NACL, SG, VPC Flow Logs
- NACL
- Networking/Firewall which controls traffic from and to interne
- can have ALLOW and DENY rules
- At subnet level
- Stateless: have to specify in and out
- Security Group
- Only ALLOW rules
- At instance level
- Stateful: return traffic automatically allowed
- VPC Flow Logs: Capture information about all interfaces
- VPC flow logs
- Subnet flow logs
- Elastic network interface flow logs