Overview

A network ACL that blacklist inbound and outbound traffic based on IP address(es).

The template creates the network access list (NACL) into an existing VPC, and requires the following details: 

  • VPC ID: Provide the VPC ID to create the NACL in.
  • NACL Rules: Click on 'Customize Rules' and enter the missing rule information (Source IP, Port number, Protocol, and Action) depending on the NACL template. 

See Related Items section for configuration templates to create a new VPC.

Configuration Templates

Items
5
Size
1.1 KB
Missing Parameters
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
  NetworkAcl:
    Type: 'AWS::EC2::NetworkAcl'
    Properties:
      VpcId: ''
  IngressRule0:
    Type: 'AWS::EC2::NetworkAclEntry'
    Properties:
      Egress: false
      NetworkAclId:
        Ref: NetworkAcl
      CidrBlock: ''
      Protocol: '-1'
      RuleNumber: '100'
      RuleAction: deny
  IngressRule1:
    Type: 'AWS::EC2::NetworkAclEntry'
    Properties:
      Egress: false
      NetworkAclId:
        Ref: NetworkAcl
      CidrBlock: 0.0.0.0/0
      Protocol: '-1'
      RuleNumber: '200'
      RuleAction: allow
  EgressRule0:
    Type: 'AWS::EC2::NetworkAclEntry'
    Properties:
      Egress: true
      NetworkAclId:
        Ref: NetworkAcl
      CidrBlock: ''
      Protocol: '-1'
      RuleNumber: '100'
      RuleAction: deny
  EgressRule1:
    Type: 'AWS::EC2::NetworkAclEntry'
    Properties:
      Egress: true
      NetworkAclId:
        Ref: NetworkAcl
      CidrBlock: 0.0.0.0/0
      Protocol: '-1'
      RuleNumber: '200'
      RuleAction: allow
Parameters: {}
Metadata: {}
Conditions: {}

Actions



 
* Required field

Sources and Documentation

Configuration Source: Native Feature