{"id":18105,"date":"2026-09-29T22:53:07","date_gmt":"2026-09-30T04:53:07","guid":{"rendered":"https:\/\/www.supportpro.com\/blog\/?p=18105"},"modified":"2026-09-29T22:54:19","modified_gmt":"2026-09-30T04:54:19","slug":"aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic","status":"publish","type":"post","link":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/","title":{"rendered":"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A network connection failing in AWS does not always mean the server is down. An EC2 instance can be healthy, the application can be running, and the route to the destination can exist, yet a connection can still be rejected somewhere along the network path.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two AWS features that frequently become part of this investigation are <strong>Security Groups<\/strong> and <strong>Network Access Control Lists (NACLs)<\/strong>. Although both are used to control network traffic, they have different scopes, rule behaviour, and troubleshooting requirements.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Knowing where each control operates can significantly reduce the time required to diagnose connectivity problems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Security Groups and NACLs Are Not the Same Firewall<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The easiest way to understand the difference is to look at what each one protects.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>Security Group<\/strong> is associated with a network interface and controls traffic for the resource using that interface.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>Network ACL<\/strong> is associated with a subnet and controls traffic entering or leaving that subnet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A simplified architecture looks like this:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Client<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;v<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Route<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;v<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Subnet<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;+&#8212;- Network ACL<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;v<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">EC2 Network Interface<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;+&#8212;- Security Group<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;v<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Operating System<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;v<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Application<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because these controls operate at different levels, a connection can pass one and still be stopped by the other.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How Security Groups Handle Traffic<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Security Groups are commonly used to define which resources can communicate with an EC2 instance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example, suppose a web server listens on TCP port 443. Its security group could allow HTTPS traffic from a load balancer or another trusted network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A rule might look like:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Protocol: TCP<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Port: 443<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Source: 10.10.1.0\/24<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Action: Allow<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security Groups are <strong>stateful<\/strong>. When an allowed connection is established, the return traffic does not require a separate rule simply to permit the response.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security Groups use allow rules. There is no explicit deny rule that can be added to a security group.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This makes them particularly useful for controlling access to individual workloads.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How Network ACLs Handle Traffic<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Network ACLs work at the subnet boundary rather than directly on an EC2 instance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A NACL can contain both allow and deny rules. Each rule has a number, and AWS evaluates matching rules in ascending numerical order.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rule 100 \u2192 Allow TCP 443 from 10.10.0.0\/16<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rule 200 \u2192 Deny TCP 443 from 0.0.0.0\/0<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Traffic matching rule 100 is allowed before AWS reaches rule 200.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NACLs are <strong>stateless<\/strong>. Allowing traffic in one direction does not automatically permit the response in the opposite direction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This distinction becomes important when troubleshooting TCP connections.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Scenario 1: The Security Group Is Missing the Application Port<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine an EC2 instance hosting an internal API on port 8080.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The server is running, but another EC2 instance receives:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Connection timed out<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first checks show that both servers are in the same VPC and that the route table contains the expected local route.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The destination security group contains rules for SSH and HTTPS but nothing for TCP 8080.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this situation, the security group is the access-control layer preventing the connection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The solution is to permit TCP 8080 from the appropriate source rather than opening the service to every IP address.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Scenario 2: The Security Group Allows Traffic, but the NACL Rejects It<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now consider the opposite situation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The destination security group allows the required port, but the subnet&#8217;s NACL contains a deny rule affecting the client network.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The security group cannot override the NACL.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The traffic must satisfy both controls.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This produces an important troubleshooting rule:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>An allow rule at one layer does not cancel a deny at another layer.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When a security group appears correct, move one level outward and inspect the NACL associated with the subnet.