{"id":69326,"date":"2019-01-04T08:27:39","date_gmt":"2019-01-04T08:27:39","guid":{"rendered":"https:\/\/www.whizlabs.com\/blog\/?p=69326"},"modified":"2020-08-31T17:56:30","modified_gmt":"2020-08-31T17:56:30","slug":"why-not-have-a-way-out-to-the-internet-from-main-route-table","status":"publish","type":"post","link":"https:\/\/www.whizlabs.com\/blog\/why-not-have-a-way-out-to-the-internet-from-main-route-table\/","title":{"rendered":"Why You should NOT have a Way Out to the Internet from Main Route Table"},"content":{"rendered":"<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">In-depth knowledge of <a href=\"https:\/\/www.whizlabs.com\/blog\/aws-vpc\/\" target=\"_blank\" rel=\"noopener noreferrer\">Virtual Private Cloud<\/a> (VPC) and its related components viz. Subnets, Route tables &amp; Internet Gateway is a must before you appear in any <a href=\"https:\/\/www.whizlabs.com\/blog\/which-aws-certification-should-i-choose\/\" target=\"_blank\" rel=\"noopener noreferrer\">AWS Certification exam<\/a>. Sometimes even the seasoned professionals miss-out on a specific nitty-gritty of a topic that may lead to losing a few marks in the exam. Here in this article, we\u2019re going to explore such a concept that has generated more than a dozen queries in our helpdesk system.<\/span><\/p>\n<p style=\"text-align: justify;\">Covering this topic is recommended for all the aspirants preparing for any of the AWS certifications.\u00a0 But if you are preparing for the\u00a0<a href=\"https:\/\/www.whizlabs.com\/blog\/aws-sysops-certification\/\" target=\"_blank\" rel=\"noopener follow noreferrer\" data-wpel-link=\"internal\">AWS Certified SysOps Administrator Associate exam<\/a>\u00a0or\u00a0<a href=\"https:\/\/www.whizlabs.com\/blog\/aws-certified-solutions-architect-associate-guide\/\" target=\"_blank\" rel=\"noopener follow noreferrer\" data-wpel-link=\"internal\">AWS Certified Solutions Architect Associate exam<\/a>, It is mandatory to cover this topic.<\/p>\n<p><a href=\"https:\/\/www.whizlabs.com\/aws-solutions-architect-associate\/online-course\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img decoding=\"async\" class=\"aligncenter wp-image-69376 size-full\" src=\"https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2018\/08\/AWS_Certified_Solutions_Architect_Associate_Online_Course.gif\" alt=\"AWS Certified Solutions Architect Associate Online Course\" width=\"728\" height=\"90\" \/><\/a><\/p>\n<p><b>Why You should NOT have a Way Out to the Internet from Main Route Table<\/b><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Or this can be rephrased as:<\/span><\/p>\n<p style=\"text-align: justify;\"><b>Why it\u2019s Not a Good Security Practice to Associate the Public Subnet with Main Route Table?<\/b><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">To put things into perspective here\u2019s a question (see below screenshot) that will tickle you to think about the Route Tables &amp; Subnets in AWS VPC.<\/span><\/p>\n<p style=\"text-align: justify;\">You are the Systems Administrator for a Company. You have been instructed to create a VPC setup which has a public and private subnet. The public subnet needs to have a NAT Gateway which will be used to route traffic to the internet for instances in the private subnet. Which of the following routing entries would you create in the respective main and custom route tables. (<strong>Choose 2 Answers from the options given below<\/strong>).<\/p>\n<ol>\n<li style=\"text-align: justify;\">In the main route table add a route with destination of 0.0.0.0\/0 and the NAT Gateway ID.<\/li>\n<li style=\"text-align: justify;\">In the main route table add a route with destination of 0.0.0.0\/0 and the Internet Gateway ID.<\/li>\n<li style=\"text-align: justify;\">In the custom route table add a route with destination of 0.0.0.0\/0 and the NAT Gateway ID.<\/li>\n<li style=\"text-align: justify;\">In the custom route table add a route with destination of 0.0.0.0\/0 and the Internet Gateway ID.<\/li>\n<\/ol>\n<p><span style=\"font-weight: 400;\"> You are working as a System Administrator in a company. As per the instructions, you need to create a VPC setup that has a private and public subnet. The public subnet requires a NAT gateway that will be used to route traffic to the internet for Instances in the private subnet. Which of the following routing entries will you create in the respective main and custom route tables?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">And the solution will be &#8211; <\/span><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">By adding a route with a destination of 0.0.0.0\/0 and the NAT gateway ID in the main route table, and<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Adding a route with the destination of 0.0.0.0\/0 and the internet gateway ID in the custom rouble table.