Concept and mechanism
Network diagnosis starts with source, destination, protocol, port, and direction. Security groups are stateful; NACLs require considering the return path and rule order as well. An allowed rule in one control does not cancel a block in another. For an instance without a public IP to initiate external connections through public NAT, check the private route to NAT and its public path to the internet gateway. NAT is not a mechanism for automatically publishing an inbound service. An S3 gateway endpoint requires association with relevant route tables and retains authorization and network-control requirements applicable to the path.
Guided application
DNS and caches introduce time between a change and observed behavior. Lowering TTL at cutover does not revoke answers already stored with the previous TTL. Prepare the change and maintain compatibility during transition. In CloudFront, OAC for S3 requires a compatible regular origin; the website endpoint is a custom origin and does not support that mechanism. The policy should authorize intended access without making the origin public. Also distinguish origin control from end-user authentication. For static-file releases, versioned names help because edge invalidation does not necessarily remove the old object held by a browser or intermediate cache.
The request leaves, but its TCP response is blocked by the NACL at the ephemeral port. Opening more security-group ports does not repair the rule actually rejecting the return.
Common pitfalls
Endpoint existence treated as routing in every subnet; DNS treated as instant update; OAC treated as user login.
Related topics: Signals, alarms, and operational diagnosis · Continuity and usable recovery · Changes, drift, and controlled automation
Validate the complete path and distinguish delivery, authorization, and caching.
Reference: VPC network ACL evaluation · SOA-C02 archived guide v2.3; retired2025-09-29