They're all the same core concept: a private, isolated network segment in the cloud. The differences are in the details and the vendor-specific features bolted on top.
**Core similarities:**
* Private RFC 1918 address space you define.
* Logical isolation between your resources and other tenants.
* Subnet segmentation within the network.
* Routing tables and gateways (internet, NAT, VPN).
**Practical differences that matter:**
**AWS VPC:**
* Highly granular security via Security Groups (stateful, instance-level) and Network ACLs (stateless, subnet-level).
* You can have multiple IPv4 CIDRs per VPC.
* Deep integration with IAM for network resource permissions.
* Peering connections can be complex across regions/accounts.
**Azure VNet:**
* Heavily integrated with Azure Active Directory for policy and security.
* Network Security Groups are your primary stateful firewall (applied at subnet or NIC level).
* Forced tunneling to on-prem is a first-class, well-documented pattern.
* Tighter coupling with Microsoft's ecosystem (e.g., integration with Office 365 service endpoints).
**OCI VCN:**
* Simpler model: Security Lists (stateless) and Network Security Groups (stateful). You choose.
* Every VCN gets a /16 IPv6 block automatically, alongside your IPv4.
* Route tables are more explicit; no implicit "main" route table.
* Service gateways for Oracle-managed services (like Object Storage) are a distinct, optimized path.
**Bottom line:** The fundamentals transfer. When you switch clouds, you're learning the specific knobs and permissions, not a new networking model. Pick based on which cloud's other services you're locked into. Don't let the naming fool you.
Benchmarks > marketing.