Concept and mechanism
A network control’s effect depends on its scope. Security groups attached to the same interface aggregate Allow rules; a narrower group does not cancel an opening in another group. There is no rule selecting the most restrictive group. Permission at this control also does not guarantee the whole path, which may depend on routes, NACLs, and application behavior. NACLs evaluate rules numerically and stop at the first match. A more specific network in a later rule does not win because of specificity, unlike prefix-routing intuition. Analyze inbound and outbound paths because a NACL is stateless.
Guided application
In HTTPS diagnosis, allowing inbound 443 does not guarantee return traffic to the client ephemeral port. Identify each direction and the blocking control before broadening rules. Exceptions also exist: a NACL does not block AmazonProvidedDNS queries; consider the appropriate DNS control, such as Route 53 Resolver DNS Firewall, for that objective. For administration, Session Manager can reduce inbound-port exposure and centralize authorization. However, content recording is unavailable for SSH or port-forwarding sessions. CloudTrail can record API calls, which is not equivalent to commands inside the tunnel. Choose an administrative path meeting the actual evidence requirement.
Rule 100 allows a /16 and rule 200 denies a contained /24. A matching packet is allowed by the first rule.
Common pitfalls
Restrictive group as Deny; more specific prefix as NACL priority; API logging as recorded shell.
Related topics: WAF and GenAI application protection · Federation and delegation across entities
Check semantics, order, and scope of each control on the complete path.
Reference: Network ACLs · SCS-C03