Overview
Project Details
- This project walks you through the steps to implement VPC peering in AWS.
- Duration: 01:00:00 Hrs
- AWS Region: US East (N. Virginia)
Introduction
AWS VPC Peering
- Amazon VPC allows us to launch the AWS resources in an isolated network that is defined by us in a more private and secure environment.
- VPC peering connection is connecting two VPCs which enables us to communicate between the VPCs as if they are in the same network.
- VPC peering connection can be established between VPCs of the same AWS account or of two different AWS accounts.
- VPC peering connections can be established between VPCs of the same or different accounts in different AWS regions too (cross regions).
- VPC peering connection enables us to access the AWS resources in another VPC
- The traffic flow between the instances in the two peered VPcs happens via the private network.
- The communication between the AWS resources in the VPC peered network can be done with the help of private IP addresses.
- The traffic between the VPC resources is encrypted and hidden from the outside world which makes communication between the peered resources highly secured.
- Transfer of data between the resources in a VPC peered network is very cost-efficient and simple.
Points to remember while creating a VPC peering connection
- The two VPC’s CIDR block should not be overlapping
- It cannot resolve private DNS values across VPCs
- No cross-referencing of security groups between VPCs(security group is within a VPC and even though it peered same security group cannot be used)
- NAT routing between the VPCs is not allowed
Architecture Diagram

Project Tasks
- Sign in to the AWS Management Console
- Create two VPCs’ in N. Virginia region
- Create and attach an Internet gateway
- Creating subnets for both the VPCs
- Creating Route tables, configuring routes, and associating subnets
- Creating VPC Peering Connection
- Editing routes in the Route table
- Creating an EC2 Instance
- Creating a Security Group for the RDS instance
- Create a RDS Instance
- SSH into EC2 and Connect to Your Database
Launching Project Environment
- To launch the lab environment, Click on the Start Project button.
- Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
- Once the Lab is started, you will be provided with an IAM username, Password, Access Key, and Secret Access Key.?
Note: You can only start one Project at any given time
Lab guide
Project Steps
Task 1: Sign in to the AWS Management Console
- Click on the Open Console button, and you will get redirected to AWS Console in a new browser tab.
- On the AWS sign-in page,
- Leave the Account ID as default. Never edit/remove the 12-digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
- Now copy your User Name and Password in the Lab Console to the IAM Username and Password in the AWS Console and click on the Sign in button.
- Once Signed In to the AWS Management Console, Make the default AWS Region as US East (N. Virginia) us-east-1.
Task 2: Create two VPCs’ in N. Virginia region
- Make sure you are in the N. Virginia region.
- Navigate to VPC by clicking on the Services menu at the top, then click on VPC in the Network and Content Delivery section.
-
Navigate to Your VPCs on the left panel and click on the Create VPC button.
- Resources to create: Select VPC only
- Name tag: Enter whizlabs_VPC1
-
IPv4 CIDR block: Enter 10.0.0.0/16

-
Click on Create VPC. To create the 2nd VPC, click on the Create VPC at the top right.
- Resources to create: Select VPC only
- Name tag: Enter whizlabs_VPC2
-
IPv4 CIDR block: Enter 192.168.0.0/16
-
Click on the Create VPC button.

-
Click on the Create VPC button.
Task 3: Create and attach an Internet gateway
-
Navigate to the Internet Gateways from the left side menu and click on the Create internet gateway button.
- Name tag: Enter whizlabs_IGW
- Click on the Create internet gateway
-
Now click on the Action button and select Attach to VPC.
- Available VPCs: Select whizlabs_VPC1 from the list.

- Now click on the Attach internet gateway.
Task 4: Creating subnets for both the VPCs
- Navigate to Subnets from the left side menu and click on Create Subnet.
- VPC ID: Select the whizlabs_VPC1 VPC from the list.
- Subnet name: Enter Subnet 1
- Availability Zone: Leave as No Preference
-
IPv4 CIDR block: Enter 10.0.1.0/26

- Click on Add new subnet again to create one more subnet
- VPC ID: Select the whizlabs_VPC1 VPC from the list.
- Subnet name: Enter Subnet 2
- Availability Zone: Leave as No Preference
-
IPv4 CIDR block: Enter 10.0.2.0/26

- Now click on the Create subnet button.
- Similarly, Create 2 Subnets in the VPC named whizlabs_VPC2 which can be used either for public or private resources.
- For Subnet 1:
- VPC ID: Select the whizlabs_VPC2 VPC from the list.
- Subnet name: Enter Subnet 3
- Availability Zone: Select us-east-1a
-
IPv4 CIDR block: Enter 192.168.1.0/26

- Click on Add new subnet to create one more subnet
- VPC ID: Select the whizlabs_VPC2 VPC from the list.
- Subnet name: Enter Subnet 4
- Availability Zone: Select us-east-1b
- IPv4 CIDR block: Enter 192.168.2.0/26
- Click on the Create Subnet button.
Task 5: Creating Route tables and configuring routes and associating subnets
- Create 2 route tables one for the Public route and another for the private route in different VPCs
- Navigate to Route Tables on the left side panel and click on the Create route table button.
- Name tag: Enter public_route
- VPC: Select the whizlabs_VPC1 from the list.

