Network controls
Security groups and network ACLs, ephemeral ports, AWS Network Firewall with Suricata rules and domain lists, Route 53 Resolver DNS Firewall, Gateway Load Balancer with third-party IDS/IPS, and egress filtering.
Exam tasks: 3.3 (network controls that permit or prevent traffic: security groups, network ACLs, Network Firewall; north/south and east/west protection)
The decision: does the control need to understand connections, names or payloads, and must it apply to one workload, one subnet, or every packet leaving the VPC?
Picking the control
Security groups vs network ACLs
| Security group | Network ACL | |
|---|---|---|
| Attached to | Network interface (instance, ALB, RDS, Lambda in VPC, endpoint) | Subnet |
| State | Stateful: return traffic is allowed automatically | Stateless: you must allow return traffic explicitly |
| Rules | Allow only | Allow and deny |
| Evaluation | All rules together, most permissive wins | Numbered, lowest first, first match wins |
| Sources | CIDR, prefix list, another security group | CIDR only |
| Default (new custom one) | Deny all in, allow all out | Deny all in and out. The VPC's default NACL allows everything |
| Best for | Least-privilege per tier | Coarse subnet guardrails, blocking a specific CIDR fast |
- Reference security groups, not CIDRs, between tiers: the app tier allows 8443 only from the ALB's security group. It keeps working as instances scale.
- Removing a security group rule doesn't cut tracked connections that are already open. They continue until they go idle (up to days for an established TCP session). Only untracked flows stop at once. To cut an attacker's live session immediately, add a NACL deny, because NACLs don't track connections.
- Default quotas: 60 inbound and 60 outbound rules per security group, 5 security groups per interface (adjustable, but the product of the two is capped). NACLs have 20 rules per direction by default, adjustable to 40.
- Security Group VPC Associations let you use one security group in several VPCs of the same account and Region, and shared security groups follow shared subnets across accounts.
Exam signal
"Block this one attacking IP range now, including sessions already open" is a NACL deny (or a WAF IP set at the edge). Security groups can't deny. "Only the load balancer may reach the instances" is a security group that references the load balancer's security group.
Ephemeral ports
A client picks a random high source port. Because NACLs are stateless, the reply to that port must be allowed in the NACL facing the client.
| Client | Ephemeral range it uses |
|---|---|
| Most Linux kernels | 32768–60999 |
| Windows Server 2008 and later | 49152–65535 |
| NAT gateway, ELB, Lambda | 1024–65535 |
- For a web subnet, allow inbound 443 from
0.0.0.0/0and outbound 1024–65535 to0.0.0.0/0, or HTTPS replies never leave the subnet. - Instances in that subnet that call out (updates, APIs) also need inbound 1024–65535 for the replies.
- In practice, allow 1024–65535 and add lower-numbered deny rules for specific ports you want blocked.
The NACL looks right but traffic fails
A NACL with inbound 443 allowed and outbound 443 allowed still breaks HTTPS: replies go to the client's ephemeral port, not to 443. When a question shows connections timing out after a NACL change, check the return-path ephemeral range first. Reachability Analyzer names the blocking rule.
AWS Network Firewall
A managed, stateful firewall and IPS that you place in the traffic path. It scales automatically and runs Suricata-compatible rules.
- Deployment: firewall endpoints in dedicated subnets, one per AZ, with route tables sending traffic through them. Or attach the firewall natively to a transit gateway, where AWS manages the inspection VPC and you route with transit gateway route tables.
- Stateless engine first: looks at single packets in priority order (like a NACL). Its actions are pass, drop, or forward to the stateful engine. Forward by default unless you have a reason not to.
- Stateful engine second: understands flows and direction. Rule group types:
- Domain list: allow or deny by HTTP
Hostheader and TLS SNI, including wildcards like.example.org. - Standard stateful (5-tuple) rules, simpler than Suricata.
- Suricata-compatible IPS rules: match on protocol fields, content and signatures, with
pass,drop,rejectandalert. - AWS managed threat signatures and domain lists (malware, botnet command and control, crypto mining).
- Domain list: allow or deny by HTTP
- Rule order: strict order evaluates rule groups in the priority you set and lets you define default actions like "drop established" for anything not explicitly passed. The older action order evaluates all pass rules, then drop, then alert. Use strict order for allow lists.
- TLS inspection decrypts, inspects and re-encrypts traffic with certificates from ACM, for inbound and outbound flows. Without it, the firewall only sees SNI and certificate metadata, not the payload.
