Security groups vs network ACLs. Ethnus Codemithra article cover.

Security groups vs network ACLs: a VPC exercise

Codemithra Team

Codemithra Team

A security group and a network ACL both filter traffic inside a VPC, but they work at different layers and follow opposite default rules. A security group is a stateful, instance-level, allow-only firewall. A network ACL is a stateless, subnet-level firewall that allows and denies. On SAA-C03 practice tests, most wrong answers come from applying one feature's behaviour to the other. This article separates the two, then walks through a small VPC exercise that makes the difference visible instead of memorised.

Security groups vs network ACLs. Ethnus Codemithra article cover.

Security groups: the instance-level, stateful allow-list

A security group controls the traffic that is allowed to reach and leave the resources it is associated with, such as an EC2 instance, acting as a virtual firewall at the instance level (AWS security group documentation). You attach one or more security groups to a network interface, and each rule states a source or destination, a port and a protocol.

Security groups support allow rules only. There is no way to write a deny rule inside a security group (AWS infrastructure security comparison). To block a specific address, leave it out of every allow rule, or move that decision to a network ACL. This gap is one reason the two features get paired on exams.

Security groups are stateful. If you send a request from an instance, the response traffic is allowed back in regardless of the inbound rules. The same holds in reverse for inbound requests (AWS security group documentation). You still open the port needed for the initial request, but return traffic does not need its own rule.

AWS creates a default security group for every VPC. Its inbound rule allows traffic only from other resources in the same security group. Its outbound rule allows all traffic (AWS default security group documentation). This self-referencing inbound rule is why instances in the default security group can talk to each other right away. Nothing outside that group can reach them until you add a rule.

Some traffic bypasses security group rules even when a rule would seem to block it. DNS, DHCP, EC2 instance metadata, ECS task metadata, Windows license activation and the Amazon Time Sync Service all pass through regardless of your rules. So does traffic from the reserved default VPC router address (AWS security group documentation). AWS also documents quotas on security groups per VPC, rules per security group and security groups per network interface. The exact numbers are adjustable service quotas, so check the current values before designing around a specific count. There is no additional charge for using security groups (AWS security group documentation).

Network ACLs: the subnet-level, stateless allow and deny list

A network ACL allows or denies specific inbound or outbound traffic at the subnet level (AWS network ACL documentation). Every subnet must be associated with exactly one network ACL, default or custom, at any given time. One custom network ACL can serve several subnets. A custom network ACL adds a second layer of control that applies to every instance in the subnet, whatever security group each instance carries.

Network ACL rules carry a number from 1 to 32,766, and AWS evaluates them in ascending order starting with the lowest number. The first rule that matches the traffic is applied, and evaluation stops there (AWS network ACL documentation). A low-numbered deny rule can therefore block traffic that a later, higher-numbered allow rule would otherwise have permitted. This ordering is a common source of exam-style trick questions.

Network ACLs are stateless. Allowing inbound traffic on a network ACL does not automatically allow the matching response. The outbound direction needs its own explicit rule, unlike the stateful behaviour of a security group (AWS network ACL documentation). Forgetting an outbound rule on a custom network ACL is a frequent cause of one-way connectivity during troubleshooting.

AWS creates a default network ACL for every VPC. It allows all IPv4 and IPv6 traffic in both directions, through explicit allow rules numbered 100 and 101. Every network ACL also carries an unnumbered asterisk rule that denies any traffic no other rule matched. This asterisk rule cannot be deleted (AWS default network ACL documentation).

Network ACLs share the same DNS, DHCP, instance metadata, time-sync and license-activation exclusions as security groups. They also cannot block Route 53 Resolver DNS requests or traffic to the Instance Metadata Service (AWS network ACL documentation). There is no additional charge for using network ACLs (AWS network ACL documentation).

How a packet reaches your instance. 1. Subnet boundary: Traffic meets the network ACL first. Then 2. Network ACL check: Numbered rules run in order. First match wins. Then 3. Security group check: If allowed through, the security group checks its rules. Then 4. Delivery and return: A match delivers the packet. The NACL must allow the reply too.
Traffic must pass the network ACL before it ever reaches a security group, and the return trip needs both gates to agree.

Side-by-side: the official comparison

AWS publishes a direct comparison table for these two features. The table below reproduces it, checked against the official AWS VPC documentation on 8 September 2026 (AWS infrastructure security comparison).

