[{"data":1,"prerenderedAt":703},["ShallowReactive",2],{"nav_featured_podcast":3,"nav_featured_press_release":21,"navigation_content":30,"engineering_blog_post:nacls-blogpost":378},{"uid":4,"title":5,"episodeLabel":6,"dateLabel":7,"episodeArt":8,"href":20},"from-payment-rails-to-connectivity","From Payment Rails to Connectivity, with The Clearing House's David Watson","EPISODE 5","August 18, 2026",{"dimensions":9,"alt":12,"copyright":13,"url":14,"id":15,"edit":16},{"width":10,"height":11},1064,652,"Payments Cannot Fail — Episode 05 with David Watson",null,"\u002F_prismic-media\u002Fd80df2e47c3ecb6f-cFcyPAgzKCMQEaND_Episode-05-David.jpg","cFcyPAgzKCMQEaND",{"x":17,"y":17,"zoom":18,"background":19},0,1,"transparent","\u002Fresources\u002Fpodcasts\u002Ffrom-payment-rails-to-connectivity",{"uid":22,"title":23,"tag":24,"dateLabel":25,"imageUrl":26,"imageAlt":27,"href":28,"imageFit":29},"form3-expands-strategic-partnership-with-sumup","Form3 expands strategic partnership with SumUp to bring real-time SEPA payments to millions of European small businesses","EU","February 25, 2026","\u002F_prismic-media\u002F3e91177f91478610-QA44Gzev0_tdg3ZI_SumUp.jpg","sumup","\u002Fresources\u002Fpress-releases\u002Fform3-expands-strategic-partnership-with-sumup","cover",{"header":31,"platform":59,"solutions":91,"developers":133,"company":155,"resources":184,"partnerships":208,"footer":220,"mobile":325},{"ctaLabel":32,"ctaHref":33,"topNav":34},"TALK TO OUR TEAM","\u002Fcontact",[35,39,43,47,51,55],{"label":36,"href":37,"key":38},"Platform","\u002Fplatform","platform",{"label":40,"href":41,"key":42},"Solutions","\u002Fsolutions","solutions",{"label":44,"href":45,"key":46},"Developers","\u002Fdevelopers","developers",{"label":48,"href":49,"key":50},"Company","\u002Fcompany","company",{"label":52,"href":53,"key":54},"Resources","\u002Fresources","resources",{"label":56,"href":57,"key":58},"Partnerships","\u002Fpartnerships","partnerships",{"sectionEyebrow":60,"primary":61,"productLinks":65,"enterprise":81,"trustFabric":86},"Explore the Platform",{"heading":62,"body":63,"ctaLabel":64,"ctaHref":37},"Our Payments Platform","A resilient, cloud-native platform powering real-time account-to-account payments at global scale.","See How It Works",[66,69,72,75,78],{"label":67,"href":68},"Payments Processing & Gateway","\u002Fpayments-processing-gateway",{"label":70,"href":71},"Orchestration & Intelligent Routing","\u002Forchestration-intelligent-routing",{"label":73,"href":74},"Payments Simulator","\u002Fpayments-simulator",{"label":76,"href":77},"Sponsor Bank Enablement","\u002Fsponsor-bank-enablement",{"label":79,"href":80},"Informed UI","\u002Finformed-ui",{"heading":82,"body":83,"ctaLabel":84,"ctaHref":85},"Form3 Enterprise","Deploy and manage proven cloud-native payments technology in the environment that works for your institution.","Deploy Enterprise","\u002Fplatform\u002Fenterprise",{"heading":87,"body":88,"ctaLabel":89,"ctaHref":90},"Form3 Trust Fabric","Manage TLS certificates, cryptographic vulnerabilities and quantum readiness at scale, with continuous visibility.","Deploy Trust Fabric","\u002Fplatform\u002Ftrust-fabric",{"regionsIntro":92,"regions":98,"industries":118},{"eyebrow":93,"heading":94,"headingLine2":95,"body":96,"ctaLabel":64,"ctaHref":97},"Regions","Global Reach.","Regional Expertise.","A proven payments platform serving organizations worldwide, with specialized experience across North America, United Kingdom, and Europe.","\u002Fglobal",[99,108,113],{"label":100,"description":101,"ctaLabel":102,"href":103,"extraLinks":104},"North America","Real-time infrastructure, through a resilient, multi-cloud platform built for scale and regulatory confidence.","US HOME","\u002Fsolutions\u002Funited-states",[105],{"label":106,"href":107},"CANADA HOME","\u002Fsolutions\u002Fcanada",{"label":109,"description":110,"ctaLabel":111,"href":112},"United Kingdom","Powering account-to-account payments at the heart of the UK financial ecosystem, with proven resilience.","UK HOME","\u002Fsolutions\u002Funited-kingdom",{"label":114,"description":115,"ctaLabel":116,"href":117},"Europe","Enabling secure, real-time and SEPA payments across European markets through a unified, cloud-native platform.","EUROPE HOME","\u002Fsolutions\u002Feurope",{"eyebrow":119,"links":120},"Industries",[121,125,129],{"label":122,"href":123,"iconSrc":124},"Financial Services","\u002Fsolutions\u002Findustries\u002Ffinancial-services","\u002F_prismic-media\u002F29c09c45caa89db9-kbUHZmgTmuIMbo1t_FinancialServices_menu.svg",{"label":126,"href":127,"iconSrc":128},"Fintech","\u002Fsolutions\u002Findustries\u002Ffintech","\u002F_prismic-media\u002F6de3e7cb4dd8d874-SjwNe6Nh-bbuTi0P_Fintech_menu.svg",{"label":130,"href":131,"iconSrc":132},"Government","\u002Fsolutions\u002Findustries\u002Fgovernment","\u002F_prismic-media\u002Fe71bc3a74a1d2142-kaGgdituzKDnVTbm_Government_menu.svg",{"engineering":134,"api":142,"pressEyebrow":154},{"eyebrow":135,"links":136},"Engineering",[137,139],{"label":135,"href":138},"\u002Fengineering",{"label":140,"href":141},"Accreditations","\u002Faccreditations",{"eyebrow":143,"links":144},"API",[145,148,151],{"label":146,"href":147},"API Docs","https:\u002F\u002Fwww.api-docs.form3.tech\u002F",{"label":149,"href":150},"API Tutorials","https:\u002F\u002Fwww.api-docs.form3.tech\u002Fapi\u002Ftutorials\u002Fgetting-started\u002Fintroduction",{"label":152,"href":153},"API Status","https:\u002F\u002Fstatus.form3.tech\u002F","Latest Press Release",{"about":156,"people":171,"podcastEyebrow":183},{"eyebrow":157,"links":158},"About",[159,162,165,168],{"label":160,"href":161},"Our Story","\u002Fcompany\u002Four-story",{"label":163,"href":164},"Our Team","\u002Fcompany\u002Fteam",{"label":166,"href":167},"Our Success & Strategic Approach","\u002Fcompany\u002Four-success",{"label":169,"href":170},"Customer Stories","\u002Fcompany\u002Fcustomer-stories",{"eyebrow":172,"links":173},"People",[174,177,180],{"label":175,"href":176},"Careers","\u002Fcompany\u002Fcareers",{"label":178,"href":179},"Vacancies","\u002Fcompany\u002Fvacancies",{"label":181,"href":182},"Culture","\u002Fcompany\u002Fculture","Latest Podcast",{"intro":185,"links":189,"pressEyebrow":154,"podcastEyebrow":183},{"eyebrow":52,"heading":186,"body":187,"ctaLabel":188,"ctaHref":53},"Form3 Resources","Our Resources bring together thought leadership, engineering insights, payments expertise, webinars, podcasts, whitepapers, company news and stories from our teams—all in one place.","LEARN MORE",[190,193,196,199,202,205],{"label":191,"href":192},"Payments Cannot Fail Podcast","\u002Fresources\u002Fpodcasts",{"label":194,"href":195},"Press Releases","\u002Fresources\u002Fpress-releases",{"label":197,"href":198},"Payment Insights","\u002Fresources\u002Fpayment-insights",{"label":200,"href":201},"Culture Blog","\u002Fresources\u002Fculture-blog",{"label":203,"href":204},"Engineering Blog","\u002Fresources\u002Fengineering-blog",{"label":206,"href":207},"Events","\u002Fevents",{"intro":209,"links":213,"pressEyebrow":154},{"eyebrow":56,"heading":210,"body":211,"ctaLabel":212,"ctaHref":57},"Partner