Q: Your database is in a private subnet with a Network ACL (NACL) that explicitly allows port 3306 inbound from the application subnet (10.0.1.0/24). However, the DB connections are timing out. The Security Group allows 3306. What is wrong?
The problem is that Network ACLs are stateless.
#Networking #Networking #L3 #VPC #DNS #Security
🎙️ Candidate Opening & Architectural Context
""In our multi-VPC setup, services in private subnets ran into this exact routing obstacle. The interviewer is testing: Ephemeral ports, stateful vs. stateless firewalls.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
The problem is that Network ACLs are stateless. Security Groups are stateful (if you allow an inbound request, the outbound response is automatically allowed). Because NACLs are stateless, returning traffic is blocked unless explicitly permitted. When the application server hits the DB on port 3306, the database must reply to the application server's random Ephemeral Port (usually ranging from 1024-65535, typical Linux is 32768-60999). You must add an outbound rule on the database subnet's NACL to allow TCP traffic across the ephemeral port range back to the application subnet 10.0.1.0/24.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: The problem is that Network ACLs are stateless.."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: The problem is that Network ACLs are stateless.
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement