Review Network Firewall use in the VPC

Choose VPC firewall controls for the traffic inspection you need.

Description

AWS Network Firewall can provide additional VPC traffic inspection and filtering. It is not mandatory for every VPC; consider the required inspection level, existing security groups, network ACLs, and centralized inspection architecture.

Potential impact

Without the inspection path the workload needs, malicious or disallowed traffic may not be adequately controlled.

Remediation

If Network Firewall is needed, create the firewall policy and endpoints, then route the traffic to be inspected through those endpoints.

Examples

The examples show only the firewall resource association. Creating a firewall does not automatically inspect all traffic in the VPC.

Before

hcl
resource "aws_vpc" "example" {
  cidr_block = "10.0.0.0/16"
}

After

hcl
resource "aws_vpc" "example" {
  cidr_block = "10.0.0.0/16"
}

resource "aws_networkfirewall_firewall" "example" {
  name                = "example"
  firewall_policy_arn = aws_networkfirewall_firewall_policy.example.arn
  vpc_id              = aws_vpc.example.id

  subnet_mapping {
    subnet_id = aws_subnet.example.id
  }

  tags = {
    Tag1 = "Value1"
    Tag2 = "Value2"
  }
}

References