Review the Network Firewall inspection path for a VPC

Route VPC traffic that needs inspection through the intended firewall path.

Description

An AWS Network Firewall design must route traffic requiring inspection through firewall endpoints. A firewall resource or matching VpcId alone does not apply inspection.

Potential impact

Traffic that bypasses the firewall may avoid the intended inspection and blocking policies.

Remediation

Configure the firewall, policy, subnets and routing in both directions for the chosen distributed or centralized design. A separate firewall in every VPC is not always necessary.

Examples

The excerpts only correct the reference to the VPC that hosts the firewall. Configure firewall subnets and traffic routes separately.

Before

yaml
Resources:
  myVPC1:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: 10.0.0.0/16

  SampleFirewall:
    Type: AWS::NetworkFirewall::Firewall
    Properties:
      FirewallPolicyArn: !Ref SampleFirewallPolicy
      VpcId: !Ref anotherVPC

After

yaml
Resources:
  myVPC1:
    Type: AWS::EC2::VPC
    Properties:
      CidrBlock: 10.0.0.0/16

  SampleFirewall:
    Type: AWS::NetworkFirewall::Firewall
    Properties:
      FirewallPolicyArn: !Ref SampleFirewallPolicy
      VpcId: !Ref myVPC1

References