with Form3","Explore how Form3 works with banks, fintechs, cloud providers, technology platforms and system integrators to accelerate payment modernization, strengthen customer offerings and unlock new opportunities for growth.","Let's Partner Together",[214,217],{"label":215,"href":216},"Technical & Ecosystem Partners","\u002Fpartnerships\u002Ftechnical-ecosystem",{"label":218,"href":219},"Channel & Distribution Partners","\u002Fpartnerships\u002Fchannel-distribution",{"platform":221,"region":229,"development":240,"company":248,"resources":259,"partnerships":267,"stayConnected":272,"legalLinks":292,"certifications":314},{"title":36,"links":222},[223,224,225,226,227,228],{"label":62,"href":37},{"label":67,"href":68},{"label":70,"href":71},{"label":73,"href":74},{"label":76,"href":77},{"label":79,"href":80},{"title":230,"links":231},"Region",[232,234,236,237,238],{"label":233,"href":97},"Global",{"label":235,"href":103},"United States",{"label":109,"href":112},{"label":114,"href":117},{"label":239,"href":107},"Canada",{"title":241,"links":242},"Development",[243,244,245,246,247],{"label":135,"href":138},{"label":140,"href":141},{"label":146,"href":147},{"label":149,"href":150},{"label":152,"href":153},{"title":48,"links":249},[250,251,252,253,254,255,256],{"label":160,"href":161},{"label":163,"href":164},{"label":169,"href":170},{"label":175,"href":176},{"label":178,"href":179},{"label":181,"href":182},{"label":257,"href":258},"Net Zero","\u002Fcompany\u002Fnet-zero",{"title":52,"links":260},[261,262,263,264,265,266],{"label":186,"href":53},{"label":191,"href":192},{"label":194,"href":195},{"label":200,"href":201},{"label":203,"href":204},{"label":206,"href":207},{"title":56,"links":268},[269,270,271],{"label":210,"href":57},{"label":215,"href":216},{"label":218,"href":219},{"title":273,"body":274,"ctaLabel":32,"ctaHref":33,"social":275},"Stay Connected","Form3 is a global account-to-account financial fabric delivering a proven payments platform trusted by banks and fintechs to deliver resilient, real-time payment experiences for their customers at scale.",[276,280,284,288],{"label":277,"href":278,"icon":279},"LinkedIn","https:\u002F\u002Fwww.linkedin.com\u002Fcompany\u002Fform3-financial-cloud\u002F","linkedin",{"label":281,"href":282,"icon":283},"X","https:\u002F\u002Fwww.x.com\u002FForm3Cloud","x",{"label":285,"href":286,"icon":287},"YouTube","https:\u002F\u002Fwww.youtube.com\u002F@Form3Cloud","youtube",{"label":289,"href":290,"icon":291},"Instagram","https:\u002F\u002Fwww.instagram.com\u002Fform3.tech","instagram",[293,296,299,302,305,308,311],{"label":294,"href":295},"Terms & Conditions","\u002Flegal\u002Fterms-and-conditions",{"label":297,"href":298},"Privacy Policy","\u002Flegal\u002Fdata-privacy-statement",{"label":300,"href":301},"Recruitment Data Policy","\u002Flegal\u002Frecruitment-data-policy",{"label":303,"href":304},"Modern Slavery Statement","\u002Flegal\u002Fmodern-slavery",{"label":306,"href":307},"License","\u002Flegal\u002Flicense",{"label":309,"href":310},"Cookie Policy","\u002Flegal\u002Fcookie-policy",{"label":312,"href":313},"Manage Cookies","#cookies",[315,317,319,321,323],{"label":316},"ISO 27001",{"label":318},"ISO 27017",{"label":320},"ISO 27018",{"label":322},"ISAE 3000 SOC 2 Type II",{"label":324},"ISO 