> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Setting up the VPC environment, launching EC2 instances, and testing reachability using the AWS Reachability Analyzer

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

#### Lab Details

1. The lab involves setting up a VPC environment with two subnets (public and private).
2. Launching EC2 instances in each subnet, configuring the necessary networking components (Internet Gateway, route tables, security groups), and then using the VPC Reachability Analyzer to test the connectivity between the instances.
3. Duration: **1 hour**
4. AWS Region: **US East (N. Virginia) us-east-1**

#### Introduction

1. In the cloud computing environment, ensuring reliable network connectivity between resources is crucial for the smooth functioning of applications and services.
2. AWS VPC Reachability Analyzer is a powerful tool designed to help identify and troubleshoot network connectivity issues within your VPCs. It provides a centralized view of your network resources and their connectivity status, enabling you to quickly diagnose and resolve connectivity problems.
3. The VPC Reachability Analyzer automates the process of testing and validating network connectivity between resources within your VPCs.
4. It provides detailed explanations and recommendations to help you troubleshoot and resolve connectivity problems more efficiently.
5. **Proactive Monitoring:** In addition to on-demand connectivity testing, the VPC Reachability Analyzer can be configured to continuously monitor your VPC resources, enabling proactive detection and notification of connectivity issues as your infrastructure evolves.

#### Architecture Diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/001.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=1fc7fb2de10b1ad2c8d9045b85862afc" alt="" width="1190" height="679" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/001.png" />

#### Task Details

1. Sign in to AWS Management Console
2. Creating VPC service associating with Subnets
3. Launching 2 EC2 instances
4. checking the connectivity using VPC Reachability Analyzer

#### Launching Lab Environment

1. To Launch The Lab Environment, Click On The **Start Lab** Button.
2. Please Wait Until The Cloud Environment Is Provisioned. It Will Take Less Than A Minute To Provision.
3. Once The Lab Is Started, You Will Be Provided With **IAM User Name, Password, Access Key,** And **Secret Access Key**.

> **Note :** You can only start one guided lab at any given time

## Lab guide

#### Lab Steps

#### Task 1: Sign in to AWS Management Console

1. Click On The **Open Console** Button, And You Will Get Redirected To AWS Console In A New Browser Tab.
2. On The AWS Sign-In Page,
3. Leave The Account ID As Default. Never Edit/Remove The 12 Digit Account ID Present In The AWS Console. Otherwise, You Cannot Proceed With The Lab.
4. Now Copy Your **User Name** And **Password** In The Lab Console To The **IAM Username And Password** In AWS Console And Click On The **Sign In** Button.
5. Once Signed In To The AWS Management Console, Make The Default AWS Region As **US East (N. Virginia) Us-East-1**.

#### Task 2: Setting Up Your Environment by creating VPC

1. In the AWS Management Console, you can find the VPC service by clicking on the “Services” dropdown at the top and type VPC in the search bar. Then, select the VPC service from the search results.

2. Once you're in the VPC service dashboard, click on **Your VPCs** and then click on **Create VPC**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/002.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=580dd88aa2cf7181ae2b96b2056ee08f" alt="" width="1570" height="154" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/002.png" />

3. Create a new VPC: Name: **reachability-test-VPC**.

4. Specify an IPv4 CIDR block for your VPC (**10.0.0.0/16**) in the IPv4 CIDR block field.

5. In this case, you're asked to use **10.0.0.0/16** as an example, but you can choose any valid CIDR block that doesn't conflict with your existing network.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/003.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=5332567baf23ee34cb9b12b0aabd9085" alt="" width="1005" height="781" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/003.png" />

6. Click on the **Create VPC** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/004.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=8c846c43dbac51089313312d8e3f2cff" alt="" width="1033" height="355" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/004.png" />

7. Within your newly created VPC, you'll need to create two subnets: one public and one private.

8. To create a subnet, go to the subnets section in the VPC service and click on the **Create Subnet** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/005.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=e49fd27661a6855b52f8b1bd3c4c2090" alt="" width="1004" height="333" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/005.png" />

9. Specify the VPC you just created, the CIDR block for the subnet

* Subnet Name: **public subnet**
* IPv4 subnet CIDR block: **10.0.1.0/24**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/006.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=1b0842a0df2fcee1b139eeaa2e6e9205" alt="" width="1004" height="786" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/006.png" />

10. Now we are going to create the same steps,

* Subnet name: **private subnet**
* subnet CIDR block: **10.0.2.0/24**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/007.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=2825bc4ba649f6b1ff1e86409047736b" alt="" width="1000" height="789" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/007.png" />

11. Configure the route tables and internet gateway for the public subnet

12. For the public subnet to have internet access, you'll need to configure the route table and attach an internet gateway.

