Cloud Networking VPC Simulator — Subnets, Routes, NAT & Security Groups

Interactive VPC simulator — trace traffic through an internet gateway, public web subnet, private database subnet and NAT gateway, and toggle routes and security-group rules to find the exact hop that blocks a connection.

← Cloud Computing Labs
About this tool — how it works & FAQOpen ▾Close ▴

About the Cloud Networking (VPC) Simulator

This simulator draws a small cloud network and lets you test four traffic patterns against it. A connection succeeds only if a route reaches the destination and the policy permits it; switch either off and the lab shows the hop where the packet stops.

What the simulator shows

• A 3D topology with an internet client, an internet gateway and NAT egress, a public subnet holding a web server, a private subnet holding a database, and a route and security-group gate. • A Traffic test selector — Internet to public HTTPS, Web to private database, Private to internet via NAT, or Internet to private database — plus checkboxes for Internet gateway and public IPv4 mapping, Required route present, NAT gateway available and Required security-group rule allows flow. • Readouts for connection attempts, successful modeled connections, blocked attempts, current hop index, whether the current path is allowed, and an illustrative successful round trip. • Experiments for local database access, a missing NAT and unsolicited inbound traffic.

Routes and rules are separate checks

An allowed connection requires a reachable route and the required policy. Public HTTPS from the internet needs the internet gateway and public address mapping; a private instance reaching out additionally needs a NAT gateway; web-to-database traffic uses local routing and works without an internet gateway. A permissive security-group rule cannot create a missing route, and NAT is not an inbound port forwarder, so unsolicited inbound traffic to the private database is unreachable in this topology. Return traffic is handled statefully, as in a security group.

What the model is and is not

The topology is an AWS-style IPv4 layout with stateful security-group return traffic. It does not include network ACLs, DNS, IPv6, peering, endpoint services, ephemeral port exhaustion or a packet-level TCP implementation. It is a reasoning tool for the route-plus-policy idea, not a configuration guide for a specific provider.

Frequently asked questions

Does an allow rule create a route?

No. Reachability and policy are separate checks. In the lab, enabling the security-group rule while the required route is missing still blocks the connection at the routing hop.

Does NAT allow unsolicited inbound traffic?

No. In this topology NAT only supports private-initiated egress and its return traffic. Testing internet to private database stays blocked even with NAT available.

Why can the web server reach the database without an internet gateway?

Traffic between subnets in the same network uses local routing, independent of the internet gateway. The Web to private database test succeeds with the gateway switched off, provided the security-group rule allows it.

What does the current hop index show?

It marks the position along the path where the connection currently is, or where it stopped. When a check fails, the blocked attempt counter increases and the highlight stays at the hop that refused the traffic.

Related tools & guides