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Scenario 3: The Request Leaves, but the Response Does Not Return<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Stateless NACL behaviour becomes particularly visible with TCP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Suppose an EC2 instance initiates a connection to a service. The outbound request is permitted, but the response is blocked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because the NACL does not maintain connection state, the return traffic must satisfy the appropriate NACL rule in the opposite direction.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This is why NACL troubleshooting should never focus only on the initial request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Source \u2192 Destination<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Destination \u2192 Source<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Both directions matter.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security Groups simplify this situation because their stateful behavior allows return traffic for an established permitted connection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Scenario 4: The Correct Security Group Is Being Checked on the Wrong Interface<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Another common mistake is investigating a security group that is not actually controlling the traffic in question.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An EC2 instance can have more than one network interface, and security group associations are applied to network interfaces.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When troubleshooting, verify the actual interface involved:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">EC2 Instance<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;+&#8211; ENI<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;|<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;+&#8211; Security Group A<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;+&#8211; Security Group B<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Check the interface&#8217;s private IP address and attached security groups before modifying any rules.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This prevents unnecessary changes to unrelated security groups.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Scenario 5: NACL Rule Ordering Creates an Unexpected Denial<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Consider this configuration:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rule 90&nbsp; \u2192 Allow TCP 443 from 10.0.0.0\/16<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Rule 100 \u2192 Deny TCP 443 from 10.0.0.0\/16<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The first matching rule determines the result.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The later deny rule does not override the earlier allow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">When investigating a NACL, therefore, examine the complete rule set rather than looking for a single rule that appears to allow the connection.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>A Practical Investigation Process<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When an EC2 connection fails, avoid immediately changing firewall rules. Work through the network path in sequence.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Identify Both Endpoints<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Record:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Source IP<\/li>\n\n\n\n<li>Destination IP<\/li>\n\n\n\n<li>Source subnet<\/li>\n\n\n\n<li>Destination subnet<\/li>\n\n\n\n<li>VPC IDs<\/li>\n\n\n\n<li>Destination port<\/li>\n\n\n\n<li>Protocol<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">This establishes exactly what traffic you are investigating.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. Validate the Route<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check the route table associated with the source subnet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Confirm that the destination address has a valid route and that the selected target is correct.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If the route is missing, neither a Security Group nor a NACL change will solve the problem.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Inspect the Destination NACL<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Determine which NACL is attached to the destination subnet.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Review inbound rules and confirm that the connection is permitted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Then check the source subnet&#8217;s NACL for the return path.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. Inspect Security Groups<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Check the security groups attached to the relevant network interface.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For an inbound connection, verify that the destination allows the source and port.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For outbound traffic, verify the source-side rules as well.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>5. Check the Host<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">AWS networking may be working while the operating system blocks the connection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On Linux, useful checks include:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">ss -lntp<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">to determine whether the service is listening, and:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">nft list rule-set<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">or:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">iptables -L -n -v<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">to inspect host-level filtering.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>6. Test the Actual Service<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Testing the application port is more useful than relying exclusively on ICMP.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">nc -vz 10.0.2.25 8080<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For an HTTP service:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">curl -I http:\/\/10.0.2.25:8080<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These tests help distinguish a network filtering problem from an application problem.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Using VPC Flow Logs<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">When the configuration looks correct but traffic still fails, <strong>VPC Flow Logs<\/strong> can provide additional evidence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Flow logs can show information such as source and destination addresses, ports, protocols, and whether observed traffic was accepted or rejected.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They are especially useful when investigating intermittent connectivity or determining whether traffic is reaching the expected network interface.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, Flow Logs should be considered together with route tables, NACLs, Security Groups, host firewalls, and application logs.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>A Simple Way to Remember the Difference<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Think of the two controls this way:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security Group<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Can this resource communicate?