Virtual Private Cloud: A Secure Network in the Cloud

23 September, 2026

Nadine Kustos
Nadine Kustos
Marketing Manager

by | Sep 23, 2026

Read more about these topics:

Blog Cloud General 

 

Don’t miss any more posts:
Subscribe to our newsletter

Every request you send in an app, every backup that runs overnight, every API call between two microservices: Behind all of this is a network that reliably and securely moves data from point A to point B. Although this network is invisible in the cloud, it determines whether your systems work together seamlessly or become a security vulnerability. Anyone setting up a Virtual Private Cloud must understand how VPCs, firewalls, and gateways work together.

In this article, we explain the most important network fundamentals in the cloud in an easy-to-understand way and show how companies can design their cloud infrastructure to be both secure and high-performing.

What Is a Virtual Private Cloud (VPC)?

A Virtual Private Cloud (VPC) is a logically isolated network segment within a larger cloud infrastructure. Think of it like a property with its own fence: Your neighbors use the same street—that is, the physical hardware—but without your permission, no one can look over your fence or even walk onto your property. Technically speaking, you get your own IP address space, your own routing rules, and full control over which systems are allowed to communicate with each other.

At NWS, we implement this using OpenStack. Your cloud infrastructure—from virtual machines to Kubernetes clusters—runs on a network that belongs exclusively to you. This is particularly important for companies that process sensitive data or must comply with strict regulations such as ISO 27001 or the GDPR.

The main difference from a traditional, physical data center lies in its flexibility. You can set up a new subnet, an additional route, or another security group in just a few minutes using the API or the interface—without any technicians or cable installation. At the same time, isolation remains just as effective as in a physically separate network. For you, this means you get the security of a dedicated infrastructure without sacrificing the speed of the cloud.

Within a VPC, you can create the following resources yourself:

  • IP Address Ranges
  • Subnets
  • Routing
  • Firewalls
  • Internet Access
  • VPN connections
  • Private connections

This creates a isolated environment that allows only defined communication channels.

Advantages of a VPC

  • Complete isolation from other cloud customers
  • Custom network architecture
  • Improved security controls
  • Flexible scaling
  • Easy integration with on-premises systems

Subnets and IP Ranges as a Blueprint

Within your VPC, you divide the address space into subnets—for example, one for web servers, one for databases, and one for internal tools. This separation not only keeps things organized but also limits the damage if something does go wrong.

Public Subnet

A public subnet is connected to the Internet.

Typical systems:

  • Web Server
  • Reverse Proxies
  • Load Balancers
  • Bastion hosts

These systems are accessible from the outside.

Private Subnet

Private subnets do not have direct Internet access.

For example, the following are running here:

  • Databases
  • Kubernetes Worker Nodes
  • Internal APIs
  • Storage Systems
  • Backend Services

This significantly reduces the attack surface.

Isolation Between Projects and Clients

Strict separation at the network level is particularly important when dealing with multiple environments, such as development, staging, and production. This prevents a test server from accidentally communicating with production systems. In a multi-tenant setup, where you serve multiple clients on the same infrastructure, this isolation is actually mandatory. Network segmentation enhances security. A key security principle is: Not all systems should be allowed to communicate with one another.

Example:

  • Web Server
  • APIs
  • Databases
  • Development Environment
  • Production environment

Each area has its own access rules.

Advantages:

  • smaller attack surface
  • better control
  • greater compliance
  • easier troubleshooting

Firewalls & Security Groups: The Gatekeepers of Your Cloud

A VPC defines which instances are generally located on the same network. Firewalls and security groups, on the other hand, determine which devices within this network—and across different subnets—are actually allowed to communicate with one another. They examine each data packet based on its sender, destination, and port before allowing it through or blocking it.

Firewalls: The Most Important Security Measure

Firewalls control data traffic.

You decide:

  • Who is allowed to communicate?
  • Which ports are open?
  • Which protocols are allowed?
  • Which IP addresses have access?

Modern cloud platforms use multiple layers of firewalls.

Network Firewalls

They operate at the network level.

Examples:

  • TCP
  • UDP
  • ICMP
  • IP addresses
  • Ports

They protect entire networks.

Host firewalls

In addition, operating systems may have their own firewalls.

Examples:

  • iptables
  • nftables
  • Windows Firewall

These protect individual servers.

