Security Group
-
It is a virtual firewall works at egress network interface or instance level.
-
Security group work at instance level.
-
Up to five security group per EC2 instance can be attached.
-
Can only have a permit rules, don't have deny rules.
-
It is stateful in nature, if a traffic is allowed in inbound rules it would be automatically into outbound rules but not vice versa.
Stateful is nothing but all rules are evaluated before decision to allow traffic
-
By default anything aside from permit or mentioned inbound or outbound rule will be considered denied.
-
By default all traffic is denied.
-
Security group have rules that control inbound and outbound instance traffic