08 - VPC Networking, Subnets and IP Ranges
Welcome to Day 08 of Learn GCP in 30 Days! Today, we kick off Week 2: Core Compute & Networking.
Today's Goal Welcome to Week 2! Today, you will learn how servers inside Google Cloud talk to each other safely—building your own private digital playground (a VPC network) where you control who gets in from the internet and who stays protected inside!
The Real-World Analogy: Building a Secure Bank
Imagine you are building a modern bank building that handles online transactions. Your bank has two main servers:
- Server 1 (Front Reception / Web Server): Where customers log into their account on your website.
- Server 2 (Back Vault / Database Server): Where private customer credit card records and money balances are stored.
Who Can Access What?
If all your servers sat directly on the public Internet without protection, any hacker could walk straight into your Back Vault and steal money!
A Virtual Private Cloud (VPC) divides your bank into two distinct rooms so access is strictly controlled:
- 🌐 Customers on the Internet: Can ONLY access Room 1 (Web Server) to browse your site or log in.
- 🔄 Web Server (Room 1): Can talk internally to Room 2 (Database) to verify balances.
- 🛡️ Hackers on the Internet: Are 100% BLOCKED from accessing Room 2 directly! Even if someone tries to connect to your database from home, the VPC blocks them at the door.
Non-Technical Breakdown: The Gated Society Analogy
Imagine you are building a modern Gated Apartment Society. Here is how all 5 networking terms map directly to real life:
1. VPC (Virtual Private Cloud)
🧱 Real-Life Equivalent: The Boundary Wall & Security Gate of your Society.
- What it does: It creates a private, fenced property. People off the street cannot walk inside unless security lets them in.
- In GCP: A VPC is a private boundary wall around your servers so no uninvited internet traffic can enter.
2. Subnets (Sub-networks)
🏢 Real-Life Equivalent: Individual Buildings inside the Gated Society.
- What it does: Inside your gated society, you build Building A (Public Reception) for guests to visit, and Building B (Private Vault) reserved only for residents.
- In GCP: A Subnet divides your VPC boundary into specific rooms tied to cities (e.g. Mumbai Subnet vs. Iowa Subnet).
3. IP Addresses & CIDR Notation
🚪 Real-Life Equivalent: Flat Door Numbers & Total Capacity of the Building.
- IP Address (
10.0.1.5): Every flat has a door number. Your server's IP address is simply its digital door number. - CIDR Notation (
/24): Tells GCP how many flats (server seats) to build in that building.- A
/24subnet means building 256 flats (10.0.1.0to10.0.1.255).
- A
The Simple Rule for CIDR Slashes (/)
- The smaller the number after the slash, the more flats in the building!
/16= 65,536 flats (Giant Skyscraper)./24= 256 flats (Medium Building)./28= 16 flats (Small Villa).
4. Public IP vs. Private IP
| IP Type | Real-Life Equivalent | Who Can Access It? | Use Case |
|---|---|---|---|
| Public IP | Main Gate Intercom Number | Anyone calling from the outside world | Public web apps |
| Private IP | Internal Intercom Extension (#102) | Only residents inside the society | Internal databases |
Golden Security Rule Never give your internal database a Public IP! Keep it strictly on a Private IP inside a private building.
5. Default VPC vs. Custom Mode VPC
- Default VPC (Auto Mode): Buying a pre-built property that forces you to own 30 empty buildings across 30 different cities. (Messy for real business).
- Custom Mode VPC (Best Practice): Buying a blank plot of land and building only the exact 2 buildings you need in Mumbai and Iowa. (Clean, organized, and secure!).
🧪 Hands-on Lab Activity: Exploring & Creating Your VPC Network
Now let's put theory into real practice! You will complete 2 quick hands-on activities in your GCP account.
Activity 1: Inspect Your Default VPC in Web Console
- Log into console.cloud.google.com.
- Open the left menu
☰Scroll down to VPC Network Click VPC networks. - You will see a pre-existing network named
default. - Click on
defaultto explore the list of subnets automatically created across regions (asia-south1,us-central1, etc.).
Activity 2: Create a Custom VPC & Subnet via Cloud Shell CLI
Now let's build a clean, production-style Custom Mode VPC and Mumbai Subnet using Cloud Shell!
Prompted to Enable "Compute Engine API"?
If GCP asks "Enable Compute Engine API?", click Enable (or type y in Cloud Shell)!
Is enabling APIs free? Yes! Enabling an API is 100% free—it simply turns on the capability for your project to manage networks and servers. You are only billed when running active paid resources.
Step 1: Open Cloud Shell
Click the Activate Cloud Shell (>_) icon at the top right of your console.
