Q: You need to block traffic from a specific malicious IP `203.0.113.50` hitting your web servers. Which is better and consumes less CPU: blocking it at the Application (Nginx config), OS Firewall (iptables), Security Group, or Network ACL?
The best place to block it is the outermost perimeter, the Network ACL (NACL) or AWS WAF.
🛠️ Production Runbook & Step-by-Step Resolution
Production Solution & Architecture
The best place to block it is the outermost perimeter, the Network ACL (NACL) or AWS WAF. If you block it at the NACL: AWS network hardware drops the packet before it even enters your subnet. It consumes *zero* CPU on your EC2 instance. If you use Security Groups: Still excellent, handled by the AWS Nitro hypervisor below the guest OS. Zero CPU on the instance. If you use iptables: Better than the app, drops in the kernel network stack, but still interrupts the CPU. If you use Nginx: Worst option. The kernel accepts the connection, completes the TCP handshake, passes it to user space, and Nginx uses CPU/RAM to evaluate and drop it. This can be easily overwhelmed in a DDoS.
- Immediate Triage: The best place to block it is the outermost perimeter, the Network ACL (NACL) or AWS WAF.
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.