22301",{"platform":326,"solutions":341,"developers":355,"company":365,"resources":366,"partnerships":374},[327,329,339,340],{"kind":328,"label":62,"href":37},"link",{"kind":330,"label":60,"children":331},"group",[332,333,334,335,337],{"label":67,"href":68},{"label":70,"href":71},{"label":73,"href":74},{"label":76,"href":336},"\u002Fplatform\u002Fsponsor-bank-enablement",{"label":79,"href":338},"\u002Fplatform\u002Finform3d-ui",{"kind":328,"label":82,"href":85},{"kind":328,"label":87,"href":90},[342,344,350],{"kind":328,"label":233,"href":343},"\u002Fsolutions\u002Fglobal",{"kind":330,"label":93,"children":345},[346,347,348,349],{"label":235,"href":103},{"label":239,"href":107},{"label":109,"href":112},{"label":114,"href":117},{"kind":330,"label":119,"children":351},[352,353,354],{"label":122,"href":123},{"label":126,"href":127},{"label":130,"href":131},[356,360],{"kind":330,"label":135,"children":357},[358,359],{"label":135,"href":138},{"label":140,"href":141},{"kind":330,"label":143,"children":361},[362,363,364],{"label":146,"href":147},{"label":149,"href":150},{"label":152,"href":153},[],[367,368,369,370,371,372,373],{"kind":328,"label":186,"href":53},{"kind":328,"label":191,"href":192},{"kind":328,"label":194,"href":195},{"kind":328,"label":197,"href":198},{"kind":328,"label":200,"href":201},{"kind":328,"label":203,"href":204},{"kind":328,"label":206,"href":207},[375,376,377],{"kind":328,"label":210,"href":57},{"kind":328,"label":215,"href":216},{"kind":328,"label":218,"href":219},{"id":379,"uid":380,"url":381,"type":382,"href":383,"tags":384,"first_publication_date":385,"last_publication_date":386,"slugs":387,"linked_documents":389,"lang":390,"alternate_languages":391,"data":392},"alz09BEAAC0AUWcc","nacls-blogpost","\u002Fresources\u002Fengineering-blog\u002Fnacls-blogpost","engineering_blog_post","https:\u002F\u002Fform3-website.cdn.prismic.io\u002Fapi\u002Fv2\u002Fdocuments\u002Fsearch?ref=apnMZxEAACcAKWxv&q=%5B%5B%3Ad+%3D+at%28document.id%2C+%22alz09BEAAC0AUWcc%22%29+%5D%5D",[],"2026-07-19T16:21:56+0000","2026-08-27T21:41:12+0000",[388],"introduction",[],"en-us",[],{"title":393,"excerpt":394,"card_image":395,"published_date":401,"reading_time":402,"tag":403,"dek":394,"featured_image":404,"about_form3":405,"client_about_heading":13,"client_about_body":406,"author_name":13,"author_title":13,"author_photo":407,"author_bio":408,"author_linkedin":409,"slices":411,"meta_title":393,"meta_description":394},"NACLS? Ain't nobody got time for that!","In this blogpost, Adam will try to convince you to implement AWS NACL as additional layer of network protection. He will go through some basics, present some best practices that you could leverage and in the end show how easy it is to implement NACLs in Terraform.",{"dimensions":396,"alt":393,"copyright":13,"url":398,"id":399,"edit":400},{"width":397,"height":397},800,"\u002F_prismic-media\u002Fe69afffe11590ca5-cckfFJmk4egWIJHY_nacls-blogpost.png","cckfFJmk4egWIJHY",{"x":17,"y":17,"zoom":18,"background":19},"2022-11-10",6,"Blogs",{},[],[],{},[],{"link_type":410},"Any",[412,429,464,498,565,610,630,640,654,665,673,684],{"variation":413,"version":414,"items":415,"primary":416,"id":427,"slice_type":428,"slice_label":13},"default","initial",[],{"body":417},[418,423],{"type":419,"text":420,"spans":421,"direction":422},"heading3","Introduction",[],"ltr",{"type":424,"text":425,"spans":426,"direction":422},"paragraph","Every engineer that once created EC2 must have stumbled across Security Groups. They're used asstatefulhost firewalls to limit access to EC2 instance, Load balancers and other AWS Compute components. If you ever created EC2 you must have modified