Step 2: Create a Custom Mode VPC
Run the following command to create a blank network named custom-vpc-demo:
gcloud compute networks create custom-vpc-demo --subnet-mode=custom
Output:
Created [https://www.googleapis.com/compute/v1/projects/.../custom-vpc-demo].
Step 3: Create a Regional Subnet in Mumbai
Now create a custom subnet room in asia-south1 (Mumbai) with IP range 10.0.1.0/24:
gcloud compute networks subnets create custom-subnet-mumbai \
--network=custom-vpc-demo \
--region=asia-south1 \
--range=10.0.1.0/24
Output:
Created [https://www.googleapis.com/compute/v1/projects/.../custom-subnet-mumbai].
Step 4: Verify Your New Subnet Live
List subnets in your new network to confirm creation:
gcloud compute networks subnets list --network=custom-vpc-demo
Output:
NAME REGION NETWORK RANGE
custom-subnet-mumbai asia-south1 custom-vpc-demo 10.0.1.0/24
🧹 Clean Up Step (Credit Safety Guarantee)
To keep your GCP environment clean and free up project quotas, delete the test subnet and VPC when finished:
gcloud compute networks subnets delete custom-subnet-mumbai --region=asia-south1 --quiet
gcloud compute networks delete custom-vpc-demo --quiet
Does keeping an empty VPC cost money? No! Empty VPCs and Subnets cost $0.00. Google Cloud charges nothing to store network definitions. Why do we clean up then? Every GCP project has a maximum quota (limit) of 5–15 VPC networks. Cleaning up unused test networks keeps your account tidy and prevents hitting your project quota limits!
Signal vs. Noise: Key Concepts & Noise Filter
Good to Know (Key Concepts)
- VPC: Private digital fence spanning worldwide.
- Subnet: Regional room inside your VPC.
- CIDR (
/24): Tells GCP how many server seats to reserve. - Public vs Private IPs: Public IPs face the Internet; Private IPs stay safe inside your VPC.
- Custom VPC: Building only the network rooms you need (production best practice).
Noise Filter (Don't Memorize)
- Do NOT calculate binary subnet numbers in your head—developers use free online CIDR calculators to pick IP ranges.
- Do NOT memorize default IP numbers for all 30+ GCP regions.
Common Doubts & Interview Traps
Q1: Can two Virtual Machines in different regions (e.g. Mumbai and Iowa) communicate over private IP addresses inside the same GCP VPC?
- Answer: Yes! Because GCP VPCs are global resources, VMs in different regions can communicate privately over Google's subsea fiber-optic network without needing public IP addresses.
Q2: Can two subnets in the SAME VPC have overlapping IP address ranges?
- Answer: No! GCP strictly prohibits overlapping IP ranges inside the same VPC network. Every subnet inside 1 VPC must have a unique CIDR block (e.g.
10.0.1.0/24and10.0.2.0/24).
Q3: Can TWO DIFFERENT VPCs have the exact same overlapping IP address ranges?
- Answer: Yes! Two separate VPCs (e.g.,
Company-VPC-AandVendor-VPC-B) can both use10.0.1.0/24. Because they are completely separate boundary walls, their internal IP addresses do not clash.
Q4: Is communication between two DIFFERENT VPCs possible?
- Answer: Yes! By default, two VPCs are 100% isolated. However, you can connect them privately using VPC Network Peering.
- Crucial Requirement for VPC Peering: The two VPCs MUST NOT HAVE OVERLAPPING IP RANGES! (If VPC A uses
10.0.1.0/24, VPC B must use10.0.2.0/24to enable VPC Peering).
- Crucial Requirement for VPC Peering: The two VPCs MUST NOT HAVE OVERLAPPING IP RANGES! (If VPC A uses
Daily Practice Drill & Self-Check
Test your understanding of today's lesson:
// Try answering these:
1. A database server needs to receive queries from a web server in the same VPC, but must never be accessed from the public Internet. Should you assign it a Public IP or Private IP?
2. Which CIDR block provides more IP addresses for your servers: 10.0.0.0/16 or 10.0.0.0/24?
💡 Click for Solutions
- Assign it a Private IP only! This ensures it can communicate inside your VPC while staying completely invisible to the public Internet.
10.0.0.0/16provides far more IP addresses (~65,536 IPs) compared to/24(256 IPs). Remember: the smaller the number after/, the larger the room capacity!
🎉 Awesome job! You have completed Day 08.
You now understand Virtual Private Cloud (VPC), regional subnets, CIDR capacity, Public vs Private IPs, and Custom VPC design. Take a break, let today's concepts sink in, and come back tomorrow fresh!
Tomorrow on Day 09, we will explore Firewall Rules and Traffic Control so you learn how to open and close virtual doors safely.
← 07 - Hands-on Lab - Setting Up Your First GCP Project & Cloud Shell | Next Topic → 09 - Firewall Rules and Traffic Control