NACL & SG
NACLstands forNetwork Access Control ListSGstands forSecurity GroupSGassociated withInstanceNACLassociated withSubnetSGis stateful- If 
Inbound RuleallowedIP/IP Ranges,Outbound Ruleis automatically allowed - If 
Outbound RuleallowedIP/IP Ranges,Inbound Ruleis automatically a llowed NACLstateless i.e. bothInbound RuleandOutbound Ruleis separately evaluatedNACLis evaluated- Lowest number has high preference
 - If no rules found, it goes to 
*numbered rule Default NACLallow every traffic for bothInboundandOutboundCustom NACLblock every traffic for bothInboundandOutbound- Each 
Subnetgoes underDefault NACLif not explicitly associated Ephemeral PORTshould be open for highly restrictedNACL- To block an 
IP AddressuseNACL