AWS Network ACLs
A network ACL (NACL) is an optional layer of security for a VPC. It filters the traffic that enters and leaves a subnet, while security groups filter it at the resource level.
Key concepts #
- Stateless: the response traffic is not allowed automatically. Return traffic, usually on ephemeral ports (1024-65535), needs its own rule.
- Allow and deny rules: unlike security groups, a NACL can explicitly deny, for example to block an abusive IP range.
- Numbered rules: evaluated in ascending order, and the first match applies. The last rule (
*) denies everything that did not match. - Every subnet is associated with exactly one NACL. The default NACL of a VPC allows all traffic; a newly created custom NACL denies all until rules are added.
- Good practice: leave the default NACL, keep the detailed control in security groups and use NACLs for coarse, subnet-wide rules such as explicit denies.
Pricing #
Network ACLs are free.
With Terraform #
The resources are aws_network_acl, aws_network_acl_rule and aws_network_acl_association.
See also: AWS Security Groups, AWS Route Tables, AWS Subnets.