Description
AWS Network Firewall can provide additional VPC traffic inspection and filtering. It is not mandatory for every VPC; consider the required inspection level, existing security groups, network ACLs, and centralized inspection architecture.
Potential impact
Without the inspection path the workload needs, malicious or disallowed traffic may not be adequately controlled.
Remediation
If Network Firewall is needed, create the firewall policy and endpoints, then route the traffic to be inspected through those endpoints.
Examples
The examples show only the firewall resource association. Creating a firewall does not automatically inspect all traffic in the VPC.
Before
hcl
resource "aws_vpc" "example" {
cidr_block = "10.0.0.0/16"
}
After
hcl
resource "aws_vpc" "example" {
cidr_block = "10.0.0.0/16"
}
resource "aws_networkfirewall_firewall" "example" {
name = "example"
firewall_policy_arn = aws_networkfirewall_firewall_policy.example.arn
vpc_id = aws_vpc.example.id
subnet_mapping {
subnet_id = aws_subnet.example.id
}
tags = {
Tag1 = "Value1"
Tag2 = "Value2"
}
}