- Now click on the Create route table button.
- Select the public_route from the list and go to the Subnet Associations tab in below.
- Click on the Edit subnet associations tab.
-
Now Select the subnet Subnet 1 and Subnet 2 and click on the Save associations button.

- Click on the Create route table button again.
- Name tag: Enter private_route
- VPC: Select the whizlabs_VPC2 from the list.

- Now click on the Create route table button.
- Select the private_route from the list and go to the Subnet Associations tab in below.
- Click on the Edit subnet associations button.
- Now select Subnet 3 and Subnet 4 and click on the Save associations button.

- Select the public_route table. Go to the Routes tab below and click on the Edit Routes button.

- Now click on the Add route button.
- Destination: Enter 0.0.0.0/0
- Target: Select Internet Gateway whizlabs_IGW and then select the Internet Gateway id.

- Click on the Save changes button. Note: Here we haven’t created any routes for the private_route table. Don’t edit or delete the default Route table.
Task 6: Creating VPC Peering Connection
- Now Navigate to your N.Virginia region VPC page.
-
On the left side menu, select Peering Connections and click on Create Peering connection
- Peering connection name tag: Enter whizlabs_peer
- VPC ID (Requester): Select whizlabs_VPC1
- Account leave as default
- Region: Select This region (us-east-1)
- VPC ID (Accepter): whizlabs_VPC2

- Click on the Create peering connection button.
- Now the status of the peering will be in Pending Acceptance.

- Select the peering connection and click on Action and then click on Accept Request.
-
Click on Accept request in the popup message.

- Once this is done, the Status changes to Active. If not please refresh the page.

- Now you need to add peering rules in route tables in both the VPC’s.
- This is because, without this route, the traffic will not pass the route table and reach the EC2s.
Task 7: Editing routes in the Route table
- Once the peering connection is established you need to edit the route tables that you have created earlier to include the route of CIDR block of other VPC.
- You need to add routes to the route table that you have created to include the VPC CIDR range of the other VPC you need to peer.
- Go to Services, and click on VPC. Choose Route Tables and select public_route table.
- Select the public_route table. Go to the Routes tab below and click on the Edit routes button.
- Now click on the Add route button.
- Destination: Enter 192.168.0.0/16
- Target: Select Peering Connection and then select the whizlabs_peer.

- Click on the Save changes button.
- Now Select the private_route table. Go to the Routes tab below and click on the Edit routes button.
- Click on the Add route button.
- Destination: Enter 10.0.0.0/16
- Target: Select Peering Connection and then select the whizlabs_peer.

Task 8: Creating an EC2 Instance
- Make sure you are in the N.Virginia Region.
- Navigate to EC2 by clicking on the Services menu at the top, then click on EC2 in the Compute section.
- Navigate to Instances from the left side menu and click on the Launch Instance button.
- Enter Name as VPC_peering_EC2.
- Choose an Amazon Machine Image (AMI): Select Amazon Linux 2023 kernel-6.1 AMI in the drop-down.
-
Choose architecture as 64-bit(x86)

-
Choose an Instance Type: Select t2.micro.

-
For Key pair: Select Create a new key pair Button
- Key pair name: Enter WhizKey
- Key pair type: Select RSA
- Private key file format: Select .pem
-
Select the Create key pair Button.

- In Network Settings Click on Edit Button:
- VPC - required: Select whizlabs_VPC1
- Subnet name: Select any Subnet
- Auto-assign public IP: Enable
- Select Create new Security group
- Security group name: Enter MyEC2Server_SG
-
Description: Enter Security Group to allow traffic to EC2

-
To add SSH,
- Choose Type: SSH
- Source: Select Anywhere
- Now under Advanced Details, scroll down to User Data, and copy and paste the script:
- Keep the Rest thing Default and Click on the Launch Instance Button.
- Launch Status: Your instance is now launching, Click on the instance ID and wait for the complete initialization of the instance till the status changes to running.

- Note down the sample IPv4 Public IP Address of the EC2 instance. A sample is shown in the screenshot below.