&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Network ACL<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;\u2193<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">&#8220;Can this subnet accept or send this traffic?&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Security Groups provide <strong>stateful, resource-level filtering<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">NACLs provide <strong>stateless, subnet-level filtering with ordered allow and deny rules<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Neither replaces the other. Both can participate in determining whether a connection succeeds.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Conclusion<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Troubleshooting blocked traffic in <a href=\"https:\/\/www.supportpro.com\/blog\/secure-aws-organizations-prevent-unauthorized-account-changes\/\" target=\"_blank\" rel=\"noopener\">AWS r<\/a>equires understanding how Security Groups and Network ACLs work together. Although both control network access, their different scopes and rule behaviour mean that a connection can be permitted at one layer and blocked at another.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Start by verifying the route between the source and destination, then inspect the NACLs associated with both subnets and the Security Groups attached to the relevant network interfaces. Pay particular attention to NACL rule ordering, stateless return traffic, and the specific ports and IP addresses involved. If AWS network controls appear correct, continue investigating host-level firewalls, listening services, and application logs.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tools such as VPC Flow Logs, ss, nc, and curl can help narrow down where the connection is failing. Rather than making broad firewall changes, apply targeted rule adjustments and test connectivity after each change. A structured troubleshooting approach helps identify the actual source of blocked traffic, minimize unnecessary security changes, and maintain reliable communication across AWS workloads.<\/p>\n\n\n\n<div class=\"wp-block-media-text alignwide has-media-on-the-right is-stacked-on-mobile is-vertically-aligned-center has-white-background-color has-background\"><div class=\"wp-block-media-text__content\">\n<p class=\"has-large-font-size wp-block-paragraph\">Facing issues? <\/p>\n\n\n\n<p class=\"has-large-font-size wp-block-paragraph\">Our technical support<br>engineers can solve it. <\/p>\n\n\n\n<!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper\" id=\"hs-cta-wrapper-3350a795-db50-482f-9911-301930d1b1be\"><span class=\"hs-cta-node hs-cta-3350a795-db50-482f-9911-301930d1b1be\" id=\"hs-cta-3350a795-db50-482f-9911-301930d1b1be\"><!--[if lte IE 8]><div id=\"hs-cta-ie-element\"><\/div><![endif]--><a href=\"https:\/\/cta-redirect.hubspot.com\/cta\/redirect\/2725694\/3350a795-db50-482f-9911-301930d1b1be\" ><img decoding=\"async\" class=\"hs-cta-img\" id=\"hs-cta-img-3350a795-db50-482f-9911-301930d1b1be\" style=\"border-width:0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/2725694\/3350a795-db50-482f-9911-301930d1b1be.png\"  alt=\"Contact Us today!\"\/><\/a><\/span><script charset=\"utf-8\" src=\"https:\/\/js.hscta.net\/cta\/current.js\"><\/script><script type=\"text\/javascript\"> hbspt.cta.load(2725694, '3350a795-db50-482f-9911-301930d1b1be', {\"useNewLoader\":\"true\",\"region\":\"na1\"}); <\/script><\/span><!-- end HubSpot Call-to-Action Code -->\n<\/div><figure class=\"wp-block-media-text__media\"><img fetchpriority=\"high\" decoding=\"async\" width=\"904\" height=\"931\" src=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2022\/09\/Free-server-checkup.png\" alt=\"guy server checkup\" class=\"wp-image-12943 size-full\" srcset=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2022\/09\/Free-server-checkup.png 904w, https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2022\/09\/Free-server-checkup-291x300.png 291w, https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2022\/09\/Free-server-checkup-768x791.png 768w, https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2022\/09\/Free-server-checkup-585x602.png 585w\" sizes=\"(max-width: 904px) 100vw, 904px\" \/><\/figure><\/div>\n","protected":false},"excerpt":{"rendered":"<p>A network connection failing in AWS does not always mean the server is down. An EC2 instance can be healthy, the application can be running, and the route to the&hellip;<\/p>\n","protected":false},"author":39,"featured_media":18106,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[69],"tags":[],"class_list":["post-18105","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-aws"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs\" \/>\n\t<meta name=\"robots\" content=\"max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n\t<meta name=\"author\" content=\"Anjali Sindhu\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Server Management Tips | SupportPRO Blog\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic\" \/>\n\t\t<meta property=\"og:description\" content=\"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png\" \/>\n\t\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t\t<meta property=\"og:image:height\" content=\"960\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-30T04:53:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-30T04:54:19+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:title\" content=\"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#article\",\"name\":\"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic\",\"headline\":\"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic\",\"author\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/anjali-sindhuarmiasystems-com\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png\",\"width\":1920,\"height\":960,\"caption\":\"AWS Security Groups vs Network ACLs\"},\"datePublished\":\"2026-09-29T22:53:07-06:00\",\"dateModified\":\"2026-09-29T22:54:19-06:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#webpage\"},\"articleSection\":\"AWS\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.supportpro.com\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/aws\\\/#listItem\",\"name\":\"AWS\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/aws\\\/#listItem\",\"position\":2,\"name\":\"AWS\",\"item\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/aws\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#listItem\",\"name\":\"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#listItem\",\"position\":3,\"name\":\"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/category\\\/aws\\\/#listItem\",\"name\":\"AWS\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#organization\",\"name\":\"SupportPRO\",\"description\":\"SupportPRO Blog\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/\",\"telephone\":\"+18476076123\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/anjali-sindhuarmiasystems-com\\\/#author\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/anjali-sindhuarmiasystems-com\\\/\",\"name\":\"Anjali Sindhu\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/da6cc3f3b96370c2f86036087fb370994fcc9b1de6e808fa3cd8a0f62dd351e3?