیٹ وے بہت دیر سے Deleting کی حالت میں پھنسا ہے۔NAT gateway bohat der se Deleting ki halat mein phansa hai.The NAT gateway is stuck in Deleting state for a long time.
✅ یہ نارمل ہے — ڈیلیشن میں کئی منٹ لگ سکتے ہیں۔ اس دوران دوسرا NAT گیٹ وے نہ بنائیں، اور Elastic IP صرف تب ریلیز کریں جب گیٹ وے مکمل طور پر ڈیلیٹ ہو چکا ہو۔Yeh normal hai — deletion mein kai minute lag sakte hain. Is doran doosra NAT gateway na banayen, aur Elastic IP sirf tab release karein jab gateway mukammal tor par delete ho chuka ho.This is normal — deletion can take several minutes. Do not create a second NAT gateway meanwhile, and release the Elastic IP only after the gateway is fully deleted.
انٹرویو سوالاتInterview Q&AInterview Q&A
❓ سیکیورٹی گروپ اور NACL میں کیا فرق ہے؟ (پریکٹس)Security group aur NACL mein kya farq hai? (practice)Security group vs NACL — what is the difference? (practice)
سیکیورٹی گروپ stateful ہوتا ہے اور ریسورسز پر لگتا ہے؛ NACL stateless ہوتا ہے اور سب نیٹ پر لگتا ہے۔ سمجھیں: سیکیورٹی گروپ وہ دربان ہے جو آپ کو یاد رکھتا ہے، NACL وہ turnstile ہے جو ہر پاس چیک کرتا ہے۔Security group stateful hota hai aur resources par lagta hai; NACL stateless hota hai aur subnet par lagta hai. Samjhen: security group woh darban hai jo aap ko yaad rakhta hai, NACL woh turnstile hai jo har pass check karta hai.A security group is stateful and attached to resources; a NACL is stateless and attached to the subnet. Think: security group is a bouncer who remembers you, NACL is a turnstile that checks every pass.
❓ ورک لوڈز کو private subnets میں کیوں رکھیں؟ (پریکٹس)Workloads ko private subnets mein kyun rakhen? (practice)Why put workloads in private subnets? (practice)
ورک لوڈز کی حفاظت کے لیے: ڈیٹابیس اور ایپلیکیشن سرورز کو کبھی سیدھا انٹرنیٹ نہیں چاہیے ہوتا۔ Private subnets حملہ آور سطح کو چھوٹا کرتے ہیں، اور NAT گیٹ وے انہیں محفوظ طریقے سے اپ ڈیٹس لینے دیتا ہے۔Workloads ki hifazat ke liye: database aur application servers ko kabhi seedha internet nahi chahiye hota. Private subnets hamla-awar satah ko chhota karte hain, aur NAT gateway inhen mehfooz tareeqe se updates lene deta hai.To protect workloads: database and application servers never need direct internet. Private subnets shrink the attack surface, and the NAT gateway lets them fetch updates safely.