You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

咨询:AWS网络访问控制列表(NACLs)运行在OSI模型哪一层?

AWS NACLs: Which OSI Layer Do They Operate On?

Hey there! Great question—this is one of those under-documented details that’s super useful to grasp once you’re digging beyond basic setup guides.

To answer directly: AWS Network Access Control Lists (NACLs) operate primarily at the OSI Layer 3 (Network Layer), with built-in support for Layer 4 (Transport Layer) filtering. Here’s a quick breakdown to make sense of this:

  • Layer 3 (Network Layer) core: NACLs are fundamentally IP-address focused. They filter traffic based on source and destination IPv4/IPv6 addresses—this is the core behavior of Layer 3 networking, as it deals with routing traffic between different networks.
  • Layer 4 (Transport Layer) granularity: Unlike strict Layer 3 devices, NACLs let you narrow down rules using source/destination port numbers and protocol types (like TCP, UDP, or ICMP). These are Layer 4 attributes, which adds precision beyond just blocking or allowing entire IP ranges.

A quick note on what NACLs don’t handle: they won’t filter based on Layer 2 details (like MAC addresses) or Layer 7 application-specific data (like HTTP request paths or user agents—you’d use AWS WAF for that kind of filtering).

If you’re comparing to security groups, both handle Layer 3/4 filtering, but the key difference is statefulness: NACLs are stateless (you have to explicitly allow return traffic in your rules), while security groups are stateful (return traffic is automatically permitted once you allow outbound).

内容的提问来源于stack exchange,提问作者Žilvinas Rudžionis

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 08:15:54