Amazon VPC NACL default rules evaluation order

Viewed 5206

With my understanding, NACL (Network Access Control List) is the subnet firewall.

I'm trying to understand what are the defaults when creating a NACL:

  • Rule #100 - all ports from all IPs are allowed by default, otherwise
  • All is denied

So, bottom line, is all allowed or denied? I know that according to AWS best practices, all access should be disabled by default.

Rules

1 Answers
Related