# Default Components Created When a VPC Is Established in AWS

> Discover the six default components AWS creates when you establish a VPC, including subnets, route tables, and internet gateways. Understand your VPC's core infrastructure.

- Repository: [Anil Kumar/DevOps-Interview-Guide](https://github.com/litu54/DevOps-Interview-Guide)
- Tags: how-to-guide
- Published: 2026-08-10

---

**When you establish an Amazon Virtual Private Cloud (VPC), AWS automatically provisions six default components: subnets in each Availability Zone, a route table, an Internet Gateway, a Network ACL, a Security Group, and a DHCP Options Set.**

Creating a VPC triggers AWS to instantiate a complete networking foundation without requiring manual resource provisioning. As documented in the `litu54/DevOps-Interview-Guide` repository within the [`TCS/SRE_1.md`](https://github.com/litu54/DevOps-Interview-Guide/blob/main/TCS/SRE_1.md) file, these default components provide immediate connectivity and security boundaries for cloud resources. Understanding these automatically created elements is essential for DevOps engineers managing AWS infrastructure.

## The Six Default AWS VPC Components

AWS establishes a functional network environment by automatically creating the following resources when you provision a new VPC.

### Default Subnets

One subnet is automatically created in each Availability Zone (AZ) within the VPC's CIDR block. These subnets are sized to `/20` for IPv4 and are immediately ready for launching EC2 instances. According to the source analysis in [`TCS/SRE_1.md`](https://github.com/litu54/DevOps-Interview-Guide/blob/main/TCS/SRE_1.md), these default subnets eliminate the need for manual subnet calculation during initial VPC setup.

### Default Route Table

A **default route table** is automatically associated with each default subnet upon VPC creation. This table contains a local route for intra-VPC traffic and, specifically for default VPCs, includes a route to the attached Internet Gateway. You can view this in the AWS Console or retrieve it via infrastructure-as-code tools to verify traffic routing rules.

### Default Internet Gateway (IGW)

An **Internet Gateway** is created and automatically attached to the VPC, enabling internet connectivity for resources deployed in public subnets. This component serves as the bridge between your VPC and the public internet, allowing outbound traffic and responses to inbound requests.

### Default Network ACL

AWS provisions a **default Network Access Control List (NACL)** that permits all inbound and outbound traffic (`0.0.0.0/0`) by default. This stateless firewall is associated with each subnet unless you explicitly replace it with a custom NACL. While permissive by design, it ensures immediate network communication for newly launched resources.

### Default Security Group

The **default Security Group** automatically permits inbound SSH (port 22) and RDP (port 3389) from any IP address while allowing all outbound traffic. As implemented in AWS and noted in the DevOps interview guide, this security group is automatically applied to new instances launched without a specific security group assignment, providing baseline remote access capabilities.

### Default DHCP Options Set

The VPC utilizes the **AWS-provided DHCP Options Set** for domain name resolution and configuration. This includes default domain-name-servers, domain-name, and NTP server configurations unless you create and associate a custom DHCP options set with your VPC.

## Referencing Default Components in Terraform

When provisioning infrastructure with Terraform, these default components exist implicitly but can be referenced using data sources. The following HCL examples demonstrate how to access these automatically created resources after VPC establishment.

To reference the default subnets created across Availability Zones:

```hcl
data "aws_subnet_ids" "default" {
  vpc_id = aws_vpc.example.id
}

```

To access the automatically attached Internet Gateway:

```hcl
data "aws_internet_gateway" "default" {
  filter {
    name   = "attachment.vpc-id"
    values = [aws_vpc.example.id]
  }
}

```

To retrieve the default security group for rule modifications:

```hcl
data "aws_security_group" "default" {
  filter {
    name   = "vpc-id"
    values = [aws_vpc.example.id]
  }
}

```

These data sources allow you to modify default security group rules, adjust route table entries, or associate the default subnets with additional resources without recreating the underlying VPC components.

## Summary

- AWS automatically creates six components when establishing a VPC: **default subnets**, a **route table**, an **Internet Gateway**, a **Network ACL**, a **Security Group**, and a **DHCP Options Set**.
- Default subnets are provisioned as `/20` CIDR blocks in every Availability Zone within the VPC region.
- The default security group permits SSH and RDP access from any IP, while the default Network ACL allows all traffic.
- These resources provide immediate connectivity but should be customized for production security requirements.
- You can reference these components in Terraform using data sources to modify their configurations.

## Frequently Asked Questions

### What is the difference between a default VPC and a custom VPC in AWS?

A default VPC is the pre-configured VPC created automatically by AWS in new regions, containing all default components with public subnets and internet connectivity enabled immediately. A custom VPC requires you to manually define the CIDR block, create subnets, and configure gateways, though AWS still creates the six default components (route table, security group, etc.) automatically when you establish it.

### Can you delete the default components created with a new VPC?

You cannot delete the default route table, default security group, or default Network ACL, as these are required VPC resources that AWS maintains for the lifecycle of the VPC. However, you can delete default subnets and detach the Internet Gateway if you no longer require internet connectivity, though you must first ensure no dependencies exist on these resources.

### How does the default security group differ from custom security groups?

The default security group is automatically applied to instances when no other security group is specified during launch, and it initially allows inbound SSH and RDP from any IP address. Unlike custom security groups, the default security group cannot be deleted from the VPC, and it uses the security group ID as its name rather than a descriptive label you define.

### Are default subnets public or private by default?

Default subnets are public by default because the automatically created route table includes a route to the Internet Gateway, allowing instances launched within them to access the internet directly. If you require private subnets, you must create additional subnets manually and configure their route tables to route traffic through a NAT Gateway instead of the default Internet Gateway.