13. Go to the Route Tables section in the VPC service and create a new route table for the public subnet.

* Route Table Name: **MY-RT**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/008.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=19a9618d550205673455fe99e293d56d" alt="" width="1031" height="655" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/008.png" />

14. Next, go to the Internet Gateways section and create a new internet gateway.

* Internet Gateway Name: **My-Internet-Gateway**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/009.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=eb0d941f78fedba386e8a7221d443d5f" alt="" width="1045" height="576" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/009.png" />

15. Once Internet gateway is created Select **Actions** from the right side and select **Attach to VPC**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/010.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=e2c05c991ee87f643cd6a4f793eadac2" alt="" width="1524" height="429" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/010.png" />

16. Select the VPC you have created and click **Attach to VPC**. The internet gateway will be attached to the VPC you have created.

17. In the route table, click on Edit routes, then add your internet gateway. The destination should be (**0.0.0.0/0**), and the target should be the internet gateway.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/011.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=a2aed99f1d3e6fa9c0ec2d5ec41e7bbc" alt="" width="1836" height="455" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/011.png" />

#### Task 3: Launch two EC2 instances within this VPC

1. Navigate to EC2 by clicking on the Services menu in the top, then click on EC2 in the Compute section.

2. In the EC2 service, you'll see a left-hand side menu. Click on the Instances option, and then click on the Launch Instances button to start the process of creating a new EC2 instance.

3. Name: Enter **MyEC2Server1**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/012.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=b4a7daa56630b3e54af294f31e0d1876" alt="" width="948" height="200" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/012.png" />

4. You'll be asked to choose an Amazon Machine Image (AMI) for your instance. Search for **Amazon Linux 2023 kernel-6.1 AMI** in the search box and select it by clicking on the Select button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/013.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=6bb2908ae7efc3ea8ce74b12bf6df7b1" alt="" width="1179" height="609" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/013.png" />

5. For Instance Type: Select t2.micro

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/014.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=339e753d0ebf0e5d02e63582e92b5283" alt="" width="971" height="338" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/014.png" />

6. You'll need to create a key pair to securely connect to your EC2 instances. Select the Create a new key pair option.

7. For Key pair(login): Select Create a new key pair Button

* **Key pair name: WhizKey**
* Key pair type: **RSA**
* Private key file format: **.pem**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/015.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=55e3538f67c5169dfc40dca357f68591" alt="" width="753" height="770" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/015.png" />

8. In Network Settings Click on Edit Button:

* VPC: select **reachability-test-VPC**
* Subnet: select **Public subnet**
* Auto-assign public IP: **Enable**
* Select **Create security group**
* Security group name: **Enter MyEC2Server\_SG**
* Description: **Enter Security Group to allow traffic to EC2**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/016.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=b5ff59aa70f006bbf9e0a3f64b28bc6c" alt="" width="969" height="736" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/016.png" />

9. We will now add the security group rules. SSH will already be present there.

* For HTTP, Select Add security group rule Button
* Choose Type: Select HTTP Source: **Select Anywhere**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/017.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=8caa69e5a6ff041389f1d1162070def7" alt="" width="977" height="662" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/017.png" />

10. Click **Launch Instance**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/018.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=98c454aabfcf143fa14785a9c67aabc2" alt="" width="471" height="691" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/018.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/019.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=5c999a5b942f4c1cd0d8d68206493236" alt="" width="1700" height="95" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/019.png" />

11. Repeat the steps to launch another instance, ensuring it's in the same (**reachability-test-VPC**) VPC but in the **private subnet**.

