Cloud Networking: VPCs, Peering, and SD-WAN

Cloud networks solve a hard problem: how do you build isolated, scalable, and controllable networks when the hardware lives in someone else’s data center? CompTIA Network+ (N10-009) expects you to explain Virtual Private Clouds (VPCs), how those VPCs talk to each other through peering, and how Software-Defined Wide Area Networks (SD-WAN) steer traffic across the internet and private links. Master these three pieces and you can design hybrid networks that stay private, follow policy, and fail over without a truck roll.


Virtual Private Clouds Isolate Your Workloads

A Virtual Private Cloud is your own slice of a public cloud. You choose a private IPv4 CIDR block, carve it into subnets, and attach route tables. The cloud provider still owns the physical switches and routers; you own the logical layout.

Start with a CIDR such as 10.0.0.0/16. Split it into a public subnet (10.0.1.0/24) and a private subnet (10.0.2.0/24). Place web servers in the public subnet and databases in the private subnet. An Internet Gateway attaches to the VPC and gives the public subnet a path to the internet. A NAT Gateway sits in the public subnet and lets private instances reach the internet without exposing inbound ports.

Network Security Groups (NSGs) and Network Security Lists act as virtual firewalls. An NSG lives on a network interface or subnet and filters traffic by protocol, port, and source. A security list applies at the subnet level and works the same way. Together they replace the physical firewall you used to rack in a closet.

Network Functions Virtualization (NFV) turns the rest of the stack into software. The same hypervisor that runs your virtual machines also runs virtual routers, load balancers, and firewalls. You spin them up with an API call instead of buying hardware.

Students who want a complete study path for these cloud concepts can follow the Network+ guide at https://legacyhaven.university/how-to-pass-comptia-network-n10-009/.

VPC Peering Connects Isolated Networks

Two VPCs cannot talk by default. Peering creates a private route between them so packets stay on the provider’s backbone and never hit the public internet.

You request a peering connection from VPC-A to VPC-B. Both sides accept. Each VPC adds a route that points the other VPC’s CIDR at the peering connection. Traffic now flows as if the two networks shared a private cable.

Peering is not transitive. If VPC-A peers with VPC-B and VPC-B peers with VPC-C, A still cannot reach C. For many-to-many connectivity you insert a Transit Gateway (or equivalent hub). Every spoke VPC attaches to the hub; the hub forwards packets according to a central route table.

VPC endpoints add another private path. An endpoint lets a VPC reach a cloud service (object storage, databases, APIs) without an Internet Gateway or NAT. The traffic never leaves the provider’s network.

When you connect an on-premises data center, you choose between a VPN (encrypted over the internet) and Direct Connect (a dedicated fiber or Ethernet circuit). Direct Connect gives you consistent latency and higher bandwidth; the VPN gives you speed of deployment.

SD-WAN Steers Traffic by Application, Not Just Destination

Traditional WANs treat every packet the same. SD-WAN looks at the application first, then picks the best path.

An SD-WAN edge device sits at each site. It builds encrypted overlays across whatever transports you give it: MPLS, broadband, LTE, or 5G. A central controller pushes policy to every edge. The policy can say “send voice over the lowest-latency link, send backups over the cheapest link, and fail over in under a second if a circuit dies.”

Zero-touch provisioning ships a new edge device to a branch. A technician plugs in power and Ethernet. The device phones home, downloads its configuration, and joins the fabric. No CLI session is required.

Because the controller sees every flow, it can apply quality-of-service markings, block unsanctioned applications, and report real-time path quality. Transport-agnostic design means you can drop an expensive MPLS circuit and replace it with two cheaper broadband links without rewriting every route.

VXLAN often rides alongside SD-WAN in data-center and cloud designs. It wraps Layer-2 Ethernet frames inside UDP packets so you can stretch a VLAN across Layer-3 networks and across availability zones.

How the Pieces Fit on the Exam

N10-009 tests the relationships, not just the definitions. Expect questions that ask which gateway a private subnet needs, why two peered VPCs still cannot reach a third VPC, or which SD-WAN feature lets a branch come online without a network engineer on site.

Draw the packet path every time. A user in a branch office opens a web app hosted in a private subnet. The SD-WAN edge encrypts the session, chooses the healthiest underlay, and hands the packet to a Direct Connect or VPN. The packet lands in the VPC, hits the Internet or NAT Gateway only if required, passes the security group, and reaches the instance. Reverse the path for the reply.

Practice that flow until it feels automatic. The exam rewards technicians who can move packets from a branch router through a cloud fabric and back again without guessing.



Leave a Reply