NACL & SG
NACL
stands forNetwork Access Control List
SG
stands forSecurity Group
SG
associated withInstance
NACL
associated withSubnet
SG
is stateful- If
Inbound Rule
allowedIP
/IP Ranges
,Outbound Rule
is automatically allowed - If
Outbound Rule
allowedIP
/IP Ranges
,Inbound Rule
is automatically a llowed NACL
stateless i.e. bothInbound Rule
andOutbound Rule
is separately evaluatedNACL
is evaluated- Lowest number has high preference
- If no rules found, it goes to
*
numbered rule Default NACL
allow every traffic for bothInbound
andOutbound
Custom NACL
block every traffic for bothInbound
andOutbound
- Each
Subnet
goes underDefault NACL
if not explicitly associated Ephemeral PORT
should be open for highly restrictedNACL
- To block an
IP Address
useNACL