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Anjali Sindhu\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#webpage\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/\",\"name\":\"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic\",\"description\":\"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/anjali-sindhuarmiasystems-com\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/author\\\/anjali-sindhuarmiasystems-com\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#mainImage\",\"width\":1920,\"height\":960,\"caption\":\"AWS Security Groups vs Network ACLs\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\\\/#mainImage\"},\"datePublished\":\"2026-09-29T22:53:07-06:00\",\"dateModified\":\"2026-09-29T22:54:19-06:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/\",\"name\":\"Server Management Tips\",\"description\":\"SupportPRO Blog\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.supportpro.com\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic<\/title>\n\n","aioseo_head_json":{"title":"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic","description":"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs","canonical_url":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/","robots":"max-snippet:-1, max-image-preview:large, max-video-preview:-1","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#article","name":"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic","headline":"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic","author":{"@id":"https:\/\/www.supportpro.com\/blog\/author\/anjali-sindhuarmiasystems-com\/#author"},"publisher":{"@id":"https:\/\/www.supportpro.com\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png","width":1920,"height":960,"caption":"AWS Security Groups vs Network ACLs"},"datePublished":"2026-09-29T22:53:07-06:00","dateModified":"2026-09-29T22:54:19-06:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#webpage"},"isPartOf":{"@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#webpage"},"articleSection":"AWS"},{"@type":"BreadcrumbList","@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.supportpro.com\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/category\/aws\/#listItem","name":"AWS"}},{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/category\/aws\/#listItem","position":2,"name":"AWS","item":"https:\/\/www.supportpro.com\/blog\/category\/aws\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#listItem","name":"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#listItem","position":3,"name":"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic","previousItem":{"@type":"ListItem","@id":"https:\/\/www.supportpro.com\/blog\/category\/aws\/#listItem","name":"AWS"}}]},{"@type":"Organization","@id":"https:\/\/www.supportpro.com\/blog\/#organization","name":"SupportPRO","description":"SupportPRO Blog","url":"https:\/\/www.supportpro.com\/blog\/","telephone":"+18476076123"},{"@type":"Person","@id":"https:\/\/www.supportpro.com\/blog\/author\/anjali-sindhuarmiasystems-com\/#author","url":"https:\/\/www.supportpro.com\/blog\/author\/anjali-sindhuarmiasystems-com\/","name":"Anjali Sindhu","image":{"@type":"ImageObject","@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/da6cc3f3b96370c2f86036087fb370994fcc9b1de6e808fa3cd8a0f62dd351e3?s=96&d=mm&r=g","width":96,"height":96,"caption":"Anjali Sindhu"}},{"@type":"WebPage","@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#webpage","url":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/","name":"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic","description":"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.supportpro.com\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#breadcrumblist"},"author":{"@id":"https:\/\/www.supportpro.com\/blog\/author\/anjali-sindhuarmiasystems-com\/#author"},"creator":{"@id":"https:\/\/www.supportpro.com\/blog\/author\/anjali-sindhuarmiasystems-com\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png","@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#mainImage","width":1920,"height":960,"caption":"AWS Security Groups vs Network ACLs"},"primaryImageOfPage":{"@id":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/#mainImage"},"datePublished":"2026-09-29T22:53:07-06:00","dateModified":"2026-09-29T22:54:19-06:00"},{"@type":"WebSite","@id":"https:\/\/www.supportpro.com\/blog\/#website","url":"https:\/\/www.supportpro.com\/blog\/","name":"Server Management Tips","description":"SupportPRO Blog","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.supportpro.com\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Server Management Tips | SupportPRO Blog","og:type":"article","og:title":"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic","og:description":"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs","og:url":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/","og:image":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png","og:image:secure_url":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png","og:image:width":1920,"og:image:height":960,"article:published_time":"2026-09-30T04:53:07+00:00","article:modified_time":"2026-09-30T04:54:19+00:00","twitter:card":"summary","twitter:title":"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic","twitter:description":"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs","twitter:image":"https:\/\/www.supportpro.com\/blog\/wp-content\/uploads\/2026\/09\/AWS-Security-Groups-vs-Network-ACLs-Finding-the-Source-of-Blocked-Traffic.png"},"aioseo_meta_data":{"post_id":"18105","title":"AWS Security Groups vs NACLs: Troubleshooting Blocked Traffic","description":"Learn how to troubleshoot blocked AWS traffic by comparing Security Groups and NACLs, checking rule order, routing, return traffic, and VPC Flow Logs","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"Article","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":"2026-09-30 04:55:10","breadcrumb_settings":null,"limit_modified_date":false,"open_ai":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-09-30 04:42:46","updated":"2026-09-30 04:55:10","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.supportpro.com\/blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.supportpro.com\/blog\/category\/aws\/\" title=\"AWS\">AWS<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tAWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.supportpro.com\/blog"},{"label":"AWS","link":"https:\/\/www.supportpro.com\/blog\/category\/aws\/"},{"label":"AWS Security Groups vs Network ACLs: Finding the Source of Blocked Traffic","link":"https:\/\/www.supportpro.com\/blog\/aws-security-groups-vs-network-acls-finding-the-source-of-blocked-traffic\/"}],"_links":{"self":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts\/18105","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/users\/39"}],"replies":[{"embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/comments?post=18105"}],"version-history":[{"count":1,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts\/18105\/revisions"}],"predecessor-version":[{"id":18107,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/posts\/18105\/revisions\/18107"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/media\/18106"}],"wp:attachment":[{"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/media?parent=18105"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/categories?post=18105"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.supportpro.com\/blog\/wp-json\/wp\/v2\/tags?post=18105"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}