A virtual firewall that controls traffic on a per-subnet basis.
Unlike a security group, it operates statelessly, requiring inbound and outbound traffic to each be explicitly allowed. Rules also being evaluated in numeric order is another design characteristic.
© 2026 ITBGM