at least one Security Group rule. However what about AWS Network Access Control Lists (NACLs)? They're a little bit hidden in the background, forgotten, often omitted on purpose, waiting for you to be used as part of your Network Defense in Depth strategy. Let me walk you through and show how they can be used together with Security Groups to increase the security posture of your VPC and AWS environment.",[],"rich_text$5ce00efc-993b-4506-ab8d-752472921106","rich_text",{"variation":413,"version":414,"items":430,"primary":431,"id":463,"slice_type":428,"slice_label":13},[],{"body":432},[433,436,443,449,452],{"type":419,"text":434,"spans":435,"direction":422},"NACLs - the basics",[],{"type":424,"text":437,"spans":438,"direction":422},"Let's start with the basics first. AWS NACLs are VPC's security control that act as stateless firewalls that are associated with subnets and control inbound and outbound traffic. They're supposed to supplement Security Groups and should be treated as an additional layer of security, not the only one. As opposed to Security Groups that are stateful, NACLS are stateless, which means you have to do define both incoming and outgoing rules to allow traffic to go through.",[439],{"start":440,"end":441,"type":442},129,136,"strong",{"type":424,"text":444,"spans":445,"direction":422},"Because they are assigned to a subnet they control traffic for all resources associated with that subnet. By default VPCc come with Default NACLs that allow ALL incoming and outgoing traffic. This NACL can be modified and additional rules can be added. Contrary to default NACLs when you create a custom one it will deny both incoming and outgoing traffic until you add proper rules.",[446],{"start":447,"end":448,"type":442},157,160,{"type":424,"text":450,"spans":451,"direction":422},"Every subnet must have a NACL associated. If you don't associate one the default one will be associated automatically for you. Each subnet can have only one NACL, however every NACL can be associated with many subnets.",[],{"type":424,"text":453,"spans":454,"direction":422},"Everything (almost?) in AWS comes with a limit, so do the NACLs. The default maximum number of NACLs per VPC is 200 and 20 inbound and 20 outbound rules per NACL (note: ipv4 and ipv6 rules are counted separately). Those are soft limits and can be increased by contacting with AWS Support",[455],{"start":456,"end":457,"type":458,"data":459},276,287,"hyperlink",{"link_type":460,"url":461,"target":462},"Web","https:\u002F\u002Fdocs.aws.amazon.com\u002Fvpc\u002Flatest\u002Fuserguide\u002Famazon-vpc-limits.html#vpc-limits-nacls","_blank","rich_text$41aebdc9-51b4-4d5d-b447-c2c988473d70",{"variation":413,"version":465,"items":466,"primary":467,"id":496,"slice_type":497,"slice_label":13},"",[],{"eyebrow":13,"heading":468,"body":469,"cta_label":13,"cta_link":473,"aside_type":474,"aside_image":475,"aside_video":483,"aside_video_poster":485,"aside_video_reduced_motion":486,"aside_video_url":13,"aside_embed":487,"pardot_form_url":13,"form_submit_label":13,"form_variant":488,"form_heading":13,"redirect_on_success":489,"theme":491,"overlay_pattern":492,"background_continuation":493,"media_position":494,"aside_vertical_align":495},[],[470],{"type":424,"text":471,"spans":472},"Overview of AWS NACL",[],{"link_type":410},"Image",{"dimensions":476,"alt":479,"copyright":13,"url":480,"id":481,"edit":482},{"width":477,"height":478},991,1069,"Diagram of AWS VPCs, subnets and