NetStack
Playground

Learn AWS networking through interactive simulation. Build, connect, and export Terraform code.

SCROLL TO EXPLORE
1

VPC: Your First Virtual Boundary

Every network starts with a boundary — your Virtual Private Cloud. Think of it like drawing a fence around your AWS environment. Everything you build will live inside it.

HOW IT WORKS

Drag a VPC node onto the canvas — it's just a container, not functional logic yet. Only one VPC is allowed for now. Gateways can be placed outside the VPC container.

TRY IT YOURSELF

Try placing two EC2 instances inside the same VPC. Notice how they still need to be connected to a Subnet before they can communicate.

CONTINUE SCROLLING
VPC
10.0.0.0/16
EC2
EC2
IGW
2

Subnet: Public or Private Pathways

Inside your VPC, you divide your network into smaller zones called Subnets. Each one can be Public (connected to the internet) or Private (isolated and secure).

HOW IT WORKS

Drag a Subnet node into the VPC and set its type. EC2s connect to Subnet nodes with visible links to define their network placement.

TRY IT YOURSELF

Connect two EC2 instances to the same Subnet and see how they can communicate. Try connecting them to different Subnets — they won't connect yet.

CONTINUE SCROLLING
VIRTUAL PRIVATE CLOUD
PUBLIC SUBNET
10.0.1.0/24
PRIVATE SUBNET
10.0.2.0/24
EC2
SUBNET
3

Route Table: The Traffic Director

Every subnet follows a map called a Route Table — it decides where traffic goes. Without it, your subnet doesn't know how to reach the internet or other networks.

HOW IT WORKS

Drag a Route Table node and connect Subnet → Route Table. This sequence is enforced. Watch how traffic flows through the connections you build.

TRY IT YOURSELF

Try building this flow: EC2 → Public Subnet → Route Table → Internet Gateway. Watch how the route lights up when connected correctly.

CONTINUE SCROLLING
EC2
SUBNET
ROUTE
IGW
0.0.0.0/0 → internet-gateway
All internet traffic routes through Internet Gateway
4

IGW and NAT Gateway: Reaching the Outside World

To reach the internet, your network needs gateways — like bridges. A Public Subnet uses an Internet Gateway (IGW). A Private Subnet needs a NAT Gateway to go out safely.

HOW IT WORKS

Connect Public Subnet → Route Table → IGW or Private Subnet → Route Table → NAT → IGW. IGW and NAT nodes live outside the VPC visually.

TRY IT YOURSELF

Make a private subnet's EC2 reach the internet: EC2 → Private Subnet → Route Table → NAT → IGW.

INTERNET GATEWAY
Public access
NAT GATEWAY
Private access
Public: EC2 → Subnet → Route → IGW
Private: EC2 → Subnet → Route → NAT → IGW
Ready to Build & Export Your Cloud Architecture

You've mastered the fundamentals. Now experiment with real AWS networking patterns and export deployable Terraform code.

Visual Simulation
See real-time packet flow
AWS Logic
Learn actual cloud patterns
Export Terraform
Generate deployable code