Operates at the instance (interface level)
Operates at the subnet level
Supports allow rules only
Supports allow and deny rules
Evaluates all rules
Processes rules in order
Applies to an instance only if associated with a group
Automatically applies to all instances in the subnet it is associated with