- Logs: alert and flow logs (and TLS logs) to S3, CloudWatch Logs or Data Firehose.
A domain allow list without a default drop
Adding a domain list that allows .amazonaws.com and .github.com doesn't block anything else in action order
mode, because the stateful default is to pass. Use strict order with a default action of drop established (or a
deny-all rule last), or the allow list is decorative.
Route 53 Resolver DNS Firewall
- Filters DNS queries that instances send to the VPC's Route 53 Resolver (now called Route 53 VPC Resolver). It stops DNS exfiltration and lookups of known-bad domains.
- Rule groups associated with VPCs contain rules that reference domain lists (your own or AWS managed: malware, botnet C2, aggregate threats). Actions: ALLOW, ALERT, or BLOCK with NODATA, NXDOMAIN or an OVERRIDE answer.
- DNS Firewall Advanced rules detect DNS tunneling and domain generation algorithm (DGA) patterns rather than fixed names.
- Choose fail open (keep resolving if DNS Firewall is impaired) or fail closed per VPC.
- It can't see queries sent straight to an outside resolver like 8.8.8.8. Block outbound 53 and 853 in security groups, NACLs or Network Firewall so everything goes through the VPC Resolver.
- Firewall Manager can associate DNS Firewall rule groups with every VPC in the organization.
Exam signal
"Allow outbound connections only to approved domains": Network Firewall domain list (or a proxy) filters the connection. "Stop malware resolving command-and-control domains" or "detect DNS tunneling": DNS Firewall. Many answers use both, because each sees a different path.
Gateway Load Balancer and third-party IDS/IPS
- GWLB sends traffic transparently to a fleet of virtual appliances (Palo Alto, Fortinet, Check Point, open-source Suricata) using GENEVE on port 6081, keeping the original packet intact.
- Consumers reach it through GWLB endpoints in their route tables, so the appliance fleet can live in a central security account.
- Keep flows symmetric: enable appliance mode on the transit gateway VPC attachment for the inspection VPC.
- Pick GWLB when the question names a vendor, requires a specific IPS signature feed, or reuses existing firewall licences. Otherwise Network Firewall is the lower-effort managed answer.
- Traffic Mirroring copies ENI traffic to an out-of-band IDS for detection only. It can't block.
Egress filtering patterns
| Pattern | What it gives you | Effort |
|---|---|---|
| No route to the internet (isolated subnets + VPC endpoints) | Strongest: nothing leaves except to AWS services | Low, if workloads only need AWS APIs |
| NAT gateway alone | Hides private IPs. Filters nothing | Low |
| Network Firewall (central egress VPC) with domain lists | FQDN allow list, IPS signatures, logs | Medium |
| Explicit forward proxy fleet (for example Squid) behind an NLB | URL-level allow list, user auth, caching | High: you patch and scale it |
| GWLB + vendor firewall | Vendor URL categories and threat feeds | High |
- An explicit proxy only filters clients configured to use it. Pair it with security groups or NACLs that stop direct outbound 80/443, or clients just go around it.
- A self-managed proxy or NAT instance forwarding traffic needs source/destination check disabled.
- Use VPC endpoints with endpoint policies so traffic to AWS services never reaches the egress path. See Hybrid and private access.
Scenarios
A domain list on Network Firewall filters the TLS connections by SNI, and strict order with a default drop blocks and logs everything else. Package CDNs change IP addresses often, so IP-based security group rules break. DNS Firewall alone stops name lookups but not connections to hard-coded IPs. NAT gateways have no filtering feature.
NACLs are stateless, so replies from the ALB to each client's high source port need an outbound allow for 1024–65535. The ALB nodes also need the matching return rules toward the targets. Security groups and NACLs always work together. TLS doesn't require port 80, and rule numbers only set order.
GWLB is built for transparent, scalable inline appliances: it health checks targets, spreads flows, and keeps them symmetric with appliance mode. Network Firewall doesn't run the vendor's product or feeds. An ALB only handles HTTP(S) it terminates and can't be a route target. Traffic Mirroring sends copies, so it detects but can't block.
Further reading
Generative AI guardrails
Amazon Bedrock Guardrails policies, the OWASP Top 10 for LLM Applications mapped to AWS controls, least privilege for agents, preventing data leakage, and logging model invocations.
Hybrid and private access
VPC endpoints and endpoint policies, PrivateLink, Site-to-Site VPN, Client VPN, Direct Connect with MACsec, VPN over Direct Connect, and AWS Verified Access for VPN-less application access.