<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">For the above scenario, we received feedback that basically revolved around the following:<\/span><\/p>\n<ul style=\"text-align: justify;\">\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The scenario doesn&#8217;t specify which route table is for the public or private subnet<\/span><\/li>\n<\/ul>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Now why the above\u00a0scenario doesn\u2019t need to explicitly mention the respective Subnet associations with Route Table. Read on to understand this.<\/span><\/p>\n<blockquote>\n<p class=\"entry-title\"><strong>Must Read:<\/strong> <a href=\"https:\/\/www.whizlabs.com\/blog\/aws-solutions-architect-associate-exam-questions\/\" target=\"_blank\" rel=\"noopener noreferrer\">Free AWS Solutions Architect Associate Exam Questions<\/a><\/p>\n<\/blockquote>\n<h4 style=\"text-align: justify;\">Here\u2019s a primer of Route Tables for Uninitiated<\/h4>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Let us read an extract from Amazon documentation:<\/span><\/p>\n<p style=\"text-align: justify;\"><i><span style=\"font-weight: 400;\">When you create a VPC, it automatically has the main route table. On the <\/span><\/i><i>Route Tables<\/i><i><span style=\"font-weight: 400;\"> page in the Amazon VPC console, you can view the main route table for a VPC by looking for \u201c<\/span><\/i><i>Yes<\/i><i>\u201d<\/i> <i>in the <\/i><i>Main<\/i><i><span style=\"font-weight: 400;\"> column. The main route table controls the routing for all subnets that are not explicitly associated with any other route table. You can add, remove, and modify routes in the main route table.<\/span><\/i><\/p>\n<p>The above statement concludes the following:<\/p>\n<ul style=\"text-align: justify;\">\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Your VPC automatically comes with the main route table that you can modify.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">You can create additional custom route tables for your VPC.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Each subnet must be associated with a route table, which controls the routing for the subnet. If you <\/span><span style=\"font-weight: 400;\">don&#8217;t explicitly associate a subnet<\/span><span style=\"font-weight: 400;\"> with a particular route table, the subnet is implicitly <\/span><span style=\"font-weight: 400;\">associated with the main route table.<\/span><\/li>\n<\/ul>\n<blockquote>\n<p style=\"text-align: justify;\">Also Read:<\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.whizlabs.com\/blog\/create-virtual-private-cloud-in-aws\/\" target=\"_blank\" rel=\"noopener noreferrer\">Build Your First Virtual Private Cloud (VPC) in AWS<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.whizlabs.com\/blog\/ephemeral-ports\/\" target=\"_blank\" rel=\"noopener noreferrer\">Simplifying Ephemeral Ports with Example<\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.whizlabs.com\/blog\/dns-records\/\" target=\"_blank\" rel=\"noopener noreferrer\">Demystifying DNS Records<\/a><\/p>\n<\/blockquote>\n<h2 style=\"text-align: justify;\">So, Why You should NOT have a Way Out to the Internet from Main Route Table<\/h2>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">Keeping in mind the best security practices, you should not have a way out to the internet from Main Route Table.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">This is because every time you create a new subnet, it&#8217;s going to be associated by default with the Main Route Table. Or to rephrase this, when a subnet has not been associated with any Route Table it is going to be associated with the Main Route Table. So, if the Main Route Table has a route out to the internet, every subnet which is not explicitly attached with any Route Table is public by default and that may create a security risk.<\/span><\/p>\n<p style=\"text-align: justify;\"><em><span style=\"font-weight: 400;\">Keeping the above statements in mind, we can infer the following as good practice:<\/span><\/em><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">A custom route table should be associated with the public subnet. This route table contains an entry that enables instances in the subnet to communicate with other instances in the VPC over IPv4. And an entry that enables instances in the subnet to communicate directly with the Internet.<\/span><\/p>\n<p style=\"text-align: justify;\"><span style=\"font-weight: 400;\">The main route table should be associated with the private subnet. This route table contains an entry that enables instances in the subnet to communicate with other instances in the VPC over IPv4, and an entry that enables instances in the subnet to communicate with the Internet through the NAT gateway over IPv4.<\/span><\/p>\n<p style=\"text-align: justify;\"><em><span style=\"font-weight: 400;\">So, it&#8217;s the reason the scenario has not explicitly mentioned about what Route Table is associated with the Public\/Private subnet. And why you should not have a Way Out to the internet from Main Route Table.