Abstract Stands for Access Control List Stateless, means return traffic must be explicitly allowed using separate rules Operate at a Subnet level