Security Groups and Access Control Lists (ACLs)

Many cloud providers rely on two additional security mechanisms.

Security Groups

Security groups operate in a stateful manner.

You define:

  • Allowed Inbound Connections
  • Allowed Outgoing Connections

They apply directly to instances or containers.

Network ACLs

ACLs operate at the subnet level.

You are responsible for:

  • all network traffic
  • incoming packets
  • outgoing packets

They complement security groups.

Security Groups vs. Traditional Firewalls

A traditional firewall is typically located centrally at the network edge and filters all incoming and outgoing traffic. Security groups offer finer-grained control: You attach them directly to individual virtual machines or services. For example, your web server might have a rule that only allows traffic on port 443 from the outside, while your database server has a rule that accepts connections only from the web servers and no one else. This creates multiple layers of security on top of each other, rather than relying on a single wall.

The Least Privilege Principle in Practice

The most important rule when configuring security groups: Allow only what is truly necessary. Open ports “just in case” are the most common cause of security incidents down the line. Anyone operating a cloud infrastructure with NWS can manage security groups directly via the API or the interface and regularly review which rules are actually still in active use.

Routing: How Data Finds Its Way

Routing tables are used to ensure that data packets can travel between different networks.

These define:

  • which destination is reachable
  • which path packets are transmitted over
  • which gateways are used

A typical workflow:

User → Load Balancer → Web Server → API → Database

Each step is carried out according to defined routing rules.

DNS: Navigation on the network

Without DNS, users would have to know IP addresses.

DNS translates:

www.meinefirma.de

to

203.0.113.42

Cloud DNS services also offer:

  • High Availability
  • Geo-routing
  • Failover
  • Load balancing

Gateways: The Interfaces to the Outside World

Your VPC may be protected, but if it’s completely isolated, it’s of no use to anyone. Data traffic has to be able to get in and out somewhere. That’s exactly what gateways are for: clearly defined and controlled passages between your private network and the outside world.

Private Gateways and Direct Connections

For business-critical applications, an Internet connection is often not enough.

That’s why cloud providers offer private network connections.

Advantages:

  • lower latency
  • higher bandwidth
  • Stable connection
  • No public Internet route

Banks, manufacturing, and the healthcare sector, in particular, frequently rely on these solutions.

Internet and NAT Gateway

An Internet gateway allows your systems to communicate with the Internet—for example, to download updates or access external APIs. A NAT gateway translates private IP addresses into a public address, allowing internal servers to communicate outbound without being accessible from the outside. While your database does not need to be visible from the outside, this is not the case for your web server, which retrieves data from an external API.

Internet Gateway

An Internet gateway connects a VPC to the public Internet.

Without an Internet Gateway:

  • No public websites
  • No APIs
  • No external user access

Only resources with the appropriate routing configuration can communicate through it.

NAT Gateway

Many servers require Internet access but should not be accessible from the outside.

Examples:

  • Operating System Updates
  • Download Container Images
  • Install software packages
  • Use Cloud APIs

A NAT gateway is used for this purpose.

It enables:

  • Outgoing connections
  • No incoming connections

This ensures that internal systems remain protected.

VPN as a Service for Secure Site Connectivity

If you want to connect your office network directly to your cloud infrastructure, a VPN gateway is the right choice. Data traffic is encrypted and routed through a tunnel, so it’s as if the office and the cloud were in the same room. For companies with multiple locations or remote teams that need to access internal systems, this is often the simplest solution for staying productive without exposing a public attack surface.

The following communicate:

  • Data Center
  • Cloud
  • Branch Offices

via VPN connections.

Typical applications:

  • Site Connectivity
  • Remote Work
  • Hybrid Cloud
  • Disaster Recovery

Load Balancers as Traffic Directors

A load balancer is also part of the network architecture. It distributes incoming requests across multiple servers, ensures an even load, and often directly handles the establishment of TLS connections. This keeps your system accessible and fail-safe even during peak loads.

Advantages:

  • Higher availability
  • better performance
  • Automatic load balancing
  • Reliability

Modern cloud platforms support:

  • Layer 4 Load Balancing
  • Layer 7 Load Balancing
  • SSL Offloading
  • Health Checks

Zero Trust Networking

Modern cloud security is increasingly based on the zero-trust principle.

