Cloud networking virtualizes the physical network fabric, giving you isolated environments, programmable routing, and global connectivity without owning hardware.
Virtual Private Cloud (VPC)
A VPC is a logically isolated section of a provider’s network. You define IP ranges, subnets, routing tables, and access control. All resources within a VPC are isolated from other tenants by default.
| Provider | Term | Key feature |
|---|---|---|
| AWS | VPC | Default VPC created per region; VPC peering and Transit Gateway for connectivity |
| Azure | Virtual Network (VNet) | Native global VNet peering; Azure Virtual WAN for hub-and-spoke |
| GCP | VPC | Global VPC — a single VPC spans all regions (vs. per-region for AWS/Azure) |
| OCI | VCN | Strong isolation; consistent networking performance |
GCP’s global VPC is a notable differentiator — subnets are regional, but the VPC itself spans regions, simplifying cross-region architecture.
Load Balancing
| Provider | Services | Notes |
|---|---|---|
| AWS | ALB (HTTP), NLB (TCP/UDP), GWLB (security appliances) | Most granular options |
| Azure | Application Gateway (L7), Load Balancer (L4), Front Door (global CDN+LB) | Front Door is powerful for global apps |
| GCP | Cloud Load Balancing | Truly global anycast — single IP routes to nearest healthy backend worldwide |
Private Connectivity
For connecting on-premises infrastructure to cloud:
- AWS Direct Connect — dedicated 1–100 Gbps connections
- Azure ExpressRoute — same model, partners worldwide
- GCP Cloud Interconnect — dedicated or partner interconnect
DNS and CDN
- AWS Route 53 — DNS with health checks, weighted routing, geolocation routing
- Azure DNS + Front Door — DNS plus global HTTP acceleration
- GCP Cloud DNS + Cloud CDN — integrated with GCP load balancing
Security Groups and Firewalls
All providers implement stateful firewalls at the instance/VM level:
- AWS: Security Groups (instance level) + Network ACLs (subnet level)
- Azure: Network Security Groups (subnet or NIC level)
- GCP: Firewall rules (VPC level, applied via network tags)