[Demetria Crawford] Hello, my name is Demetria Crawford, and in this lesson we will review the AWS Virtual Private Cloud, which we call VPC. Now, as you can see, we have a diagram representing our AWS network, where we have two Availability Zones. We are in the region US East, and as you can see, we have EC2s or a representation of EC2s that we've separated from private subnets and two public subnets. We have routing tables, we have an Internet gateway, and on our far-right-hand side, we see our Internet cloud. Now, when we're dealing with VPCs, a VPC represents everything that it takes for us to create our virtual network. This is the parts and components that we're using within AWS to make sure that we can, one, reach across the Internet to connect and how we manage the subnets. How do we segment or provide segmentation for our network as well? There are three things that you have to have in order for your VPC to function. The bare minimum is that you must have subnets, you must have a routing table, and you must have an Internet gateway. So if you were to see a question on an exam where, there, for some reason, your particular instance, either you can't connect to it or you can't connect to the Internet from it, one of the first things you're gonna check is to make sure that these three things are available and functioning in your VPC. Now, there are other things you can check for from a security standpoint, such as your security groups and NACLs, but this should be a part of your thought process when going through any type of troubleshooting skills with connectivity. So let's actually go to AWS and take a look at what we have for our VPCs. To access our VPCs, you can get there multiple ways. You can type VPC in the search service and it should be the first one in your list. And if you've recently visited, you can click on VPC. Now, one of the things you noticed, we have a lot of options available to us on the far-left side under the VPC dashboard. We're going to function under the VPC Private Cloud mostly. But if you take a look, you will also notice, security is a part of VPC. We have our NACLs, or our network ACLs, our security groups. We can get into our firewalls and we can deal more with the security side. But for now, let's take a look at the virtual private cloud. If you'll click on Your VPCs, you already have a VPC. Every account has one default virtual private cloud that's created automatically when you actually create your account. Now, it is not a best practice to use this. Once you're setting up your actual environment, you're gonna create your own VPCs because you don't have all of the security features already there and you wanna build your VPC according to the specifications of your environment that you want it to be. Now, if we actually put a check under or next to our default VPC and you scroll down, we can see the details. One, we can actually see what the CIDR block is. When I say "CIDR block," I'm saying, "What is the block of IP addresses? What is the range of IP addresses that this VPC works with?" We have a /16, which gives us a Class B network that we can function from. We have the name of our routing table, of which we could click on this and see the routing table. If there's a NACL that's already created, which there is for your default, you'll see that as well, in the details. So let's click on the Main route table, just to see what's there. If you put a check next to the route table and scroll down, you'll see, one, the VPC that it's representing. If you click on Routes, we can see what routes are in our routing table. A route tells where traffic should go. So if an IP address has a destination of 172.31.2.24, because we have a route in our routing table for this particular subnet, it knows where to send it, where should it go. If you see 0.0.0/0, this represents everything. It represents anything that doesn't have a destination. If it is unaware of a destination in its routing table, everything goes to this place. This is what we put for the Internet. If you need to access something on the Internet, this is your Internet destination and the target is what it's going to send it through, which is your Internet gateway. That's why you have to have an Internet gateway set up in your VPC to actually connect to the Internet. If you do not have this route in your routing table, the actual instances and services that you have cannot connect via the Internet. Now, there are other alternatives, another alternative to use for the services to communicate with each other through endpoint connections. But as far as through the routing table, you have to have a destination of 0.0.0/0 and you have to have it pointing to the target of an Internet gateway. Next, you're gonna notice that there are subnets already associated with your default VPC. There should be six of them. This is already created for you for the default VPC. When you create your own VPC you have to identify what subnets are associated with it. Thanks for watching.