NACLs","\u002F_prismic-media\u002F19d56f1be94f70e3-rlF-Z65L5trMToYT_d9a492d3-cab5-422c-8293-152843e.png","rlF-Z65L5trMToYT",{"x":17,"y":17,"zoom":18,"background":19},{"link_type":484},"Media",{},{},{},"Contact (default)",{"link_type":490},"Document","Light","None","Solid color (no gradient)","Right","Top of section","content_block$1d61f0da-ad2d-4d3a-8976-530d3c5d5ed9","content_block",{"variation":413,"version":414,"items":499,"primary":500,"id":564,"slice_type":428,"slice_label":13},[],{"body":501},[502,505,508,511,515,518,521,524,527,530,533,536,539,542,550,553,556],{"type":419,"text":503,"spans":504,"direction":422},"Rules",[],{"type":424,"text":506,"spans":507,"direction":422},"Each NACL consists of an ordered list of rules. Rules are evaluated in descending order. When traffic is matched the evaluation stops, regardless of the action taken.",[],{"type":424,"text":509,"spans":510,"direction":422},"Each ruleset can have the following:",[],{"type":512,"text":513,"spans":514,"direction":422},"list-item","Rule Number",[],{"type":512,"text":516,"spans":517,"direction":422},"Type",[],{"type":512,"text":519,"spans":520,"direction":422},"Protocol",[],{"type":512,"text":522,"spans":523,"direction":422},"Port Range",[],{"type":512,"text":525,"spans":526,"direction":422},"Source (inbound) \u002F Destination (outbound)",[],{"type":512,"text":528,"spans":529,"direction":422},"Action",[],{"type":512,"text":531,"spans":532,"direction":422},"Comment",[],{"type":424,"text":534,"spans":535,"direction":422},"Comment is optional, others are mandatory.",[],{"type":424,"text":537,"spans":538,"direction":422},"The Rule number must be between 1 and 32766.",[],{"type":424,"text":540,"spans":541,"direction":422},"Type is the type of the traffic, for example it can be SSH, HTTP, or All IPV4 Traffic.",[],{"type":424,"text":543,"spans":544,"direction":422},"Protocol is defined as in IANN standard",[545],{"start":546,"end":547,"type":458,"data":548},26,39,{"link_type":460,"url":549,"target":462},"http:\u002F\u002Fwww.iana.org\u002Fassignments\u002Fprotocol-numbers\u002Fprotocol-numbers.xhtml",{"type":424,"text":551,"spans":552,"direction":422},"Port range is the usual TCP\u002FUDP port or port range.",[],{"type":424,"text":554,"spans":555,"direction":422},"As Source\u002FDestination you can specify CIDR.",[],{"type":424,"text":557,"spans":558,"direction":422},"Action can be either Allow or Deny.",[559,561],{"start":560,"end":546,"type":442},21,{"start":562,"end":563,"type":442},30,34,"rich_text$556f328f-c4d4-4d50-964b-8d929a7fd26e",{"variation":413,"version":414,"items":566,"primary":567,"id":609,"slice_type":428,"slice_label":13},[],{"body":568},[569,572,578,581,585,588,591,594,597,600,603],{"type":419,"text":570,"spans":571,"direction":422},"Best Practices",[],{"type":424,"text":573,"spans":574,"direction":422},"The one of the biggest advantages of NACL rules is that they can be used to block incoming and outgoing traffic for specific IP address in response to attack or other corporate or regulatory requirements. This cannot be achieved using Security Groups, as you can only allow traffic and not block.",[575],{"start":576,"end":577,"type":442},210,216,{"type":424,"text":579,"spans":580,"direction":422},"Below you can find an open list of best practices that you can follow to implement NACLs in your environment:",[],{"type":582,"text":583,"spans":584,"direction":422},"o-list-item","Rules have to be ordered from 1 to 32766. Instead of using sequential numbering you can leave a gap of at least 50 between each rule. This way it will be easier