AWS Certified Advanced Networking – Specialty (ANS-C01)Network ImplementationMedium

A company is setting up a new VPC for a containerized application. The application will use a private subnet (10.0.1.0/24) for its containers and requires a public subnet for a Load Balancer and NAT Gateway. The VPC CIDR is 10.0.0.0/16. What is the largest non-overlapping CIDR block that could be assigned to the public subnet while keeping it within the same VPC and ensuring it does not overlap with the private subnet?

  1. A10.0.2.0/24
  2. B10.0.1.0/25
  3. C10.0.0.0/23
  4. D10.0.0.0/24
Show answer & explanation

Correct answer: A. 10.0.2.0/24

The existing private subnet is 10.0.1.0/24. This block covers IPs from 10.0.1.0 to 10.0.1.255. The next available non-overlapping /24 block is 10.0.2.0/24, which covers 10.0.2.0 to 10.0.2.255. This is the largest possible non-overlapping /24 block directly after the given private subnet.

Why the other options are wrong

  • B. 10.0.1.0/25 overlaps with the existing 10.0.1.0/24 private subnet.
  • C. 10.0.0.0/23 overlaps with 10.0.1.0/24 as it encompasses both 10.0.0.0/24 and 10.0.1.0/24.
  • D. 10.0.0.0/24 is a valid /24 block but is not the 'largest non-overlapping' in the context of the available space after 10.0.1.0/24. It also implies placing it before the private subnet, which is less about 'largest non-overlapping' after a specific block.

Subnet Non-overlap

When allocating CIDR blocks for subnets within a VPC, each subnet's CIDR range must be unique and not overlap with any other subnet's CIDR range.

  • CIDR blocks define IP ranges (Start IP - End IP)
  • Overlapping CIDRs cause routing conflicts
  • Subnets are typically assigned contiguously for efficient IP space management
  • Larger CIDR masks (e.g., /24) mean smaller IP ranges

Memory trick: No two roads can share the same address numbers.

More Network Implementation questions