Description
An AWS Network Firewall design must route traffic requiring inspection through firewall endpoints. A firewall resource or matching VpcId alone does not apply inspection.
Potential impact
Traffic that bypasses the firewall may avoid the intended inspection and blocking policies.
Remediation
Configure the firewall, policy, subnets and routing in both directions for the chosen distributed or centralized design. A separate firewall in every VPC is not always necessary.
Examples
The excerpts only correct the reference to the VPC that hosts the firewall. Configure firewall subnets and traffic routes separately.
Before
yaml
Resources:
myVPC1:
Type: AWS::EC2::VPC
Properties:
CidrBlock: 10.0.0.0/16
SampleFirewall:
Type: AWS::NetworkFirewall::Firewall
Properties:
FirewallPolicyArn: !Ref SampleFirewallPolicy
VpcId: !Ref anotherVPC
After
yaml
Resources:
myVPC1:
Type: AWS::EC2::VPC
Properties:
CidrBlock: 10.0.0.0/16
SampleFirewall:
Type: AWS::NetworkFirewall::Firewall
Properties:
FirewallPolicyArn: !Ref SampleFirewallPolicy
VpcId: !Ref myVPC1