AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium
A company is setting up a new VPC for a containerized application. The application will use a private subnet (10.0.1.0/24) for its containers and requires a public subnet for a Load Balancer and NAT Gateway. The VPC CIDR is 10.0.0.0/16. What is the largest non-overlapping CIDR block that could be assigned to the public subnet while keeping it within the same VPC and ensuring it does not overlap with the private subnet?
- A10.0.2.0/24
- B10.0.1.0/25
- C10.0.0.0/23
- D10.0.0.0/24
Show answer & explanationAnswer & explanation
Correct answer: A. 10.0.2.0/24
The existing private subnet is 10.0.1.0/24. This block covers IPs from 10.0.1.0 to 10.0.1.255. The next available non-overlapping /24 block is 10.0.2.0/24, which covers 10.0.2.0 to 10.0.2.255. This is the largest possible non-overlapping /24 block directly after the given private subnet.
Why the other options are wrong
- B. 10.0.1.0/25 overlaps with the existing 10.0.1.0/24 private subnet.
- C. 10.0.0.0/23 overlaps with 10.0.1.0/24 as it encompasses both 10.0.0.0/24 and 10.0.1.0/24.
- D. 10.0.0.0/24 is a valid /24 block but is not the 'largest non-overlapping' in the context of the available space after 10.0.1.0/24. It also implies placing it before the private subnet, which is less about 'largest non-overlapping' after a specific block.
Subnet Non-overlap
When allocating CIDR blocks for subnets within a VPC, each subnet's CIDR range must be unique and not overlap with any other subnet's CIDR range.
- CIDR blocks define IP ranges (Start IP - End IP)
- Overlapping CIDRs cause routing conflicts
- Subnets are typically assigned contiguously for efficient IP space management
- Larger CIDR masks (e.g., /24) mean smaller IP ranges
Memory trick: No two roads can share the same address numbers.