Security group Network ACL
Level of operation Operates at the instance level Operates at the subnet level
Scope Applies only to instances specified when it is associated with a network interface Applies to all instances in the subnet it is associated with
Rule type Supports allow rules only Supports allow and deny rules
Rule evaluation Evaluates all rules before deciding whether to allow traffic Processes rules in number order, starting with the lowest, when deciding whether to allow traffic
Return traffic Stateful: return traffic is automatically allowed, regardless of any rules Stateless: return traffic must be explicitly allowed by rules
Security group vs network ACL. Security group: instance level: Network ACL: subnet level. Security group: only its associated instances: Network ACL: all instances in the subnet. Security group: allow rules only: Network ACL: allow and deny rules. Security group: evaluates all rules before deciding: Network ACL: evaluates in number order, first match wins. Security group: stateful, allowed automatically: Network ACL: stateless, must be allowed explicitly
The same five rows, as a quick-reference card.

AWS recommends security groups as the primary way to control access to resources. Network ACLs act as a stateless, coarser secondary control. They help if an instance is ever launched into a subnet without the security group you intended (AWS infrastructure security guidance).

A hands-on VPC exercise to see the difference

This is a suggested learning exercise you can run in your own AWS account. It is not a claim that a specific Ethnus batch includes this exact lab. Treat it as independent practice that pairs with the SAA-C03 networking domain.

  1. Create one VPC with one public subnet. Launch one EC2 instance in that subnet, with a security group that allows inbound SSH or RDP from your own IP address.
  2. Confirm you can connect. This works because the default network ACL already allows all traffic in both directions, and your security group allows the specific inbound port.
  3. Replace the default network ACL association on the subnet with a new custom network ACL. A custom network ACL denies everything by default until you add rules. Your connection now fails.
  4. Add an inbound allow rule on the custom network ACL for your connection port, but leave the outbound rules untouched. The connection still fails. The network ACL is stateless, so the response traffic needs its own outbound allow rule.
  5. Add the matching outbound allow rule, using an ephemeral port range for the response. Confirm the connection now succeeds. Then remove the inbound allow rule on the security group instead, leaving both network ACL rules in place, and confirm the connection fails again.

Each step isolates one gate. Step 3 shows that a network ACL denies by default once you stop using the AWS-managed default. Step 4 shows statelessness directly: an inbound allow rule alone is not enough. Step 5 shows that even a fully open network ACL cannot substitute for a security group rule, because both gates must independently allow the traffic.

Where this fits an SAA-C03 study plan

Ethnus's AWS Solutions Architect Associate course targets the AWS Certified Solutions Architect - Associate (SAA-C03) credential. It includes a networking module covering VPC and Direct Connect. Running the exercise above alongside that module gives you a reference for exam questions that describe a connectivity problem. You can then work out whether a security group or a network ACL rule is missing.

The course also includes lab and sandbox access with step-by-step walkthroughs and unlimited attempts. Live sessions with trainers let you bring a misconfiguration, like the one in step 4 above, and ask why it behaves that way. Placement preparation in the course covers a resume building workshop, practice interviews and continuous placement opportunities.

Key takeaway

A security group is a stateful, instance-level firewall that supports allow rules only, and automatically permits return traffic. A network ACL is a stateless, subnet-level firewall that supports both allow and deny rules, evaluated in ascending rule-number order. Every direction needs its own explicit rule. Traffic must clear both gates on the way in and out. The network ACL guards the subnet boundary, and the security group guards the instance.

Frequently asked questions

Which one should I configure first, a security group or a network ACL?

Most VPCs work correctly using only the default network ACL, which allows all traffic, plus a security group you configure per instance. Add a custom network ACL only when you need a subnet-wide rule. It should apply no matter which security group an instance has (AWS infrastructure security guidance).

Can a network ACL block traffic that a security group allows?

Yes. Traffic must pass the network ACL before it reaches the instance's security group. A network ACL deny rule stops traffic even if every security group on the instance would have allowed it.

Why did my connection fail after I added an inbound rule to my custom network ACL?

Because network ACLs are stateless, an inbound allow rule does not permit the response. Add a matching outbound rule, typically for the ephemeral port range your client uses, before testing again (AWS network ACL documentation).

