Ravindra BagaleCourses & study guides मराठी Track your progress

Chapter 15: Amazon VPC — Subnets, Route Tables, NACL, NAT Gateway and Bastion Host

15.8 Security group vs NACL

The interview favourite! The wing's guard (NACL) and the flat's lock (security group) – you need both. The guard looks after the whole wing and reads his rules in order – allow as well as deny. The lock is only for that one flat and knows only an allow list. Come on, let's see the difference in a table.

Both are firewalls, but they work at different places and in different ways:

Security group Network ACL
Level Instance (its network interface) Subnet
State Stateful: the reply to allowed traffic is allowed automatically Stateless: the reply needs its own rule (ephemeral ports)
Rule types Allow only Allow and deny
Evaluation All rules are evaluated together; if any rule allows, traffic passes Rules in number order; the first match wins
New or custom one No inbound rules, all outbound allowed Custom ACL denies everything; the default ACL allows everything
Applies to Only instances you attach it to Every instance in the associated subnets
Source or destination CIDR, prefix list or another security group CIDR only
Block one IP Not possible (no deny rules) Yes, a deny rule with a lower number
Security group vs network ACL: where each one checks traffic A request first meets the network ACL at the subnet edge, which checks its numbered inbound rules. Then it meets the security group around the instance, which checks its allow rules. The reply goes out through the security group automatically because it is stateful, but the network ACL is stateless and checks the reply again against its outbound rules, so ports 1024-65535 must be allowed outbound. User request :80reply to port 1024–65535 Subnet NACL (subnet) Security group EC2 inbound rule 100 ✓ allow 80 ✓ stateful: auto stateless: outbound rule NACL checks both directions (stateless) · SG remembers the connection (stateful) req reply

A request meets the network ACL at the subnet edge, then the security group at the instance. The reply leaves the security group automatically (stateful), but the network ACL checks it again (stateless), so outbound ports 1024–65535 must be allowed.

How one request passes both

  1. A request from the internet arrives through the internet gateway and the route table.
  2. The subnet's network ACL inbound rules are checked in number order.
  3. The instance's security group inbound rules are checked.
  4. The web server answers.
  5. The security group lets the reply out automatically (stateful).
  6. The network ACL outbound rules must allow the reply to the ephemeral port (stateless).

Which one should I use?

Use security groups as your main, precise control, and chain them by referring to other groups, like app-sg allowing port 9000 only from web-sg. Use a network ACL as a coarse extra guard for a whole subnet: blocking an attacker's IP range, or making sure a database subnet never accepts traffic from the public subnet on port 3306. Most beginners keep the default network ACL and do everything with security groups, which is fine until you need a deny.

Ravindra Bagale's Tip

Many students keep searching for a "Deny" option in the security group – it simply isn't there! A security group only allows. To block a particular IP, use a NACL. And one line for interviews: SG = instance level, stateful, allow only; NACL = subnet level, stateless, allow + deny, rule number order. Got it?

Practice task

Chala, without looking at the table, write five differences between a security group and a network ACL. Then give one situation where only a network ACL can solve the problem.

Got it? The NACL is the wing's guard – rules in order, allow and deny, and a separate rule for replies. The security group is the flat's lock – allow only, and replies go out automatically. Now let's move on and see how to reach private servers.