Skip to main content

Security Group

A Security Group is a stateful virtual firewall attached to EC2 instances, RDS databases, and other AWS resources that supports allow rules only — there is no explicit deny. Because it's stateful, return traffic for an allowed inbound connection is automatically permitted outbound without a matching rule, unlike stateless Network ACLs which require explicit rules in both directions.

A three-tier fintech app chains Security Groups by reference rather than IP: the ALB's SG allows 443 from the internet, the App EC2 SG allows 8080 only from the ALB's SG ID, and the RDS SG allows 5432 only from the App SG ID — so the rule stays correct even as instances scale up and down and IPs change.

One EC2, Multiple Security Groups

An instance can have up to 5 Security Groups attached simultaneously, with all their allow rules combined — there's no conflict resolution needed since nothing can explicitly deny.

Common Mistake

Opening port 22 to 0.0.0.0/0, even temporarily. Automated internet scanners probe every public IP within minutes. Restrict SSH to a specific IP or use SSM Session Manager instead, which needs no open port at all.

Remember

A "connection timeout" points to a Security Group or NACL blocking the packet; a "connection refused" means the packet arrived but nothing is listening on that port.

Frequently Asked Questions

Why doesn't a Security Group support explicit deny rules?

Security Groups are allow-list only by design — you add rules for traffic you want permitted, and everything else is implicitly denied, with no way to write a rule that explicitly blocks a specific source. This keeps evaluation simple and predictable (the union of matching allow rules across every attached security group determines access), but it means you can't use a Security Group alone to carve out an exception, like allowing a whole subnet except one bad-actor IP — that requires a Network ACL instead.

Why do Security Groups and Network ACLs need different rule configurations for the same traffic flow?

Security Groups are stateful — an allowed inbound request automatically permits its response traffic outbound with no matching rule needed — while Network ACLs are stateless and require separate explicit rules for both directions of every connection. A frequent misconfiguration is copying security-group-style thinking onto a NACL: forgetting to add the outbound ephemeral-port return-traffic rule, which breaks connections that the security group alone would have handled correctly.