You need state to block only inbound originated sessions (i.e. the one way door to a private subnet).
You need state to block only inbound originated sessions (i.e. the one way door to a private subnet).