Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host
15.8 Security group vs NACL
The interview favourite! The wing's guard (NACL) and the flat's lock (security group) – you need both. The guard looks after the whole wing and reads his rules in order – allow as well as deny. The lock is only for that one flat and knows only an allow list. Come on, let's see the difference in a table.
Interview चा favourite प्रश्न! Wing चा guard (NACL) आणि flat चं कुलूप (security group) – दोन्ही लागतात. Guard पूर्ण wing सांभाळतो आणि क्रमाने rules वाचतो – allow पण आणि deny पण. कुलूप फक्त त्या एकाच flat साठी आहे आणि फक्त allow list ओळखतं. चला, table मध्ये फरक बघू.
Interview का favourite सवाल! Wing का guard (NACL) और flat का ताला (security group) – दोनों चाहिए. Guard पूरी wing संभालता है और क्रम से rules पढ़ता है – allow भी और deny भी. ताला सिर्फ उस एक flat के लिए है और सिर्फ allow list पहचानता है. चलो, table में फर्क देखते हैं.
Both are firewalls, but they work at different places and in different ways:
| Security group | Network ACL | |
|---|---|---|
| Level | Instance (its network interface) | Subnet |
| State | Stateful: the reply to allowed traffic is allowed automatically | Stateless: the reply needs its own rule (ephemeral ports) |
| Rule types | Allow only | Allow and deny |
| Evaluation | All rules are evaluated together; if any rule allows, traffic passes | Rules in number order; the first match wins |
| New or custom one | No inbound rules, all outbound allowed | Custom ACL denies everything; the default ACL allows everything |
| Applies to | Only instances you attach it to | Every instance in the associated subnets |
| Source or destination | CIDR, prefix list or another security group | CIDR only |
| Block one IP | Not possible (no deny rules) | Yes, a deny rule with a lower number |
A request meets the network ACL at the subnet edge, then the security group at the instance. The reply leaves the security group automatically (stateful), but the network ACL checks it again (stateless), so outbound ports 1024–65535 must be allowed.
Request आधी subnet च्या edge वर network ACL ला भेटते, मग instance वर security group ला. Reply security group मधून आपोआप बाहेर जातो (stateful), पण network ACL तो पुन्हा check करतो (stateless), म्हणून outbound ports 1024–65535 allow करावे लागतात.
Request पहले subnet के edge पर network ACL से मिलती है, फिर instance पर security group से. Reply security group से अपने आप बाहर जाता है (stateful), पर network ACL उसे फिर से check करता है (stateless), इसलिए outbound ports 1024–65535 allow करने पड़ते हैं.
How one request passes both
- A request from the internet arrives through the internet gateway and the route table.
- The subnet's network ACL inbound rules are checked in number order.
- The instance's security group inbound rules are checked.
- The web server answers.
- The security group lets the reply out automatically (stateful).
- The network ACL outbound rules must allow the reply to the ephemeral port (stateless).
Which one should I use?
Use security groups as your main, precise control, and chain them by referring to other groups, like app-sg allowing port 9000 only from web-sg. Use a network ACL as a coarse extra guard for a whole subnet: blocking an attacker's IP range, or making sure a database subnet never accepts traffic from the public subnet on port 3306. Most beginners keep the default network ACL and do everything with security groups, which is fine until you need a deny.
Ravindra Bagale's Tip
Many students keep searching for a "Deny" option in the security group – it simply isn't there! A security group only allows. To block a particular IP, use a NACL. And one line for interviews: SG = instance level, stateful, allow only; NACL = subnet level, stateless, allow + deny, rule number order. Got it?
Ravindra Bagale's Tip – मराठी
बरेच students security group मध्ये "Deny" option शोधत बसतात – तो नाहीच आहे! Security group फक्त allow करतो. एखादा IP block करायचा असेल तर NACL वापरा. आणि interview साठी एक line: SG = instance level, stateful, allow only; NACL = subnet level, stateless, allow + deny, rule number order. समजलं का?
Ravindra Bagale's Tip – हिंदी
बहुत से students security group में "Deny" option ढूँढते रहते हैं – वह है ही नहीं! Security group सिर्फ allow करता है. किसी IP को block करना हो तो NACL इस्तेमाल करो. और interview के लिए एक line: SG = instance level, stateful, allow only; NACL = subnet level, stateless, allow + deny, rule number order. समझ आया?
Practice task
Chala, without looking at the table, write five differences between a security group and a network ACL. Then give one situation where only a network ACL can solve the problem.
Step-by-step guide
Got it? The NACL is the wing's guard – rules in order, allow and deny, and a separate rule for replies. The security group is the flat's lock – allow only, and replies go out automatically. Now let's move on and see how to reach private servers.
समजलं का? NACL म्हणजे wing चा guard – क्रमाने rules, allow आणि deny, आणि reply साठी वेगळा rule. Security group म्हणजे flat चं कुलूप – फक्त allow, आणि reply आपोआप. आता पुढे जाऊया private servers पर्यंत कसं पोहोचायचं ते बघायला.
समझ आया? NACL यानी wing का guard – क्रम से rules, allow और deny, और reply के लिए अलग rule. Security group यानी flat का ताला – सिर्फ allow, और reply अपने आप. अब आगे चलते हैं यह देखने कि private servers तक कैसे पहुँचें.