Glossary

    AWS Network Firewall

    Network Security

    AWS Network Firewall is a managed firewall service that provides network traffic filtering for VPCs. It sits in its own subnet and inspects traffic passing through it.

    Capabilities

    • Stateful Inspection: track connection state for TCP, UDP, ICMP
    • Domain Filtering: allow or deny outbound traffic based on domain names (e.g., allow *.amazonaws.com only)
    • Intrusion Prevention (IPS): Suricata-compatible rules for deep packet inspection
    • TLS Inspection: decrypt and inspect HTTPS traffic (requires certificate)
    • Managed Rule Groups: AWS-curated threat intelligence rules

    Architecture Patterns

    • Centralized Inspection: deploy in a dedicated inspection VPC with Transit Gateway routing all traffic through it
    • Per-VPC Deployment: deploy firewall endpoints in each VPC for isolated inspection
    • East-West Traffic: inspect traffic between VPCs (lateral movement prevention)

    Toc Consulting: AWS Security & Cloud Architecture

    Securing your AWS estate?

    Our team helps engineering teams secure and architect AWS the right way: assessment in week one, a prioritized action plan in week two.