<\/span><\/em><\/p>\n<p style=\"text-align: justify;\">Hope this explanation will help you in your preparation for the AWS certifications. Whizlabs is highly determined to help you in your certification preparation. So, if you are looking for any online study material or the practice material for AWS certifications preparation, check out Whizlabs <a href=\"https:\/\/www.whizlabs.com\/aws-certifications\/\" target=\"_blank\" rel=\"noopener noreferrer\">AWS Certifications Training<\/a>\u00a0now.<\/p>\n<p style=\"text-align: justify;\">Also, if you want to discuss your doubts with the AWS experts, just submit your query at <a href=\"http:\/\/ask.whizlabs.com\/c\/aws\" target=\"_blank\" rel=\"noopener noreferrer\">Whizlabs Forum<\/a> and get connected with the industry experts.<\/p>\n<p style=\"text-align: justify;\"><b>References<\/b><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_Scenario2.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_Scenario2.html<\/span><\/a><\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_Route_Tables.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">https:\/\/docs.aws.amazon.com\/vpc\/latest\/userguide\/VPC_Route_Tables.html<\/span><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In-depth knowledge of Virtual Private Cloud (VPC) and its related components viz. Subnets, Route tables &amp; Internet Gateway is a must before you appear in any AWS Certification exam. Sometimes even the seasoned professionals miss-out on a specific nitty-gritty of a topic that may lead to losing a few marks in the exam. Here in this article, we\u2019re going to explore such a concept that has generated more than a dozen queries in our helpdesk system. Covering this topic is recommended for all the aspirants preparing for any of the AWS certifications.\u00a0 But if you are preparing for the\u00a0AWS Certified [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":69341,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[4],"tags":[201,296,313,417,1050,1343],"class_list":["post-69326","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aws-certifications","tag-aws-certifications","tag-aws-security-specialty","tag-aws-sysops-administrator-associate","tag-best-security-practices","tag-main-route-table","tag-public-subnet-with-main-route-table"],"uagb_featured_image_src":{"full":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",600,315,false],"thumbnail":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table-150x150.png",150,150,true],"medium":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table-300x158.png",300,158,true],"medium_large":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",600,315,false],"large":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",600,315,false],"1536x1536":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",600,315,false],"2048x2048":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",600,315,false],"profile_24":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",24,13,false],"profile_48":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",48,25,false],"profile_96":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",96,50,false],"profile_150":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",150,79,false],"profile_300":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",300,158,false],"tptn_thumbnail":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table-250x250.png",250,250,true],"web-stories-poster-portrait":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",600,315,false],"web-stories-publisher-logo":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",96,50,false],"web-stories-thumbnail":["https:\/\/www.whizlabs.com\/blog\/wp-content\/uploads\/2019\/01\/Internet_from_Main_Route_Table.png",150,79,false]},"uagb_author_info":{"display_name":"Pavan Gumaste","author_link":"https:\/\/www.whizlabs.com\/blog\/author\/pavan\/"},"uagb_comment_info":1,"uagb_excerpt":"In-depth knowledge of Virtual Private Cloud (VPC) and its related components viz. Subnets, Route tables &amp; Internet Gateway is a must before you appear in any AWS Certification exam. Sometimes even the seasoned professionals miss-out on a specific nitty-gritty of a topic that may lead to losing a few marks in the exam. Here in&hellip;","_links":{"self":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts\/69326","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/comments?post=69326"}],"version-history":[{"count":1,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts\/69326\/revisions"}],"predecessor-version":[{"id":71490,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/posts\/69326\/revisions\/71490"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/media\/69341"}],"wp:attachment":[{"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/media?parent=69326"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/categories?post=69326"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.whizlabs.com\/blog\/wp-json\/wp\/v2\/tags?post=69326"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}