Do security groups or network ACLs cost anything to use?

No. AWS documents no additional charge for using either security groups or network ACLs (AWS security group documentation).

Is this comparison specific to the SAA-C03 exam?

The underlying AWS behaviour is not exam-specific. It is how VPC networking works in any account. The comparison shows up often on SAA-C03 practice tests. It tests whether you can tell a stateful, instance-level control apart from a stateless, subnet-level one. SAA-C03 is the code for the current AWS Certified Solutions Architect - Associate exam (AWS certification page).

Practise this exercise inside a working VPC setup, with a trainer on hand when a rule does not behave as expected. Start with Ethnus's AWS Solutions Architect Associate course.

About the Author

Read More

Ethnus User Agreement

I agree to submit my personally identifiable information to Ethnus, who may use it to communicate regarding their events, courses, and other services through various media including phone calls, text messages, email, and social media. I also agree with Ethnus' Privacy Policy and Terms of Service.

I agree with Ethnus sharing my personal data, including email address, with Salesforce family of companies, who may contact me for sales and marketing purposes and as described in Salesforce's Privacy Statement.

Privacy Policy

This Privacy Notice describes how we collect and use your personal information in relation to Ethnus websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, "Ethnus Offerings").

This Privacy Notice does not apply to the "content" processed, stored, or hosted by our customers using Ethnus Offerings in connection with an Ethnus account. This Privacy Notice also does not apply to any products, services, websites, or content that are offered by third parties or have their own privacy notice.

Personal Information We Collect

We collect your personal information in the course of providing Ethnus Offerings to you.

Here are the types of information we gather:

        a) Information You Give Us: We collect any information you provide in relation to Ethnus Offerings. Click here to see examples of information you give us. Example: Name, email, phone, etc.

        b) Automatic Information: We automatically collect certain types of information when you interact with Ethnus Offerings. Example: IP address, location, browser identity, etc.

        c) Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources. Example: marketing analytics, keywords, etc.

How We Use Personal Information

We use your personal information to operate, provide, and improve Ethnus Offerings. Our purposes for using personal information include:

        a) Provide Ethnus Offerings: We may use your personal information to provide and deliver Ethnus Offerings and process transactions related to Ethnus Offerings, including registrations, subscriptions, purchases, and payments.

        b) Measure, Support, and Improve Ethnus Offerings: We use your personal information to measure use of, analyze the performance of, fix errors in, provide support for, improve, and develop Ethnus Offerings.

        c) Recommendations and Personalization: We use your personal information to recommend Ethnus Offerings that might be of interest to you, identify your preferences, and personalize your experience with Ethnus Offerings.

        d) Comply with Legal Obligations: In certain cases, we have a legal obligation to collect, use, or retain your personal information.

        e) Communicate with You: We use your personal information to communicate with you in relation to Ethnus Offerings via different channels (e.g., by phone, email, chat) and to respond to your requests.

        f) Marketing: We use your personal information to market and promote Ethnus Offerings. We might display interest-based ads for Ethnus Offerings.

        g) Purposes for Which We Seek Your Consent: We may also ask for your consent to use your personal information for a specific purpose that we communicate to you.

Cookies

To enable our systems to recognize your browser or device and to provide Ethnus Offerings, we use cookies.

How We Share Personal Information

Information about our customers is an important part of our business and we are not in the business of selling our customers' personal information to others. We share personal information only as described below and with Ethnus Consultancy Services Private Limited, . and its affiliates that are either subject to this Privacy Notice or follow practices at least as protective as those described in this Privacy Notice.

Transactions Involving Third Parties: We make available to you services, software, training, and content provided by third parties for use on or through Ethnus Offerings. You can tell when a third party is involved in your transactions, and we share information related to those transactions with that third party. For example, you can order services, software, and content from sellers using the Authorized Training Partner's marketplace and we provide those sellers information to facilitate your subscription, purchases, or support.

Other than as set out above, you will receive notice when personal information about you might be shared with third parties, and you will have an opportunity to choose not to share the information.

How We Secure Information

        a) We protect the security of your information during transmission to or from websites, applications, products, or services by using encryption protocols and software.

        b) We maintain physical, electronic, and procedural safeguards in connection with the collection, storage, and disclosure of personal information.

