4 ms·
Yes and no. NACLs are, indeed, associated with a subnet so more of a networking construct. It's somewhat a firewall, but it's also stateless which is different
by rellimevad 9y ago
Yes and no. NACLs are, indeed, associated with a subnet so more of a networking construct. It's somewhat a firewall, but it's also stateless which is different than many (non-network engineer) people's mental model of a firewall.
Security Groups have some key differences from a host-based firewall. A packet destined for an EC2 instance will not make it to the instance IP stack and be evaluated there, it will be evaluated before it gets there.
It depends on your audience. A web dev that's relatively new to syadmin tasks... sure, it's like a host based firewall. For a syadmin or network admin, that explanation might be more confusing than helpful.
- felipelemos 9y agoBut SG are related to a network interface, not with your network (which would the VPC).