A company is setting up a new VPC for a containerized application. The application will use a private IP address range of 10.100.0.0/20. The security team mandates that the VPC must have at least four private subnets, each capable of hosting a minimum of 200 instances. Additionally, there must be a separate public subnet for load balancers and NAT Gateways. What is the most efficient way to design the subnet CIDR blocks to meet these requirements while conserving IP addresses?
- AFour private subnets as 10.100.0.0/22, 10.100.4.0/22, 10.100.8.0/22, 10.100.12.0/22, and one public subnet as 10.100.16.0/22.
- BFour private subnets as 10.100.0.0/23, 10.100.2.0/23, 10.100.4.0/23, 10.100.6.0/23, and one public subnet as 10.100.8.0/22.
- CFour private subnets as 10.100.0.0/21, 10.100.8.0/21, 10.100.16.0/21, 10.100.24.0/21, and one public subnet as 10.100.32.0/20.
- DFour private subnets as 10.100.0.0/24, 10.100.1.0/24, 10.100.2.0/24, 10.100.3.0/24, and one public subnet as 10.100.4.0/23.
Show answer & explanationAnswer & explanation
Correct answer: B. Four private subnets as 10.100.0.0/23, 10.100.2.0/23, 10.100.4.0/23, 10.100.6.0/23, and one public subnet as 10.100.8.0/22.
A /23 subnet provides 512 total IPs, which is 507 usable IPs (512 - 5 reserved by AWS), comfortably exceeding the 200 instance requirement. Four /23 subnets would consume 10.100.0.0/23 through 10.100.7.255. The remaining 10.100.8.0/22 (1024 IPs) from the original /20 (4096 IPs) is large enough for a public subnet, and this uses the address space efficiently. Option B's /24 subnets only provide 251 usable IPs, barely meeting the 200 instance requirement and leaving little room for growth. Options C and D use much larger subnets than necessary, wasting IP addresses.
Why the other options are wrong
- A. A /22 subnet (1024 IPs) provides 1019 usable IPs, which is far more than the required 200, leading to significant IP waste. Four of these would consume 10.100.0.0/20, leaving no space for a public subnet within the VPC's CIDR.
- C. A /21 subnet (2048 IPs) provides 2043 usable IPs, which is excessive for 200 instances, leading to extreme IP waste. Four such subnets would exceed the /20 VPC CIDR.
- D. A /24 subnet (256 IPs) provides 251 usable IPs, which is tight for a minimum of 200 instances and leaves little buffer for growth. The public subnet 10.100.4.0/23 is also small.
VPC Subnet Sizing (CIDR)
VPC subnet sizing involves selecting appropriate CIDR blocks for subnets to allocate sufficient IP addresses for resources while efficiently utilizing the overall VPC CIDR range.
- AWS reserves 5 IP addresses in each subnet (first four and last one).
- A /28 is the smallest subnet (16 IPs, 11 usable).
- A /23 provides 507 usable IP addresses.
- Efficient sizing balances current needs with future growth and IP conservation.
Memory trick: CIDR: The IP address jigsaw puzzle, fitting pieces for all your cloud rooms.