AWS SAA – Lecture 35: Security Groups & Classic Ports Overview

Published on
Written by Henry Nguyen

Phase Verbs / Action Phrases

PhraseMeaning
regulate (access to)control which traffic is allowed through
authorize (an IP range)permit traffic from a specific address range
attach (to an instance)link a security group to an EC2 instance
reference (a security group)use another SG’s identity as a rule source
block (traffic)prevent it from reaching the instance

Technical Vocabulary

TermDefinition
Security GroupA virtual firewall attached to EC2 instances; contains only allow rules
Inbound trafficNetwork traffic coming from outside into the EC2 instance
Outbound trafficNetwork traffic going from the EC2 instance out to the internet
PortA numbered channel on a computer used for specific protocols (e.g., 80 for HTTP)
ProtocolRules for how data is transmitted (e.g., TCP, UDP)
IP rangeA range of IP addresses (e.g., 0.0.0.0/0 = all IPs; 1.2.3.4/32 = one IP)
CIDRIP address range notation (e.g., 10.0.0.0/24)
TimeoutWhen a connection attempt hangs with no response — usually a security group block
Connection refusedServer responded but rejected the request — app error, not firewall
VPCVirtual Private Cloud — network boundary within which security groups are scoped

Key Concepts

Security Group Behavior

  • Only contains allow rules (no explicit deny — unmatched traffic is denied automatically)
  • Rules specify: Type, Protocol, Port, Source (IP or Security Group)
  • 0.0.0.0/0 as source = allow from anywhere
  • Default: all inbound blocked, all outbound allowed

Security Group Scope

  • Locked to a region + VPC combination (can’t reuse across regions/VPCs)
  • Lives outside the EC2 instance — blocked traffic never reaches the instance
  • One security group can attach to multiple instances
  • One instance can have multiple security groups

Security Group Referencing

  • A rule can allow traffic from another security group (not just IPs)
  • Used with load balancers: allow SG-of-LB → SG-of-EC2
  • Great for decoupled services — no need to manage IP addresses

Debugging with Security Groups

SymptomCause
Timeout (connection hangs)Inbound rule is missing → security group is blocking
Connection refusedSecurity group allowed it, but app/service on EC2 has an error

Classic Ports You Must Know

PortProtocolUsed For
22SSHSecure Shell — log into Linux instances
22SFTPSecure File Transfer (uses SSH)
21FTPFile Transfer Protocol (unsecured)
80HTTPUnencrypted web traffic
443HTTPSEncrypted web traffic
3389RDPRemote Desktop Protocol — log into Windows instances

Exam Tips

  • Security groups = allow rules only (no deny rules)
  • Default = inbound blocked, outbound open
  • Timeout → security group issue; connection refused → app issue
  • One SG can be shared across multiple instances
  • Port 22 = SSH (Linux) | Port 3389 = RDP (Windows) — know both
  • Security groups can reference other security groups (very useful for load balancers)