Cloud Networking (AWS) · Cloud 3

Security groups and network ACLs: stateful vs stateless

Two firewalls, two jobs. Security groups sit on the instance, allow only, remember connections and can name other groups as the source. Network ACLs sit on the subnet, have numbered allow and deny rules, and forget every packet the moment it passes. Build a three-tier app with group-to-group rules, then fix a database that a stateless ACL has silently cut off.

35 min read4 chapters2 labs5 quiz

This module is part of the paid plans

The free Starter plan opens the first module of every path. Upgrade to unlock this module's lesson, labs, quiz and scenarios.

Your free Starter plan includes

  • ✓First module of every path — lessons and quizzes
  • ✓3 hands-on labs in total
  • ✓Practice questions (up to 10 per set)
  • ✓Build your own lab — 3 sessions a month, up to 4 devices

Inside this module

  • Lab 1 · Lock down a three-tier app with group-to-group rules
  • Lab 2 · Ticket: the database stopped answering after the security review
🎓 For educational purposes only — all devices are simulationsTerms of UsePrivacy Policy© 2026 Network Kings
CONFIG by Network Kings — an educational IT simulation platform for learning purposes only. It is not Cisco IOS, Junos, FortiOS or PAN-OS and contains no Cisco, Juniper, Fortinet or Palo Alto Networks software. Cisco, IOS, CCNA, CCNP, Juniper, JNCIA, JNCIS, JNCIP, Fortinet, FortiGate, FortiOS, NSE, Palo Alto Networks, PAN-OS and PCNSE are trademarks of their respective owners. Network Kings is not affiliated with or endorsed by Cisco Systems, Inc., Juniper Networks, Inc., Fortinet, Inc. or Palo Alto Networks, Inc.