Worked example · AWS VPC · two availability zones

AWS Three-Tier VPC Subnet Plan

A 10.0.0.0/16 VPC split into public, application and data subnets in two availability zones, sized for 250 hosts each and packed under AWS reservations.

The plan

AWS rule: 5 reserved per subnet, /16–/28

parent 10.0.0.0/16 subnets 6 allocated 1,536 of 65,536 (2.3%) free 64,000

Largest first: public-a takes the first /24 (256 addresses), so every smaller block that follows starts on a multiple of its own size with no gaps.

NameHostsSubnetNetmaskUsable rangeBroadcastUsableUnused
public-a25010.0.0.0/24255.255.255.010.0.0.4 – 10.0.0.25410.0.0.2552511
app-a25010.0.1.0/24255.255.255.010.0.1.4 – 10.0.1.25410.0.1.2552511
data-a25010.0.2.0/24255.255.255.010.0.2.4 – 10.0.2.25410.0.2.2552511
public-b25010.0.3.0/24255.255.255.010.0.3.4 – 10.0.3.25410.0.3.2552511
app-b25010.0.4.0/24255.255.255.010.0.4.4 – 10.0.4.25410.0.4.2552511
data-b25010.0.5.0/24255.255.255.010.0.5.4 – 10.0.5.25410.0.5.2552511

Free blocks: 10.0.6.0/23 10.0.8.0/21 10.0.16.0/20 10.0.32.0/19 10.0.64.0/18 10.0.128.0/17

How the plan maps to the VPC

The six subnets are allocated in input order because they are all the same size, so each availability zone gets the same public–application–data sequence:

ZoneTierSubnetTypical use
apublic10.0.0.0/24Load balancer nodes, NAT gateway
aapplication10.0.1.0/24Application instances
adata10.0.2.0/24Database subnet group
bpublic10.0.3.0/24Load balancer nodes, NAT gateway
bapplication10.0.4.0/24Application instances
bdata10.0.5.0/24Database subnet group

The 250-host request fits a /24 with room to spare: AWS leaves 251 usable addresses after reserving the first four and the last. The planner reports the usable range as .4 to .254, which is the range you can hand to instances.

Why this layout

Check the finished ranges in the VLSM planner, or inspect a single subnet in the subnet calculator. The Azure version of this exercise is the hub-spoke example.

Questions

How many /24 subnets does a /16 VPC hold?

256. A /16 fixes the first 16 bits, so the remaining 8 bits give 28 = 256 /24 blocks. This plan uses six of them and leaves the rest for growth.

Why does each subnet show 251 usable addresses instead of 254?

AWS reserves five addresses in every subnet: the first four (network, VPC router, DNS and a future-use address) and the last (broadcast). A /24 therefore has 256 − 5 = 251 usable addresses, and the planner reports the usable range as .4 to .254.

Why are the three tiers packed in the same order in each availability zone?

Requests of equal size keep the order you entered, so public, application and data subnets are allocated sequentially in each zone. That makes the mapping from subnet to availability zone and tier predictable in route tables and security groups.

Can the same VPC grow beyond two availability zones?

Yes. The plan uses 6 of the 256 /24s in 10.0.0.0/16. A third zone can repeat the same three-tier pattern from 10.0.6.0/24, and the planner shows the remaining free space.