Process Flow - Stateful behavior of security groups
Incoming Packet Arrives
Check Security Group Rules
Is Incoming Allowed?
No→Drop Packet
Yes
Allow Incoming Packet
Record Connection State
Outgoing Response Packet Arrives
Check Connection State
Is Response Allowed?
No→Drop Packet
Yes
Allow Outgoing Packet
Security groups check incoming packets against rules, allow if matched, then remember the connection to allow related outgoing packets automatically.