NACLs — Complete Guide
NACLs — Complete Guide: free step-by-step lesson with examples, common mistakes, and interview tips — part of AWS Cloud Tutorial on Toolliyo Academy.
On this page
AWS Cloud Tutorial · Lesson 15 of 100
NACLs
Core services → Projects
Core services · 1 — AWS basics · ~6 min · AWS — Networking & Security
What is this?
Network ACLs are stateless subnet-level filters with numbered allow/deny rules. They apply to all traffic entering or leaving a subnet.
Why should you care?
AwsVerse adds NACL deny rules for known bad CIDRs at the subnet edge as a second layer beyond SGs.
See it live — copy this example
Run in AWS CloudShell / local AWS CLI v2, or follow the matching steps in the AWS Console (Free Tier).
aws ec2 create-network-acl-entry \
--network-acl-id acl-0sub789 \
--rule-number 50 \
--protocol -1 \
--rule-action deny \
--cidr-block 203.0.113.0/24 \
--ingress
What happened?
- Denies all protocols from a blocklisted CIDR into the subnet.
- NACLs need explicit outbound return rules because they are stateless.
Practice next
- Open VPC → Network ACLs → select subnet ACL.
- Add deny rule for a test CIDR; add allow 1024-65535 outbound for ephemeral returns.
- Compare: SG change vs NACL change effect on same instance.
- Add allow rule 100 before deny 50 for your office IP.
- Document rule numbers — lower evaluated first.
Remember
NACL = subnet edge, stateless. SG = instance, stateful. Use NACL for coarse deny lists.
AwsVerse edge deny
Threat intel feeds bad IP ranges.
Outcome: NACL deny rules drop traffic before it hits instances.
Interview prep for this lesson
Practice these questions aloud after reading—each links to a full structured answer.
Sign in to ask a question or upvote helpful answers.
No questions yet — be the first to ask!