QuestionQ38

Security and Compliance

A CloudOps engineer is building a simple public-facing website on Amazon EC2. The CloudOps engineer created the EC2 instance in an existing public subnet and assigned the instance an Elastic IP address. Next, the CloudOps engineer created and applied a new security group to the instance that permits inbound HTTP traffic from 0.0.0.0/0. Finally, the CloudOps engineer created a new network ACL and applied it to the subnet to permit inbound HTTP traffic from 0.0.0.0/0. However, the website cannot be accessed from the internet.

What is causing this issue?

Explanation

Network ACLs are stateless, so response traffic is not automatically allowed. An ACL that permits inbound HTTP on TCP port 80 also needs an outbound rule that permits the web server’s response traffic to the clients’ ephemeral ports. Security groups are stateful, so an inbound HTTP rule allows the corresponding response traffic without a separate outbound response rule.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!