Welcome to Stateful vs Stateless Firewalls in Modern Cloud Networks. Understanding the fundamental mechanics of packet filtering is critical when designing Virtual Private Clouds (VPCs). Misconfiguring a firewall layer often leads to mysterious timeouts or glaring security holes.

1. Stateless Firewalls (Network ACLs)

Stateless firewalls, commonly implemented as Network Access Control Lists (NACLs) at the subnet level, operate purely on individual packets. They inspect the source IP, destination IP, source port, and destination port. They do not remember previous packets.

This means if you open Inbound Port 80 for web traffic, a stateless firewall will block the return traffic back to the client unless you also explicitly open Outbound ephemeral ports (usually 1024-65535). Because they don't track connections, they are incredibly fast and immune to state-exhaustion DDoS attacks.

2. Stateful Firewalls (Security Groups)

Stateful firewalls, like AWS Security Groups or Linux iptables/nftables, track the state of active network connections in a connection tracking (conntrack) table. They understand the TCP handshake (SYN, SYN-ACK, ACK).

If a stateful firewall allows an inbound connection on Port 443, it automatically allows the outbound return traffic for that specific connection, regardless of outbound rules. This makes them much easier to configure for developers.

3. The State Exhaustion Vulnerability

Because stateful firewalls must allocate RAM to track every active connection, they are vulnerable to SYN Flood attacks. An attacker sends millions of spoofed SYN packets, filling the conntrack table. Once full, the firewall drops all new legitimate connections. This is why edge DDoS mitigation often relies on stateless BGP scrubbing before traffic hits stateful cloud load balancers.

4. Defense in Depth Architecture

A robust cloud architecture utilizes both. Stateless NACLs are placed at the edge of the subnet as a coarse filter to drop obvious malicious traffic (e.g., blocking known botnet IP ranges) without consuming compute resources. Stateful Security Groups are attached directly to the network interfaces of the VMs for granular, application-specific access control.