9 min read

    08 - VPC Networking, Subnets and IP Ranges

    gcpcloudnetworkingvpc

    Welcome to Day 08 of Learn GCP in 30 Days! Today, we kick off Week 2: Core Compute & Networking.

    🎯

    Today's Goal Welcome to Week 2! Today, you will learn how servers inside Google Cloud talk to each other safely—building your own private digital playground (a VPC network) where you control who gets in from the internet and who stays protected inside!


    The Real-World Analogy: Building a Secure Bank

    Imagine you are building a modern bank building that handles online transactions. Your bank has two main servers:

    1. Server 1 (Front Reception / Web Server): Where customers log into their account on your website.
    2. Server 2 (Back Vault / Database Server): Where private customer credit card records and money balances are stored.

    Who Can Access What?

    If all your servers sat directly on the public Internet without protection, any hacker could walk straight into your Back Vault and steal money!

    A Virtual Private Cloud (VPC) divides your bank into two distinct rooms so access is strictly controlled:

    mermaid
    • 🌐 Customers on the Internet: Can ONLY access Room 1 (Web Server) to browse your site or log in.
    • 🔄 Web Server (Room 1): Can talk internally to Room 2 (Database) to verify balances.
    • 🛡️ Hackers on the Internet: Are 100% BLOCKED from accessing Room 2 directly! Even if someone tries to connect to your database from home, the VPC blocks them at the door.

    Non-Technical Breakdown: The Gated Society Analogy

    Imagine you are building a modern Gated Apartment Society. Here is how all 5 networking terms map directly to real life:


    1. VPC (Virtual Private Cloud)

    🧱 Real-Life Equivalent: The Boundary Wall & Security Gate of your Society.

    • What it does: It creates a private, fenced property. People off the street cannot walk inside unless security lets them in.
    • In GCP: A VPC is a private boundary wall around your servers so no uninvited internet traffic can enter.

    2. Subnets (Sub-networks)

    🏢 Real-Life Equivalent: Individual Buildings inside the Gated Society.

    • What it does: Inside your gated society, you build Building A (Public Reception) for guests to visit, and Building B (Private Vault) reserved only for residents.
    • In GCP: A Subnet divides your VPC boundary into specific rooms tied to cities (e.g. Mumbai Subnet vs. Iowa Subnet).

    3. IP Addresses & CIDR Notation

    🚪 Real-Life Equivalent: Flat Door Numbers & Total Capacity of the Building.

    • IP Address (10.0.1.5): Every flat has a door number. Your server's IP address is simply its digital door number.
    • CIDR Notation (/24): Tells GCP how many flats (server seats) to build in that building.
      • A /24 subnet means building 256 flats (10.0.1.0 to 10.0.1.255).
    💡

    The Simple Rule for CIDR Slashes (/)

    • The smaller the number after the slash, the more flats in the building!
    • /16 = 65,536 flats (Giant Skyscraper).
    • /24 = 256 flats (Medium Building).
    • /28 = 16 flats (Small Villa).

    4. Public IP vs. Private IP

    IP TypeReal-Life EquivalentWho Can Access It?Use Case
    Public IPMain Gate Intercom NumberAnyone calling from the outside worldPublic web apps
    Private IPInternal Intercom Extension (#102)Only residents inside the societyInternal databases
    🛡️

    Golden Security Rule Never give your internal database a Public IP! Keep it strictly on a Private IP inside a private building.


    5. Default VPC vs. Custom Mode VPC

    • Default VPC (Auto Mode): Buying a pre-built property that forces you to own 30 empty buildings across 30 different cities. (Messy for real business).
    • Custom Mode VPC (Best Practice): Buying a blank plot of land and building only the exact 2 buildings you need in Mumbai and Iowa. (Clean, organized, and secure!).

    🧪 Hands-on Lab Activity: Exploring & Creating Your VPC Network

    Now let's put theory into real practice! You will complete 2 quick hands-on activities in your GCP account.


    Activity 1: Inspect Your Default VPC in Web Console

    1. Log into console.cloud.google.com.
    2. Open the left menu ☰ →\rightarrow Scroll down to VPC Network →\rightarrow Click VPC networks.
    3. You will see a pre-existing network named default.
    4. Click on default to explore the list of subnets automatically created across regions (asia-south1, us-central1, etc.).

    Activity 2: Create a Custom VPC & Subnet via Cloud Shell CLI

    Now let's build a clean, production-style Custom Mode VPC and Mumbai Subnet using Cloud Shell!

    💡

    Prompted to Enable "Compute Engine API"? If GCP asks "Enable Compute Engine API?", click Enable (or type y in Cloud Shell)! Is enabling APIs free? Yes! Enabling an API is 100% free—it simply turns on the capability for your project to manage networks and servers. You are only billed when running active paid resources.

    Step 1: Open Cloud Shell

    Click the Activate Cloud Shell (>_) icon at the top right of your console.

