AWS Network ACLs

· 1 min read · AWS

A network ACL (NACL) is an optional layer of security for a VPC. It filters the traffic that enters and leaves a subnet, while security groups filter it at the resource level.

Key concepts #

  • Stateless: the response traffic is not allowed automatically. Return traffic, usually on ephemeral ports (1024-65535), needs its own rule.
  • Allow and deny rules: unlike security groups, a NACL can explicitly deny, for example to block an abusive IP range.
  • Numbered rules: evaluated in ascending order, and the first match applies. The last rule (*) denies everything that did not match.
  • Every subnet is associated with exactly one NACL. The default NACL of a VPC allows all traffic; a newly created custom NACL denies all until rules are added.
  • Good practice: leave the default NACL, keep the detailed control in security groups and use NACLs for coarse, subnet-wide rules such as explicit denies.

Pricing #

Network ACLs are free.

With Terraform #

The resources are aws_network_acl, aws_network_acl_rule and aws_network_acl_association.

See also: AWS Security Groups, AWS Route Tables, AWS Subnets.

More tutorials that use Network ACLs

#AWS #Security #AWS VPC