Internet Advertising and Third Parties

Ethnus Offerings may include third-party advertising and links to other websites and applications. Third party advertising partners may collect information about you when you interact with their content, advertising, or services. For more information about third-party advertising, including interest-based ads, please read our Interest-Based Ads notice.

Access and Choice

You have choices about the collection and use of your personal information. Many Ethnus Offerings include settings that provide you with options as to how your information is being used. You can choose not to provide certain information, but then you might not be able to take advantage of certain Ethnus Offerings.

        a) Communications: If you do not want to receive promotional messages from us, please unsubscribe or adjust your communication preferences in the emails.

        b) Advertising: If you don't want to see interest-based ads, please adjust your Advertising Preferences.

        c) Browser and Devices: The Help feature on most browsers and devices will tell you how to prevent your browser or device from accepting new cookies, how to have the browser notify you when you receive a new cookie, or how to disable cookies altogether.

Children's Personal Information

We don't provide Ethnus Offerings for purchase by children. If you're under 18, you may use Ethnus Offerings only with the involvement of a parent or guardian.

Retention of Personal Information

We keep your personal information to enable your continued use of Ethnus Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you. How long we retain specific personal information varies depending on the purpose for its use, and we may delete your personal information in accordance with applicable law.

Contacts, Notices, and Revisions

If you have any concern about privacy at Ethnus, you may also contact us at the addresses below:

Ethnus Consultancy Services Pvt Ltd,

SST Chambers, No.151/17/1 Second Floor, 36th Cross Rd, 5th Block, Jayanagar, Bengaluru, Karnataka 560041

Or, email us at [email protected]

Or call us at: +91 - 8929 334 324

You will find the updated contact information on our website: www.ethnus.com/contact/

If you interact with Ethnus Offerings on behalf of or through your organization, then your personal information may also be subject to your organization's privacy practices, and you should direct privacy inquiries to your organization.

Our business changes constantly, and our Privacy Notice may also change. You should check our website frequently to see recent changes. You can see the date on which the latest version of this Privacy Notice was posted. Unless stated otherwise, our current Privacy Notice applies to all personal information we have about you and your account. We stand behind the promises we make, however, and will never materially change our policies and practices to make them less protective of personal information collected in the past without informing affected customers and giving them a choice.

Terms & Conditions

This Privacy and Security Policy is provided for the benefit of customers and clients of Ethnus Consultancy Services Private Limited. ("Ethnus") as well as other consumers and parties who use Ethnus and/or its website(s), particularly codemithra.com ("Website", "www.codemithra.com", "Codemithra" or "Ethnus Codemithra"), and/or applications ("Apps") (collectively, "Ethnus Services" or "Ethnus Platform").

Since Ethnus serves several different audiences, customers find it helpful to read the Terms of Use that apply specifically to them based upon the purpose for which they use Ethnus. For this reason, we link to three separate agreements below for employer customers, job seeker customers, and staffing customers, respectively.

For your convenience, we define each of these audiences that Ethnus serves as follows:

"Employer Customer" means an entity using Ethnus Services that is seeking to hire an individual as an employee and/or independent contractor to be employed by it directly.

"Job Seeker Customer" means an individual using Ethnus Services who is seeking to be employed as an employee or independent contractor by an employer.

"Staffing Customer" means a staffing company using Ethnus Services that provides staffing services to their own Staffing Clients.

So long as your use of the Ethnus website and services remains within the scope of the particular audience or customer for which you began using Ethnus (e.g. a job seeker does not use Ethnus as an employer, or an employer does not use Ethnus as a job seeker), the complete Terms of Use applicable to your use of the Ethnus website and services is contained within the applicable Terms of Use linked below.

Employer Terms of Use

The following Terms of Use apply to any Ethnus Employer Customer seeking to hire employees or independent contractors for its own business. If you seek to find employees or independent contractors for the benefit of your clients (and not yourself), you need to review the Terms of Use specifically for our Ethnus Staffing Customers accessible at www.Codemithra.com/terms/staffing.

Ethnus, Inc. ("Ethnus") provides online services through which employers and staffing companies seeking employees and independent contractors can efficiently and effectively review and interview candidates. Ethnus provides these services and its suite of features and products through its Apps and Website (collectively, "Ethnus Services") subject to these terms of use ("Terms of Use") and the agreements incorporated herein.