    Step 2: Create a Custom Mode VPC

    Run the following command to create a blank network named custom-vpc-demo:

    bash
    gcloud compute networks create custom-vpc-demo --subnet-mode=custom
    

    Output:

    text
    Created [https://www.googleapis.com/compute/v1/projects/.../custom-vpc-demo].
    

    Step 3: Create a Regional Subnet in Mumbai

    Now create a custom subnet room in asia-south1 (Mumbai) with IP range 10.0.1.0/24:

    bash
    gcloud compute networks subnets create custom-subnet-mumbai \
        --network=custom-vpc-demo \
        --region=asia-south1 \
        --range=10.0.1.0/24
    

    Output:

    text
    Created [https://www.googleapis.com/compute/v1/projects/.../custom-subnet-mumbai].
    

    Step 4: Verify Your New Subnet Live

    List subnets in your new network to confirm creation:

    bash
    gcloud compute networks subnets list --network=custom-vpc-demo
    

    Output:

    text
    NAME                  REGION        NETWORK          RANGE
    custom-subnet-mumbai  asia-south1   custom-vpc-demo  10.0.1.0/24
    

    🧹 Clean Up Step (Credit Safety Guarantee)

    To keep your GCP environment clean and free up project quotas, delete the test subnet and VPC when finished:

    bash
    gcloud compute networks subnets delete custom-subnet-mumbai --region=asia-south1 --quiet
    gcloud compute networks delete custom-vpc-demo --quiet
    
    💰

    Does keeping an empty VPC cost money? No! Empty VPCs and Subnets cost $0.00. Google Cloud charges nothing to store network definitions. Why do we clean up then? Every GCP project has a maximum quota (limit) of 5–15 VPC networks. Cleaning up unused test networks keeps your account tidy and prevents hitting your project quota limits!


    Signal vs. Noise: Key Concepts & Noise Filter

    🧠

    Good to Know (Key Concepts)

    • VPC: Private digital fence spanning worldwide.
    • Subnet: Regional room inside your VPC.
    • CIDR (/24): Tells GCP how many server seats to reserve.
    • Public vs Private IPs: Public IPs face the Internet; Private IPs stay safe inside your VPC.
    • Custom VPC: Building only the network rooms you need (production best practice).
    ℹ️

    Noise Filter (Don't Memorize)

    • Do NOT calculate binary subnet numbers in your head—developers use free online CIDR calculators to pick IP ranges.
    • Do NOT memorize default IP numbers for all 30+ GCP regions.

    Common Doubts & Interview Traps

    Q1: Can two Virtual Machines in different regions (e.g. Mumbai and Iowa) communicate over private IP addresses inside the same GCP VPC?

    • Answer: Yes! Because GCP VPCs are global resources, VMs in different regions can communicate privately over Google's subsea fiber-optic network without needing public IP addresses.

    Q2: Can two subnets in the SAME VPC have overlapping IP address ranges?

    • Answer: No! GCP strictly prohibits overlapping IP ranges inside the same VPC network. Every subnet inside 1 VPC must have a unique CIDR block (e.g. 10.0.1.0/24 and 10.0.2.0/24).

    Q3: Can TWO DIFFERENT VPCs have the exact same overlapping IP address ranges?

    • Answer: Yes! Two separate VPCs (e.g., Company-VPC-A and Vendor-VPC-B) can both use 10.0.1.0/24. Because they are completely separate boundary walls, their internal IP addresses do not clash.

    Q4: Is communication between two DIFFERENT VPCs possible?

    • Answer: Yes! By default, two VPCs are 100% isolated. However, you can connect them privately using VPC Network Peering.
      • Crucial Requirement for VPC Peering: The two VPCs MUST NOT HAVE OVERLAPPING IP RANGES! (If VPC A uses 10.0.1.0/24, VPC B must use 10.0.2.0/24 to enable VPC Peering).

    Daily Practice Drill & Self-Check

    Test your understanding of today's lesson:

    text
    // Try answering these:
    1. A database server needs to receive queries from a web server in the same VPC, but must never be accessed from the public Internet. Should you assign it a Public IP or Private IP?
    2. Which CIDR block provides more IP addresses for your servers: 10.0.0.0/16 or 10.0.0.0/24?
    
    💡 Click for Solutions
    1. Assign it a Private IP only! This ensures it can communicate inside your VPC while staying completely invisible to the public Internet.
    2. 10.0.0.0/16 provides far more IP addresses (~65,536 IPs) compared to /24 (256 IPs). Remember: the smaller the number after /, the larger the room capacity!

    🎉 Awesome job! You have completed Day 08.

    You now understand Virtual Private Cloud (VPC), regional subnets, CIDR capacity, Public vs Private IPs, and Custom VPC design. Take a break, let today's concepts sink in, and come back tomorrow fresh!

    Tomorrow on Day 09, we will explore Firewall Rules and Traffic Control so you learn how to open and close virtual doors safely.


    ← 07 - Hands-on Lab - Setting Up Your First GCP Project & Cloud Shell | Next Topic → 09 - Firewall Rules and Traffic Control