Task 9: Creating a Security Group for the RDS instance
- Create a security group for the RDS instance which will provide access for the EC2 instance to connect with the RDS.
- Navigate to VPC by clicking Services on the top menu. Click on Security Groups in the left navigation panel. Click on the Create Security Group button and then provide the following details
- Security group name: Enter rdssecurity
- Description: Security group for RDS instance
- VPC: whizlabs_VPC2 (select from the dropdown)
- Now you need to add Inbound rules to the Security group that you have created, Click on Add rule under Inbound Rules
- Type: MYSQL/Aurora (select from the drop-down)
- Source: Custom: Copy and paste the EC2 instance’s private IP from the instance description page along with a CIDR block range /32 at the end (in my case it is 10.0.1.61/32 )
-
Click on the Create Security Group button**.**

Task 10: Create a RDS Instance
- Navigate to RDS available under the database section of the Services menu.
- Make sure you are in the N.Virginia Region.
- Click on Databases in the left panel.
- Click on Create Database.
- Let’s configure the database in the Create Database Page In Choose a Database Creation Method: Select Full Configuration
-
In Engine options
-
Engine type: Choose MySQL

-
Engine type: Choose MySQL
-
In Templates: Choose Sandbox/Free Tier

-
In Settings
- DB cluster identifier: Specify cluster identifier name as whizlabs-identifier
-
In credential settings
- Master Username: Enter whizlabs_admin
- Master password: Enter Whizlabs123
- Confirm password: Enter Whizlabs123
- Note: These are the username and password used to log on to your database. Please make note of them.
- In DB instance size:
- DB instance class: Choose Burstable classes (includes t classes)
-
Select db.t3.micro from the available list

- Uncheck the Enable storage autoscaling checkbox.
- Connectivity
- Virtual Private Cloud: Choose whizlabs_VPC2
- Subnet group: Create New subnet group
-
Publicly accessible: No

- VPC security group: Select Choose existing
- Existing VPC Security group: rdssecuritygroup (remove the default and select it from the drop-down)
- Availability Zone: No preference
- Database port: 3306
- Click on Additional Configuration.
-
Database options
- Initial database name: Enter whizlabsdb
- Uncheck the Enable automated backups checkbox.
- Uncheck the Enable auto minor version upgrade checkbox
- Once filled in all the necessary then click on Create database.
- It will take around 10-15 minutes for the database to be created. Please wait until the database status changes from creating to available.
- Once the database is created, you can see the Status as Available.
- To connect the RDS instance we need the Endpoint (DNS name for RDS instance).
-
Click on the RDS instance created and then navigate to Connectivity & security to find the endpoint of your RDS instances with which you can connect to your DB instance.

- My RDS endpoint: whizlabs-identifier.ckme4zarvihq.us-east-1.rds.amazonaws.com
Task 11: SSH into EC2 and Connect to Your Database
- SSH into the EC2 instance using the following steps in SSH into EC2 Instance.
- Switch to root user using the command:
- Hostname: whizlabs-cluster.cdegnvsebaim.us-east-1.rds.amazonaws.com (In the above command you have to remove the RDS endpoint and use your RDS’s endpoint )
- User name: whizlabs_admin
- Enter the Password: Whizlabs123
- Database name: whizlabsrds
- You can now able to log in to the database as shown below:

- EC2 instance can able to establish a connection with the RDS instance if it is in the same VPC but in our case, we can able to connect the RDS instance from the EC2 instance even though they are in different VPCs. This can only be possible if a peering connection is established between the VPC’s.
Do you know?
It’s important to note that VPC peering is limited to specific scenarios. For example, it’s only possible to peer VPCs within the same AWS region, and you cannot peer VPCs that have overlapping IP address ranges. Additionally, some advanced networking features may not work across peered VPCs.
- Once the project steps are completed, please click on the Validation button on the Right side panel.
Completion and Conclusion
- In this lab, you have successfully created 2 VPCs with non-overlapping CIDR blocks.
- You have successfully created an Internet gateway and associated it with any of the created VPC.
- You have successfully created 4 subnets, 2 subnets per VPC.
- You have successfully created 2 Route tables each in a separate VPC.
- You have successfully created Associate the subnets with the route tables.
- You have successfully created the Initiate VPC Peering connection from VPC1 to VPC2 and accepted the connection.
- You have successfully edited route tables to have access to the other VPC CIDR blocks in the routes.
- You have successfully created a Security group to allow SSH access from anywhere in the inbound rule.
- You have successfully launched an EC2 instance in a VPC with auto-assigned IP
- You have successfully created another security group with port 3306 open only for the private IP of the EC2 instance.
- You have successfully launched an RDS instance in another VPC.
- You have successfully SSH into the EC2 instance.
- You have successfully logged into the RDS instance from the EC2 instance.
End Project
- Sign out of the AWS Account
- You have successfully completed the project.
- Click on the End Project button from the IP Lab Portal console and wait till the process gets completed.
What gets checked
When you press Check my work, the platform verifies each of these:- Create Amazon Custom VPC — Check whether a Custom VPC is created or not.
- Create VPC Peering Connection — Check whether a VPC Peering Connection is created with Active status or not.
- Launch an EC2 Instance — Check whether an EC2 Instance is launched or not.
- Validate EC2 Instance Type t2.micro — Check whether the EC2 instance type is t2.micro.
- Launch EC2 AMI type Amazon Linux — Check whether the EC2 instance is launched using an Amazon AMI.
- Launch RDS instance — Check whether an RDS Instance is created or not
- Check whether RDS database Engine type is mysql — Check whether allowed database type mysql is deployed or not