# AWS Network ACLs

> A network access control list (NACL) is a stateless firewall that allows or denies traffic at the subnet level of an AWS VPC, using numbered rules.

- Source: https://www.itwonderlab.com/aws-network-acl/
- Published: 2026-10-05
- Updated: 2026-10-05
- Author: Javier Ruiz Jiménez (https://www.javierruizjimenez.com/)
- Site: IT Wonder Lab (https://www.itwonderlab.com/)

---

A **network ACL** (NACL) is an optional layer of security for a [VPC](https://www.itwonderlab.com/aws-vpc/). It filters the traffic that enters and leaves a **[subnet](https://www.itwonderlab.com/aws-subnets/)**, while [security groups](https://www.itwonderlab.com/aws-security-groups/) filter it at the resource level.

### Key concepts

- **Stateless**: the response traffic is not allowed automatically. Return traffic, usually on ephemeral ports (1024-65535), needs its own rule.
- **Allow and deny rules**: unlike security groups, a NACL can explicitly deny, for example to block an abusive IP range.
- **Numbered rules**: evaluated in ascending order, and the first match applies. The last rule (`*`) denies everything that did not match.
- Every subnet is associated with exactly one NACL. The **default NACL** of a VPC allows all traffic; a newly created custom NACL denies all until rules are added.
- Good practice: leave the default NACL, keep the detailed control in security groups and use NACLs for coarse, subnet-wide rules such as explicit denies.

### Pricing

Network ACLs are free.

### With Terraform

The resources are `aws_network_acl`, `aws_network_acl_rule` and `aws_network_acl_association`.

See also: [AWS Security Groups](https://www.itwonderlab.com/aws-security-groups/), [AWS Route Tables](https://www.itwonderlab.com/aws-route-tables/), [AWS Subnets](https://www.itwonderlab.com/aws-subnets/).