to add more rules later between already existing rules. Remember rules are evaluated in order!",[],{"type":582,"text":586,"spans":587,"direction":422},"Using Default NACLs should be avoided.",[],{"type":582,"text":589,"spans":590,"direction":422},"You should be as specific as possible in defining your rules, eg. avoid 0.0.0.0\u002F0 rules or other broad CIDR ranges.",[],{"type":582,"text":592,"spans":593,"direction":422},"Avoid rules with All ports for incoming rules.",[],{"type":582,"text":595,"spans":596,"direction":422},"Remember that NACLs are stateless so define outgoing rules. For that you could use ephemeral port ranges: 5.1. For AWS ELBs 1024-65535 5.2. For Linux servers 32768-61000 5.3. For Windows 49152-65535 5.4. For NAT Gateway and Lambda 1024-65535",[],{"type":582,"text":598,"spans":599,"direction":422},"Allow SSH (TCP 22) and RDP (TCP\u002FUDP 3389) traffic only from your corporate network",[],{"type":582,"text":601,"spans":602,"direction":422},"It's good to keep your rules documented for audit purpose and other engineers. Keep the comment brief but explain the reason for each rule",[],{"type":582,"text":604,"spans":605,"direction":422},"Remember about limits!",[606],{"start":607,"end":560,"type":458,"data":608},15,{"link_type":460,"url":461,"target":462},"rich_text$cd87dac8-451f-4f12-9fa2-d24685723405",{"variation":413,"version":414,"items":611,"primary":612,"id":629,"slice_type":428,"slice_label":13},[],{"body":613},[614,617],{"type":419,"text":615,"spans":616,"direction":422},"NACL and NAT Gateway",[],{"type":424,"text":618,"spans":619,"direction":422},"If you use NAT Gateways to NAT the traffic from your private networks you might see some strange logs in VPC flow logs. At first glance it might looks like the NAT gateway is accepting traffic from public internet. This could lead to potentially a lot of false positive alerts triggered in your SOC. NAT Gateway will never accept traffic from public internet, however there is one reason that it might look like it does. If you use default NACL or permit all inbound traffic in NACL that is associated with the same subnet as your NAT Gateway the packets will be accepted by NACL, recorded by VPC flow logs but dropped by NAT Gateway. As you cannot associate Security Group with NAT Gateway in order to block such traffic (for example from bots scanning the whole internet all the time) the only way would be to not allow any unnecessary traffic in NACL. If you want to check that in fact this is the case, you can use below query for Cloudwatch Insights:",[620,623,626],{"start":621,"end":622,"type":442},317,322,{"start":624,"end":625,"type":442},642,648,{"start":627,"end":628,"type":442},812,815,"rich_text$a7db11cc-485c-49f7-9566-5d5a5a3b01fa",{"variation":413,"version":414,"items":631,"primary":632,"id":638,"slice_type":639,"slice_label":13},[],{"language_label":13,"code":633},[634],{"type":635,"text":636,"spans":637},"preformatted","filter (dstAddr like 'IP_OF_NAT_GW' and srcAddr like 'PUBLIC_IP')\n| stats sum(bytes) as bytesTransferred by srcAddr, dstAddr\n| limit 10",[],"code_block$21b8697b-5dcd-4999-855f-0f6cf02344ab","code_block",{"variation":413,"version":414,"items":641,"primary":642,"id":653,"slice_type":428,"slice_label":13},[],{"body":643},[644],{"type":424,"text":645,"spans":646},"if the query returns only traffic from PUBLIC_IP to IP_OF_NAT_GW and not from other way around it means that packets were dropped by NAT