The basic idea:

No one is automatically trusted, not even within one’s own network. Every connection is verified.

Typical measures:

  • Identity Verification
  • Multi-factor authentication
  • Least Privilege
  • Encrypted Communication
  • Continuous monitoring

Zero Trust is becoming increasingly important, particularly in multi-cloud and hybrid cloud environments.

Encryption During Data Transmission

Data should not only be protected at rest but also in transit.

Common methods:

  • TLS
  • HTTPS
  • SSH
  • IPSec
  • WireGuard

This ensures that data remains protected even if the connection is intercepted.

Monitoring Network Traffic

A secure network requires transparency.

Modern cloud platforms monitor:

  • Network Traffic
  • Bandwidth
  • Error rates
  • Latencies
  • Unusual connections
  • Attempted attacks

Tools such as Prometheus, Grafana, and OpenTelemetry help companies identify issues early on and continuously optimize their infrastructure.

Best Practices for Secure Cloud Networks

Companies should consider the following recommendations:

  • Consistently separate resources into public and private subnets.
  • Configure firewalls according to the “default deny” principle.
  • Consistently implement network segmentation.
  • Encrypt all data transfers without exception.
  • Use VPNs or private connections for hybrid environments.
  • Regularly review access permissions and remove unnecessary permissions.
  • Establish permanent network monitoring.
  • Integrate zero-trust principles into the network architecture.
  • Manage security policies automatically using Infrastructure as Code (IaC).
  • Regularly audit firewall and routing rules.

Common Pitfalls in Cloud Networks

In practice, we at NWS consistently observe the same patterns whenever a cloud network later becomes a problem. These issues usually arise not from negligence, but from time pressure: A rule is quickly enabled to fix a deployment error and then simply remains in place.

A classic example is a database that is made accessible “just for a short time” from anywhere in order to run a migration script. Weeks later, no one remembers why that rule exists, and it becomes an open door for anyone looking for it. Equally common is a VPC that exists but has not been further divided into subnets. In this case, the front end, back end, and database are all on the same flat network, and a single compromised application can move freely throughout it.

It’s also worth taking a closer look at gateways. Is every service that’s currently publicly accessible actually needed, or is internal access via “VPN as a Service” entirely sufficient? Those who regularly review their network and consistently remove rules that are no longer needed significantly reduce their attack surface without sacrificing functionality. This is precisely one of the reasons why many of our customers prefer to hand this task over to a managed service like MyEngineer®. That way, someone stays on top of things, even when other issues take priority in day-to-day operations.

Common Mistakes in Cloud Networks: A Summary

Similar configuration errors occur time and again:

  • Databases are publicly accessible.
  • Security groups allow an unnecessarily large number of ports.
  • All systems are on the same subnet.
  • Lack of network segmentation.
  • No monitoring of network traffic.
  • Unencrypted internal communication.
  • Firewall rules are too broad.
  • Test systems with open access that have not been removed.

These errors significantly increase the risk of security incidents.

Interaction in Practice: An Example

Imagine a SaaS company that runs its application in three environments: development, staging, and production. Each environment has its own VPC with separate subnets for frontend, backend, and database. Security groups allow only the communication necessary for the respective service. Via the Internet Gateway, incoming traffic is only allowed through the production environment’s load balancer, while all other environments remain invisible from the outside. Developers securely access internal tools via a VPN-as-a-Service without those tools needing to be publicly accessible.

The result: An error in the staging environment cannot compromise production. Nevertheless, the system remains quickly accessible to customers at all times. It is precisely this interplay between VPCs, security groups, and gateways that makes the difference between a cloud infrastructure that “somehow works” and one that remains stable even in the event of a security incident.

Conclusion

A Virtual Private Cloud, firewalls, and gateways are not separate tools, but rather a system that works together. The VPC creates the secure environment, security groups regulate communication in detail, and gateways control what goes out and what comes in. If you plan these three layers carefully from the start, you’ll save yourself a lot of trouble in an emergency while also protecting your customers’ data. At NWS, you get all of this directly from a single source on a German cloud infrastructure based on modern open-source technologies.

How is your cloud network currently set up? Feel free to check out our cloud services or talk to our team about your specific network architecture.

Our portfolio

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

How did you like our article?