Compare boundaries and rule evaluation

A security group uses allow rules; there is no numbered first-match deny rule. A NACL evaluates entries in ascending rule order until a matching entry decides the result. The default unmatched-traffic rule denies traffic.

Both can apply to the same connection. Passing one does not guarantee the other passes. An earlier matching NACL deny can make a later allow irrelevant.

The reply changes the answer

The example client opens SSH from port 49152 to server port 22. The reply targets the client port. A stateful security group permits the response to an allowed request; a stateless NACL needs an applicable return rule.

The client port is an explicit model assumption. Select an appropriate ephemeral range for real clients and intermediaries. A rule allowing only port 22 in both directions does not necessarily allow the full connection.

Choose the control for the boundary

Use security groups for resource traffic relationships. NACLs can add subnet-level filtering, including explicit denies. Adding another layer without a reason adds configuration work and more ways to break a path.

For an application tier talking to a database, identify which resources may initiate traffic. For a subnet-wide denied address range, identify the broader boundary and affected workloads. The desired access relationship guides the choice.

Practice beyond the table

Predict the request and response outcome, then toggle only one rule. Keep the SG allow while denying the NACL reply. Repair it and explain why the connection now completes.

A comparison becomes useful when you can reason through a changed case. The model intentionally simplifies the network; use its trace as an explanation of supported controls rather than a substitute for real account verification.

SimAWS · ShahriarLabs

Predict it. Test it. Change one thing.

Local educational model. No account or cloud charges. Nothing is deployed to AWS.

Path and controls
ClientInternet route → NACL → Security groupWorkerReply is checked separately. Client/return address: 203.0.113.10; modeled port: 49152.

sim.shahriarlabs.com · Free to explore

Sources and scope

Reviewed against these official references. The model’s supported scope appears alongside its controls.

How we review explanations