SimAWSby ShahriarLabs
Search

The network your resources live in · Chapter 2 of 3

How Security Groups and NACLs defend networks

Securing a network requires firewalls at both the instance and subnet levels, but understanding statefulness and rule orders prevents mysterious connection timeouts.

FoundationsBuilds the idea from nothing. No prior AWS assumed.

Stateful Security Groups and stateless NACLs

What are the core differences between Security Groups and Network ACLs?

Subnet BoundaryClient203.0.113.5NACLStatelessSecurity GroupStatefulWeb ServerPort 80Security Groups are stateful and auto-allow response traffic, whereas NACLs are stateless and require explicit outbound rules for return packets.

Inbound HTTP request on port 80 evaluates against NACL rule 100 ALLOW.

1/5
  1. 01

    Security Groups guard the instance

    A Security Group acts as a firewall at the network interface level. It is stateful: if you allow inbound traffic on port 80, the return outbound traffic is automatically allowed. Security Groups contain allow rules only; you cannot write a rule that explicitly blocks a specific IP address.

  2. 02

    Network ACLs guard the subnet

    A Network Access Control List acts as a firewall at the subnet boundary. It is stateless: it evaluates inbound traffic and outbound traffic independently. A NACL evaluates rules in numeric order and supports explicit deny rules, which makes them ideal for blocking traffic from malicious IPs.

  3. 03

    The necessity of ephemeral ports

    Because NACLs are stateless, allowing inbound traffic on port 443 is not enough for clients to establish a connection. You must also write an outbound rule that permits traffic to return on the ephemeral port range that the client browser opened to receive the data.

Check yourself

Why does a Security Group not require a corresponding outbound rule to return traffic for an allowed inbound connection?

Under the hoodThe same thing from underneath: limits, failure modes, numbers.

Stateless evaluation and ephemeral port mappings

What are the performance limits and evaluation mechanics of Security Groups and NACLs?

Subnet BoundaryClient203.0.113.5NACLStatelessSecurity GroupStatefulWeb ServerPort 80Security Groups are stateful and auto-allow response traffic, whereas NACLs are stateless and require explicit outbound rules for return packets.

Inbound HTTP request on port 80 evaluates against NACL rule 100 ALLOW.

1/5
  1. 01

    The stateless return path

    When an external client initiates a TCP connection, the client OS allocates a port from its ephemeral port range. If a stateless NACL blocks these ports on the outbound path, the TCP handshake cannot complete, resulting in connection timeouts.

  2. 02

    NACL evaluation mechanics

    NACL rules are processed in ascending numerical order. The first rule that matches the traffic type and IP range determines the outcome. If rule 100 denies an IP address, and rule 200 allows that same IP, the traffic is denied because rule 100 was evaluated first.

  3. 03

    VPC firewall limits

    AWS enforces quotas on the number of Security Groups and NACL rules to ensure low network latency. Exceeding these quotas can impact network architecture, forcing designers to consolidate rules or split workloads across different subnets.

The numbers

Security Group rule limit
60 rules per groupLimits are placed on both inbound and outbound paths.
Security Groups per interface
5 groups by defaultApplies to each Elastic Network Interface.
NACL rule limit
20 rules by defaultCan be increased up to 40, but may degrade network performance.
Ephemeral port range (Linux)
32768 to 61000Many client operating systems use this range for outbound connections.
IANA ephemeral port range
49152 to 65535AWS Services and Windows clients use this range.

Check yourself

A NACL has Rule 100 allowing port 80 from all IPs, and Rule 110 denying port 80 from IP 192.168.1.50. What happens when IP 192.168.1.50 connects to port 80?

Official references & further reading

These lessons simplify selected behaviors for learning. Verify current service limits, Region support and production requirements with the official references. Experiments describe their own assumptions.

Report an error or suggest a clearer explanation →