I Was Deploying Wrong — What Subnet, Internet Gateway & NAT Gateway Taught Me About My NGold EC2
Day 8: I Was Deploying Wrong — What Subnet, Internet Gateway & NAT Gateway Taught Me About My NGold Attack
People asked me yesterday after my AWS attack alert: "SirVick, do you even know subnet, Internet Gateway, NAT Gateway?" I laughed because 2 days ago I didn't. I just clicked "Launch EC2" and thought AWS does networking automatically. After my instance at 32.196.145.76:3000 was scanned, I finally sat down to learn VPC networking. And I realized I was deploying wrong from Day 1.
Let me explain networking like I explained Docker with garri and cooler — Port Harcourt style, so you never forget.
VPC = Your Fenced Family Compound
VPC (Virtual Private Cloud) is like your family compound in PH. When you create AWS account, AWS gives you default VPC — like government giving you land with fence already built. Inside that fence, you can build houses (subnets), you have main gate (Internet Gateway). Without fence, your house is on the road — anyone enters. My mistake from Day 2-7: I never checked which VPC my EC2 was inside. I used default VPC and thought it's secure. Default VPC is like living in a compound where gate is permanently open.
Subnet = Rooms Inside Compound — Public vs Private
Subnet is subdivision of your compound. You have two types of rooms:
Public Subnet = Room with window facing the main road. Anyone outside can see inside if gate is open. This room has route to Internet Gateway. My NGold EC2 was here. That is why bots found me.
Private Subnet = Room inside inside, no road window. Even if gate is open, outsiders can't see this room. Perfect for database, backend workers, Jenkins server. If I had put my database in private subnet, even if EC2 was attacked, database would be safe.
How to know if subnet is public? Check Route Table. If route table has 0.0.0.0/0 -> Internet Gateway (igw-xxxx), it is public. If 0.0.0.0/0 -> NAT Gateway, or no IGW at all, it is private. I checked my default subnet route table yesterday and saw 0.0.0.0/0 -> igw. Yes, public. So I was literally sleeping with window open.
Internet Gateway = Main Gate of Compound
Internet Gateway (IGW) is the gate that connects your compound to the outside world — the internet. Without IGW, no one inside compound can talk to internet, and internet cannot talk to you. It is 1 gate per VPC. You attach it to VPC. Then you add rule in route table: 0.0.0.0/0 (meaning everywhere) -> IGW. This one rule makes subnet public.
My error: I opened IGW plus Security Group 0.0.0.0/0 for port 22 and 3000. That is like opening main gate PLUS removing burglary proof on all windows. Double danger. Bots scan IGW IP range constantly.
NAT Gateway = Secret One-Way Window
This is where most juniors get confused, including me. NAT Gateway is for private subnet. Imagine you have a boy in private room (no road window). He wants to browse, download apt update, pull Docker image from Docker Hub, but you don't want outsiders to enter his room. How? You give him a special one-way window: He can look outside and go out to buy something, but outsiders cannot look inside or enter. That one-way window is NAT Gateway.
Technically: NAT Gateway lives in public subnet, has Elastic IP, and allows instances in private subnet to initiate outbound connections to internet (for updates, patches) but blocks inbound connections from internet to private instances. So your private database can do apt update, can pull code, but hackers cannot SSH into it even if they know IP.
Fig: NGold Correct 2-Tier Architecture — Public Subnet with IGW (Main Gate) and Private Subnet with NAT Gateway (One-Way Window)
What I Did Wrong vs What I Will Do Now
Wrong architecture (Day 2-7):
- One EC2 in public subnet (default)
- Security Group: 0.0.0.0/0 on 22, 80, 3000
- Docker -p 3000:3000 on 0.0.0.0
- Route: 0.0.0.0/0 -> IGW (public)
Result: AWS GuardDuty alert, penetration attempts.
Correct architecture (Starting Day 8):
- VPC: Custom vpc-ngold (10.0.0.0/16)
- Public Subnet: 10.0.1.0/24 with IGW — only Nginx EC2 here
- Private Subnet: 10.0.2.0/24 with NAT Gateway — App + DB here
- Security Group Public: Only 80, 443 from internet, 22 from my IP only
- Security Group Private: Only allow 3000 from Public SG, no internet direct
- Docker binding: 127.0.0.1:3000:3000
This is called 2-tier architecture. Companies use 3-tier: Public (Load Balancer), Private App, Private DB.
Commands I Used to Learn This
aws ec2 describe-vpcs aws ec2 describe-subnets aws ec2 describe-route-tables aws ec2 describe-internet-gateways
When I ran those, I finally understood my setup.
Lesson: You cannot be DevOps if you only know Docker. You must know networking. Subnet, IGW, NAT is foundation. Without it, you will always deploy like I did — open to world, then surprised when attacked.
My NGold is still stopped for re-architecture. Tomorrow Day 9 I will rebuild with correct VPC + Nginx + SSL at https://sirvickcloud9.online and show diagram.
Question for you: Have you checked if your EC2 is in public or private subnet? Run the route table check and comment Public or Private below.
Live (Paused for VPC rebuild): 32.196.145.76:3000
GitHub: Sirvickcloud91/netflix-frontend-1
Comments
Post a Comment