An instance-level virtual firewall applied to EC2 and similar resources.
It's whitelist-based, denying all inbound traffic by default, and behaves statefully (return traffic is automatically allowed). Understanding how it differs from a network ACL is important.
© 2026 ITBGM