# AWS NWD5: Subnet

After the **Route Table**, the packet is forwarded to the **Subnet**.

Inside Amazon Virtual Private Cloud, the route table only decides **where the packet should go next**. Once the destination is determined, the traffic is delivered to the **subnet that contains the resource**.

# What Comes After Route Table

### 1\. Subnet

A **subnet** is a logical section of a VPC where resources like Amazon EC2 instances are placed.

Example:

```plaintext
VPC CIDR: 10.0.0.0/16

Subnet A: 10.0.1.0/24
Subnet B: 10.0.2.0/24
```

If a packet has destination IP:

```plaintext
10.0.1.25
```

AWS immediately knows it belongs to:

```plaintext
Subnet 10.0.1.0/24
```

So the packet is forwarded to that subnet.

# What Happens Inside the Subnet

Once traffic enters the subnet, the next checks occur:

1.  Network Access Control List  
    Subnet-level firewall that evaluates inbound and outbound rules.
    
2.  Elastic Network Interface  
    Virtual network card attached to the instance.
    
3.  Security Group  
    Instance-level firewall controlling allowed ports and protocols.
    
4.  Application running on the instance.
    

# Full Flow Until the Instance

```plaintext
User
↓
Internet
↓
Internet Gateway
↓
VPC Router
↓
Route Table
↓
Subnet
↓
Network ACL
↓
Elastic Network Interface
↓
Security Group
↓
OS Firewall
↓
Application
```

# One Easy Memory Trick

```plaintext
Gateway → Routing → Subnet → Firewalls → Instance
```

This sequence explains how traffic moves from the internet to an instance inside a VPC.
