description AWS Network Firewall Overview
help AWS Network Firewall FAQ
How is AWS Network Firewall different from a security group or network ACL?
Security groups protect individual AWS resources, while network ACLs filter traffic at the subnet boundary. AWS Network Firewall is a managed inspection service deployed through VPC firewall endpoints and supports both stateless and stateful rule engines. [AWS documentation](https://docs.aws.amazon.com/network-firewall/latest/developerguide/what-is-aws-network-firewall.html)
What kinds of rules can AWS Network Firewall use?
Its stateful rules can use 5-tuple matching, domain lists, and Suricata-compatible intrusion-prevention rules. Stateless rule groups handle fast packet filtering before traffic reaches the stateful inspection engine. [AWS News Blog](https://aws.amazon.com/blogs/aws/aws-network-firewall-new-managed-firewall-service-in-vpc/)
How does traffic reach an AWS Network Firewall endpoint?
The firewall creates endpoints in selected VPC subnets, and route tables send traffic through those endpoints for inspection. A firewall policy then combines the stateless and stateful rule groups that determine whether matching flows are allowed or rejected. [AWS documentation](https://docs.aws.amazon.com/network-firewall/latest/developerguide/what-is-aws-network-firewall.html)
Does AWS Network Firewall replace AWS WAF or AWS Shield?
No. Network Firewall protects VPC traffic, while AWS WAF focuses on web requests and AWS Shield provides dedicated DDoS protection. A production architecture may use all three because they inspect different traffic paths and attack types. [AWS Network Firewall announcement](https://aws.amazon.com/blogs/aws/aws-network-firewall-new-managed-firewall-service-in-vpc/)
explore Explore More
Similar to AWS Network Firewall
ui.x_see_all arrow_forwardReviews & Comments
Write a Review
Be the first to review
Share your thoughts with the community and help others make better decisions.