Security groups in a VPC is basically used to specify which traffic is allowed to or from an Amazon EC2 instance. Network ACLs operate at the subnet level that is used to evaluate traffic entering and exiting a subnet. Network ACLs is used to set both Allow and Deny rules. Network ACLs can not filter traffic between instances present in the same subnet.