Your privacy is very important to us. We designed our accompanying Privacy and Security Policy to provide important disclosures about how your information will be used by Ethnus in providing you Ethnus Services. These Terms of Use expressly incorporate our Privacy and Security Policy.

Please read these Terms of Use and our Privacy and Security Policy carefully before using any of the diverse Ethnus Services. By visiting the Website, installing any of the Apps, and/or using any of the Ethnus Services, you shall have affirmed your agreement to these Terms of Use.

1. Definitions

2. Modifications - Will Ethnus ever modify these Terms of Use?

3. Ethnus Services - What are the Ethnus Services?

4. Video Content and Services - How and when do you record videos?

5. Pricing, Payments, and Billing - How and when will I be billed for Ethnus Services?

6. Objectionable Content - What if I find content to be objectionable?

7. Customer Conduct

8. Intellectual Property

9. DMCA Policy

10. Reserved for Future Use

11. Resale of Services

12. Indemnification

13. Disclaimer of Warranties

14. Third Party Links and Products

15. Limitations of Liability

16. Exclusions and Limitations

17. General Terms

1. Definitions

"Consumer" means any individual or entity that uses any of the Ethnus Services. Where applicable, the term "Consumer" shall encompass all Ethnus Customers.

"Content" means all material, whether publicly posted or privately transmitted, available on or through any of the Ethnus Services.

"Customer" means, for purposes of this Terms of Use, You, a Job Seeker Customer.

"Customer Content" means any Content uploaded to and/or created through the Ethnus Services by a Ethnus Customer.

"Employer Customer" means an entity using Ethnus Services that is seeking to hire an individual as an employee and/or independent contractor to be employed by it directly.

"GDPR" means the European Union's General Data Protection Regulation.

"Job Seeker Customer" means an individual using Ethnus Services who is seeking to be employed as an employee or independent contractor by an employer.

"Profile Video" means a promotional video created by a Job Seeker Customer to promote themselves as a candidate employee and/or independent contractor. It is not an interview. The Job Seeker Customer completes this independently and on their own.

"Software" means any necessary software used in connection with the Ethnus Services.

"Ethnus Account" means an account associated with a Ethnus Customer who uses or has used Ethnus Services.

"Ethnus Content" means any Content excluding Customer Content and Video Content in which Ethnus does not participate.

"Ethnus Customer" means any person who uses or has used Ethnus Services including, but not limited to, Employer Customers, Job Seeker Customers, and Staffing Customers.

"Ethnus Services" means the suite of features, products and services offered through Ethnus, its Apps, its App Services, the Website, and the Website Services.

"Ethnus Trademarks" means any trademarks, tradenames, logos, and other commercial designs of Ethnus or licensed to Ethnus, whether or not formal registration exists including, but not limited to, "Ethnus."

"Staffing Clients" means third-party employer clients of Staffing Customers.

"Staffing Customer" means a staffing company using Ethnus Services that provides staffing services to their own Staffing Clients.

"Strategic Partners" means those trusted partners that Ethnus employs, engages, or retains to perform functions and/or provide services on its behalf.

"Sub Accounts" means subsidiary accounts created for or by an Employer Customer or Staffing Customer ("such as a consultant group or employer") under its primary account.

"Username" means the valid email address provided by each Ethnus Customer to be used as their username or login identification.

"Video Content" means any video content created by or associated with any Ethnus Customer accessible on and through Ethnus Services including, but not limited to, Profile Videos, Video Questions, Video Interviews, and Welcome Videos.

"Video Interview" means an interview completed through Ethnus Services using a video or "web" camera that an Employer Customer or Staffing Customer requests a Job Seeker Customer complete. A Video Interview may involve a Job Seeker Customer alone or with other participants from an Employer Customer or Staffing Customer. A Video Interview may be pre-recorded by a Job Seeker in response to questions or occur live at which time it would be recorded.

"Video Question" means a question recorded in video and audio that can be sent to potential employee and independent contractor candidates by an Employer Customer or Staffing Customer.

"Website" means all of the content, information and services (in any format whatsoever) accessible through the World Wide Web at the domain name Codemithra.com.

"Website Services" means the services provided by Ethnus through the website at the domain name Codemithra.com, hire.li, and any of our other websites that may be used from time to time