12. To create the second EC2 instance, repeat the same steps 2-8 and make sure to select the same VPC you created.

13. Name: Enter **MyEC2Server2**

14. Create a new security group for this instance, allowing inbound traffic from the first instance's security group.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/020.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=56bb1ad910097fb19721b946437fe5d8" alt="" width="974" height="790" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/020.png" />

15. Security Group for the second EC2 instance (Private):

* Name: **PrivateEC2Server\_SG (or any descriptive name)**
* Description: **Security Group for Private EC2 Instance**
* Inbound Rules:
* Allow All Traffic (or specific ports/protocols) from the MyEC2Server\_SG security group

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/021.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=24327afc07d823dd6211776c254d13d9" alt="" width="979" height="647" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/021.png" />

16. Click **Launch Instance**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/022.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=911c01556b02b0b35513dfb99da0a627" alt="" width="1588" height="243" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/022.png" />

#### Task 4: Testing Connectivity

1. Go to **AWS Network Manager** you'll see a left-hand side menu. Click on the Reachability Analyzer option and click on **create and analyze path**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/023.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=29cbd8a72d066b5f730c521eca81cb44" alt="" width="376" height="487" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/023.png" />

2. Name tag: **ec2-to-ec2-reachability**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/024.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=c7112c2573b14a869ac7118e98220c48" alt="" width="1001" height="224" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/024.png" />

3. In the **source type**, select instances and choose the first EC2 instance you created.

4. In the **destination type**, select instances and choose the second EC2 instance.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/025.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=2a75c1076971f60d0d780ad00898f3fd" alt="" width="1004" height="731" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/025.png" />

5. Leave everything as default.

6. After configuring the source and destination instances, click on the **create and analyze path** button to run the analysis test.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/026.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=6a7fcd44c7a8ce8cc662d64a5ed86093" alt="" width="1479" height="72" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/026.png" />

#### Task 5: Now We are going to analyze the path to both the source and destination

1. Click on the Analyze path to reach the both source and destination path.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/027.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=3cacc4fbb7d56e1a906401ce93087bba" alt="" width="1374" height="350" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/027.png" />

2. click on the confirm button

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/028.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=2b1061207a5595b33f685162f6a62eed" alt="" width="1025" height="395" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/028.png" />

#### Task 6: Reviewing Results

1. Once the reachability test is complete, review the results displayed by the Reachability Analyzer.

2. If the test result shows Reachable, it indicates that the two EC2 instances can communicate with each other within the VPC you created.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/661uoCRNYJkWyoF5/images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/029.png?fit=max&auto=format&n=661uoCRNYJkWyoF5&q=85&s=e20d1551800450136781eefc50fc524e" alt="" width="1376" height="302" data-path="images/labs/setting-up-the-vpc-environment-launching-ec2-instances-and-testing-reachability-/029.png" />

3. If the test result shows unreachable, the Reachability Analyzer will provide detailed information about the issue and potential reasons for the connectivity problem between the two instances.

> **Do you know?**
> Introducing VPC Reachability Analyzer, a game-changer in AWS network troubleshooting. Unlike traditional methods, it dynamically maps network traffic, providing real-time insights across VPCs and subnets. This end-to-end visibility extends beyond boundaries, automating root cause analysis and integrating seamlessly with AWS services like CloudWatch. Not just troubleshooting, it ensures compliance and security, scaling effortlessly from small deployments to enterprise networks. With its speed, accuracy, and automation, VPC Reachability Analyzer revolutionizes network management in AWS environments.

#### Completion and Conclusion

1. You Have Successfully logged into AWS console.
2. You Have Successfully created VPC.
3. You Have Successfully created EC2 instance.
4. You Have Successfully created Reachability analyzer

#### End Lab

1. **Sign Out** Of AWS Account.
2. You Have Successfully Completed The Lab.
3. Once You Have Completed The Steps, Click On **End Lab** From Your IP Lab Portal And Wait Till The Process Gets Completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Create Amazon Custom VPC** — Check whether a Custom VPC is created or not.
* **Create Amazon Custom VPC Subnet** — Check whether a Subnet is created for the Custom VPC or not.
* **Create Internet Gateway** — Check whether an Internet Gateway is created and attached to the Custom VPC or not.
* **Launch an EC2 Instance** — Check whether an EC2 Instance is launched or not.
* **Create Network Reachability Analyzer** — Check whether a Network Reachability Analyzer path is created or not.

## Related help

* [FAQs and Troubleshooting](/aws-saa/support/faqs-and-troubleshooting)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.