gateway.",[647,650],{"start":547,"end":648,"type":649},48,"em",{"start":651,"end":652,"type":649},52,64,"rich_text$0833a29f-5f28-443b-844c-5e06b9d7c775",{"variation":413,"version":414,"items":655,"primary":656,"id":664,"slice_type":428,"slice_label":13},[],{"body":657},[658,661],{"type":419,"text":659,"spans":660,"direction":422},"IaC",[],{"type":424,"text":662,"spans":663,"direction":422},"If you love IaC as we do at FORM3, here is how you can implement NACLs in Terraform:",[],"rich_text$7917cc32-c751-487b-93bf-7efbaab852d9",{"variation":413,"version":414,"items":666,"primary":667,"id":672,"slice_type":639,"slice_label":13},[],{"language_label":13,"code":668},[669],{"type":635,"text":670,"spans":671},"# Network ACL definition\nresource \"aws_network_acl\" \"bar\" {\n  vpc_id = aws_vpc.foo.id\n  \n  tags = {\n    \"Name\"        = \"bar\"     \n    \"Description\" = \"NACL for public subnets requiring SSH access and outgoing HTTPS traffic\"\n  }\n}\n\n#NACL subnet association\nresource \"aws_network_acl_association\" \"main\" {\n  network_acl_id = aws_network_acl.bar.id\n  subnet_id      = aws_subnet.main.id\n}\n\n# This rule allows inbound SSH access from corporate CIDR\nresource \"aws_network_acl_rule\" \"bar1\" {\n  network_acl_id = aws_network_acl.bar.id\n  rule_number    = 50\n  egress         = false\n  protocol       = \"tcp\"\n  rule_action    = \"allow\"\n  cidr_block     = \"192.168.1.0\u002F24\"\n  from_port      = 22\n  to_port        = 22\n}\n\n# This rule allows return traffic on the ephemeral port range to corporate CIDR\nresource \"aws_network_acl_rule\" \"bar3\" {\n  network_acl_id = aws_network_acl.bar.id\n  rule_number    = 50\n  egress         = true\n  protocol       = \"tcp\"\n  rule_action    = \"allow\"\n  cidr_block     = \"192.168.1.0\u002F24\"\n  from_port      = 32768\n  to_port        = 61000\n}\n\n# This rule allows outgoing traffic on https port to the different subnet\nresource \"aws_network_acl_rule\" \"bar4\" {\n  network_acl_id = aws_network_acl.bar.id\n  rule_number    = 100\n  egress         = true\n  protocol       = \"tcp\"\n  rule_action    = \"allow\"\n  cidr_block     = \"192.168.2.0\u002F24\" #Subnet CIDR\n  from_port      = 443\n  to_port        = 443\n}",[],"code_block$2f21010a-be8e-4508-9be5-6a2fbdc001b1",{"variation":413,"version":414,"items":674,"primary":675,"id":683,"slice_type":428,"slice_label":13},[],{"body":676},[677,680],{"type":419,"text":678,"spans":679,"direction":422},"Conclusions",[],{"type":424,"text":681,"spans":682,"direction":422},"Using AWS NACLs can increase the general security posture of AWS VPC and the whole environment. It should be treated as an additional security control implemented alongside Security Groups. It's not that hard and can also greatly reduce the amount of false positive alerts and reduce unnecessary traffic.",[],"rich_text$355d8220-1196-440e-bef2-6e0bc7072361",{"variation":413,"version":414,"items":685,"primary":686,"id":702,"slice_type":428,"slice_label":13},[],{"body":687},[688,690,695],{"type":419,"text":52,"spans":689,"direction":422},[],{"type":512,"text":691,"spans":692,"direction":422},"Quotas",[693],{"start":17,"end":402,"type":458,"data":694},{"link_type":460,"url":461,"target":462},{"type":512,"text":696,"spans":697,"direction":422},"Control traffic to subnets using Network ACLs",[698],{"start":17,"end":699,"type":458,"data":700},45,{"link_type":460,"url":701,"target":462},"https:\u002F\u002Fdocs.aws.amazon.com\u002Fvpc\u002Flatest\u002Fuserguide\u002Fvpc-network-acls.html","rich_text$4302df4a-3a06-4ff6-bdf2-3ad60e53f35a",1788466508443]