VPC security: subnets, security groups, NACLs and NAT
7 min read · about 1 h 30 min with practice3 quick checks≈4% of the testCore: Core: tested on most papers
Reading is free. Sign in to tick off lessons, keep your place and track your mastery.
VPC security is the most heavily weighted topic in Domain 1. Expect several items built on a three-tier application, a connectivity symptom or a flow-log excerpt, asking where each component belongs and which control (route table, security group, network ACL, NAT gateway) fixes the problem.
By the end you’ll be able to
Segment a multi-tier application into public, private and isolated subnets with the correct route tables
Contrast security groups (stateful, allow-only, instance level) with network ACLs (stateless, allow and deny, subnet level, ordered rules, ephemeral ports)
Chain security groups by referencing source security groups between tiers
Provide outbound internet access for private subnets with NAT gateways and administrative access without open SSH/RDP (Systems Manager Session Manager)
Use VPC Flow Logs to troubleshoot and audit accepted and rejected traffic
What the exam asks
Place each tier in a public, private or isolated subnet across at least two Availability Zones.
Choose security groups or network ACLs from a requirement: allow-only or deny, stateful or stateless, instance or subnet.
Chain tiers with security-group references instead of IP ranges.
Give private instances outbound internet access with a NAT gateway or an egress-only internet gateway, and make NAT highly available.
Replace bastion hosts and open SSH/RDP with Session Manager.
Read VPC Flow Logs to find which control is dropping traffic.
Core ideas
Subnet tiers and route tables
A subnet lives in one AZ. Its route table, not its name, makes it public or private.
Databases and caches. They reach AWS services through VPC endpoints
To be reachable, an instance in a public subnet also needs a public IPv4 address or an Elastic IP address. Every tier should span at least two AZs.
Internet access for private subnets
NAT gateway:
Managed by AWS and highly available within its AZ.
Placed in a public subnet with an Elastic IP address.
Allows only outbound-initiated IPv4 connections and has no security groups of its own.
For independence from any one AZ, create one NAT gateway per AZ and give each AZ’s private subnets their own route table that points to the local NAT gateway.
NAT instance: self-managed EC2 with the source/destination check disabled. Legacy: more work, and a single point of failure unless you script failover.
Egress-only internet gateway: outbound-only IPv6, the IPv6 counterpart of NAT (no address translation is needed).
vii.Check your understanding
3 questions on VPC security: subnets, security groups, NACLs and NAT. Every option is explained once you answer.
Sign in to try the quick check
Answers are checked on our side, every option is explained, and your result feeds your mastery for this topic. It’s free.
The first 3 of 11 cards for this topic. Sign in and finish the lesson to review them with spaced repetition.
PromptCard 1 of 3
Security group vs network ACL: the four differences
Security groups vs network ACLs
Security group
Network ACL
Applies to
ENI (instance, ALB, RDS, Lambda ENI…)
Subnet (all traffic entering or leaving it)
Rules
Allow only
Allow and deny
State
Stateful: return traffic is allowed automatically
Stateless: return traffic needs its own rule
Evaluation
All rules together
In rule-number order; the first match wins
Defaults
New SG: no inbound, all outbound allowed
Default NACL: allows all. New custom NACL: denies all
Sources
CIDRs, prefix lists, other security groups
CIDRs only
Ephemeral ports. Network ACLs are stateless. A web subnet that allows inbound 443 must therefore also allow outbound TCP 1024–65535 to the clients. Connections that the instances start need the same rule in the other direction. Missing ephemeral-port rules are the most common NACL bug in exam stems.
Blocking an IP range needs a deny rule. Use a network ACL, or AWS WAF for HTTP traffic on an ALB, CloudFront or API Gateway. Security groups cannot deny.
Neither control filters traffic to the Amazon DNS resolver, DHCP or the instance metadata service.
Chaining tiers with security-group references
Text
ALB SG: inbound 443 from 0.0.0.0/0
App SG: inbound 8080 from ALB SG
DB SG: inbound 3306 from App SG
A security-group reference follows instances as Auto Scaling replaces them, and it excludes everything else in the same subnet. It is more secure than subnet CIDRs and needs no maintenance.
Administrative access without open ports
AWS Systems Manager Session Manager gives shell or port-forwarding access with no inbound rules, no bastion host and no SSH keys:
IAM controls who can connect.
CloudTrail records every session.
The full session output can be logged to S3 or CloudWatch Logs.
Session Manager has three requirements:
The SSM Agent, which is preinstalled on common AMIs.
An instance profile with the AmazonSSMManagedInstanceCore policy.
HTTPS access to Systems Manager, through a NAT gateway or, in isolated subnets, through interface VPC endpoints for ssm, ssmmessages and ec2messages.
EC2 Instance Connect Endpoint also allows SSH to instances without public IP addresses, but the instances still need port 22 open to the endpoint.
VPC Flow Logs
Flow logs capture traffic metadata: addresses, ports, protocol, bytes and whether the traffic was accepted or rejected (ACCEPT or REJECT).
Scope: a VPC, a subnet or a single ENI, filtered to accepted, rejected or all traffic.
Destinations: CloudWatch Logs, Amazon Data Firehose or Amazon S3. On S3 you can use Parquet format, which is cheap to query with Athena.
Not captured: packet contents (use VPC Traffic Mirroring for those) and traffic to the Amazon DNS resolver or instance metadata.
How to read them:
If the inbound request is ACCEPT and its outbound response is REJECT, the cause is a network ACL. A stateful security group always allows the response to a connection it accepted.
If the inbound request itself is REJECT, the cause is either the security group or the network ACL.
Worked examples
Exam technique
Stateful vs stateless decides half of these items. Any option that adds a return-traffic rule to a security group is wrong.
“Deny” or “block this IP” points to a NACL, or to WAF at layer 7. “Only from the app tier” points to a security-group reference.
Two common traps: an option that puts a component needing inbound internet traffic in a private subnet, and an option that puts a NAT gateway in a private subnet.
“No inbound ports” or “audit every session” points to Session Manager.
“MOST highly available” with NAT means one NAT gateway per AZ with per-AZ route tables. A single NAT gateway is justified only when the stem asks for “MOST cost-effective”, for example in dev/test.
In flow-log items, first find which direction shows REJECT.
Common mistakes
Quick recap
The route table decides whether a subnet is public, private or isolated. Spread every tier across two or more AZs.
Put the ALB in public subnets, the app tier in private subnets and the database in isolated subnets.
Security groups are stateful and allow-only, and they can reference other security groups. NACLs are stateless, support allow and deny, are evaluated in order and apply to the whole subnet.
Put NAT gateways in public subnets, one per AZ for high availability. Use an egress-only internet gateway for outbound IPv6.
Session Manager replaces bastion hosts: no inbound ports, access controlled by IAM, and full session logs.
Flow logs record metadata with ACCEPT or REJECT. An outbound REJECT of a response means a NACL problem.