Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Use security groups for the usual resource-level access control in a VPC. Add network ACLs (NACLs) when you need subnet-wide, stateless allow-and-deny guard rails. Choose AWS Network Firewall when traffic needs managed inspection or filtering beyond those controls—such as domain filtering, protocol detection, or deep packet inspection. They operate at different points in the network, so you can layer them; Network Firewall inspects only traffic routed through its firewall endpoints.

How the three controls differ

The key distinction is scope: a security group protects associated resources, a NACL applies at a subnet boundary, and Network Firewall inspects traffic on paths that routing sends through its endpoints. AWS describes security groups as the primary access-control mechanism for VPC resources; NACLs can provide coarser subnet controls or additional defense in depth. AWS VPC infrastructure security guidance explains the baseline recommendation.

Control Where it applies Rules and traffic state Best fit Main caveat
Security group Associated resource, such as an instance or network interface Stateful; allow rules only. Return traffic for an allowed connection is automatically allowed. Workload-level access policies limited to required sources, destinations, ports, and protocols. It does not provide subnet-wide deny rules or Network Firewall’s deeper inspection features.
Network ACL Subnet and its resources Stateless; rules can allow or deny. Rules are evaluated in ascending order until a match, and both traffic directions need explicit rules. Coarse subnet guard rails, targeted denies, or a further defense-in-depth layer. Rule order and return-path rules require care; a NACL is not a stateful flow-inspection engine.
AWS Network Firewall VPC traffic paths routed through firewall endpoints Stateless packet inspection followed, when configured, by stateful flow inspection; stateful rules support Suricata-compatible syntax. Managed perimeter or east-west inspection, domain or IP filtering, protocol-aware filtering, and deeper packet inspection. Requires firewall endpoints, policy and rule-group configuration, routing integration, and an architecture compatibility review.

For the details behind security-group and NACL scope and rule behavior, see AWS’s subnet access-control example. The comparisons between Network Firewall’s rule engines and these VPC controls are useful analogies, not evidence that the controls are interchangeable.

When to use each control

Use security groups for ordinary workload access

Start with security groups when deciding which resources can communicate. Scope each allow rule to the required traffic rather than treating a VPC-wide firewall as a substitute for resource-level policy. Because security groups are stateful, return traffic for an allowed connection does not need a separate rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Add a NACL for subnet-wide guard rails

Consider a NACL when the intended policy applies to a whole subnet, especially when you need an explicit deny rule or a coarse additional boundary. Its ordered, stateless evaluation means you must account for both the outbound and return directions. A NACL may complement security groups, but it does not replace their resource-level role.

Use Network Firewall for routed inspection

Choose Network Firewall when you need capabilities such as domain or IP endpoint filtering, custom bad-domain lists, deep packet inspection, or protocol detection independent of port. AWS documents perimeter (north-south) and internal (east-west) inspection use cases. See What is AWS Network Firewall? and AWS’s overview of filtering VPC traffic with Network Firewall.

How Network Firewall inspection works

Network Firewall has two rule engines. The stateless engine evaluates packets individually and can pass, drop, or forward matching traffic to stateful inspection. The stateful engine evaluates traffic in flow context and supports Suricata-compatible rules. The stateless policy is evaluated first; whether traffic reaches the stateful engine depends on the stateless action and policy settings. AWS documents these engines in its stateless and stateful rules engine guide.

Although AWS compares the stateless engine’s behavior to NACLs and the stateful engine’s to security groups, the analogy has limits: Network Firewall’s stateful engine has a default pass behavior, unlike the security group default-deny model. Do not assume that configuring one layer supplies a missing rule or default at another.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Routing determines what Network Firewall can inspect

Creating a firewall does not automatically put every VPC packet through it. Firewall endpoints are placed in selected Availability Zone subnets, and VPC routes determine whether a traffic path traverses those endpoints. AWS describes filtering traffic to and from internet and NAT gateways, as well as traffic over VPN or Direct Connect; it also documents inspection of north-south and east-west traffic.

Plan routes and endpoint placement for the specific paths you want inspected, then validate that the architecture is supported. AWS’s how Network Firewall works and getting started guide describe traffic flow and configuration considerations.

Can you layer the controls?

Yes. A common design keeps security groups as resource-level controls, uses NACLs where subnet-wide guard rails are appropriate, and routes selected VPC traffic through Network Firewall for inspection. Treat each layer as an independent policy point: check the effective rules and routes together. A permissive rule at one layer does not override a deny at another, and a firewall cannot inspect a path that bypasses its endpoint.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to check before deploying Network Firewall

  • Which traffic paths must be inspected, including the relevant ingress, egress, and internal routes.
  • Where firewall endpoints will sit and whether the chosen Availability Zone and VPC design are supported.
  • Which stateless actions, stateful rules, and policy settings produce the intended result.
  • How logs and monitoring will support operational review.
  • Current pricing for the target Region and planned endpoint configuration and usage. The cost depends on regional pricing and deployment details, so a meaningful estimate needs those inputs and a date.

Do not compare a firewall cost with the cost of security groups or NACLs using a single generic figure: this article establishes no price or savings estimate, and a complete comparison depends on the architecture and any surrounding AWS services.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.