Q: What is the difference between a Security Group and a Network ACL (NACL)?
Architectural comparison between AWS Security Groups (stateful, instance-level firewall) and Network ACLs (stateless, subnet-level packet filter).
#AWS #Networking & VPC #L1 #Cloud #Infrastructure #Terraform State
🎙️ Candidate Opening & Architectural Context
""In our AWS cloud environment, we managed high-traffic microservices where this exact scenario occurred. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
Security Groups and Network Access Control Lists (NACLs) form AWS's defense-in-depth perimeter. Security Groups act as stateful firewalls at the virtual network interface (ENI) level, whereas NACLs act as stateless packet filters at the subnet boundary.
- Security Groups Best Practice: Apply granular, least-privilege security between microservices and databases within your VPC.
- NACLs Best Practice: Apply coarse subnet-level shields (such as dropping known malicious IP/CIDR ranges or blocking specific external protocols).
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Security Groups are stateful ENI firewalls evaluating all rules simultaneously; NACLs are stateless subnet firewalls evaluating ordered allow/deny rules."
⚡ 60-Second Elevator Pitch Talking Points
- Security Group: Instance/ENI level, stateful connection tracking, allow-only rules.
- Network ACL: Subnet boundary level, stateless packet inspection, ordered allow and deny rules.
- Defense-in-Depth Pattern: Pair coarse NACL CIDR blocks at the subnet edge with fine-grained Security Groups per service tier.
Advertisement