Security Groups vs NACLs Explained: Cloud Firewalls for Cloud+
Security groups are the instance-level firewall in cloud platforms. They are compared constantly with network access control lists, and the comparison is one of the most reliably examined points in cloud networking. The core distinction: stateful versus stateless Security groups are stateful. If you allow inbound traffic on port 443, the response is automatically permitted outbound. The platform tracks the connection and allows return traffic without a matching rule. Network ACLs are stateless. Every packet is evaluated independently. Allowing inbound 443 does not permit the response — you must also allow the outbound traffic, and because responses come from ephemeral ports you generally have to allow a wide ephemeral range outbound. That single difference explains most misconfigurations. A NACL that permits inbound HTTPS but nothing outbound produces a connection that establishes and then appears to hang, and the ephemeral port range is the thing people forget. The full compari...