The ANS-C01 exam retires on December 31, 2026
You can still take and pass the exam until then — plan your exam date accordingly.
3.1.2. AWS Network Firewall
AWS Network Firewall provides fully managed, scalable network intrusion prevention, web filtering, and granular traffic inspection at the VPC level, centralizing network security for enterprises.
Scenario: A large enterprise needs to implement advanced network traffic inspection, intrusion prevention, and web filtering for all traffic entering and leaving its production VPC. They want a fully managed solution that scales automatically.
For network specialists, deploying and managing traditional network firewalls can be complex and costly. AWS Network Firewall simplifies this by offering a fully managed, highly available firewall directly within your VPC.
AWS Network Firewall is a fully managed network firewall service that provides network intrusion prevention, web filtering, and granular traffic inspection for your Amazon VPCs.
Key Features of AWS Network Firewall:
- Fully Managed: AWS manages the underlying infrastructure, scaling, and high availability of the firewall.
- Centralized Protection: Deploy a single firewall for an entire VPC or multiple VPCs through AWS Transit Gateway (TGW).
- Deep Packet Inspection: Inspects network traffic at multiple layers for malicious activity or policy violations.
- Intrusion Prevention System (IPS): Detects and prevents common exploits, malware, and network-based attacks.
- Web Filtering: Filters outbound traffic based on domain names or URL categories (e.g., block access to known malicious websites).
- Stateful Filtering: Filters traffic based on connection state (e.g., allowing established connections).
- Stateless Filtering: Filters traffic based on individual packets.
- Rules Engine: Define custom firewall rules based on IP addresses, ports, protocols, domain names, and even custom content.
- Integration with AWS Firewall Manager: Centrally manage firewall policies across multiple accounts in AWS Organizations.
- Centralized Egress Pattern: Spoke VPCs send
0.0.0.0/0to the transit gateway; the TGW routes it to the firewall endpoints in an inspection VPC; the firewall subnet's route table sends allowed traffic to a NAT gateway in a public subnet, whose route table points to the internet gateway. The firewall has no public IP and performs no NAT itself. Enable appliance mode on the inspection VPC's TGW attachment so both directions of a flow use the same AZ. - Domain Filtering vs. Other Controls: Stateful rule groups can allow or deny by domain (TLS SNI / HTTP Host) — e.g., allow only
*.ubuntu.comwith a default drop, the preventive control against exfiltration from instances with NAT access. Security groups (CIDRs, prefix lists, security group references) and NACLs (CIDRs only) cannot name an FQDN; Route 53 Resolver DNS Firewall blocks name lookups but not connections made straight to an IP. Malware scanning of web downloads is typically done by a third-party secure web proxy or appliance (often behind a Gateway Load Balancer). - Firewall Logging: Network Firewall can send alert logs (traffic matching stateful rules with drop or alert actions), flow logs and TLS logs to S3, CloudWatch Logs or Firehose. VPC Flow Logs on the firewall subnet show packets reaching the endpoint, not the firewall's decision; CloudTrail shows only API changes to the firewall.
- Third-party appliance fleets: next-generation firewalls you run yourself sit behind a Gateway Load Balancer in the same inspection VPC (the routing is in 2.2.2.3). Because every spoke reaches other spokes through the same Transit Gateway hub, the same inspection VPC also inspects east-west (VPC-to-VPC) traffic.
Practical Implementation: Network Firewall Deployment (Conceptual)
# Network Firewall is typically deployed in a dedicated "inspection VPC" or "DMZ VPC".
# Traffic is then routed through the Network Firewall endpoints using TGW or VPC route tables.
# 1. Create a Firewall Policy
aws network-firewall create-firewall-policy \
--firewall-policy-name MyFirewallPolicy \
--firewall-policy '{"StatelessDefaultActions":["aws:pass"],"StatelessFragmentDefaultActions":["aws:pass"],"StatefulRuleGroupReferences":[{"ResourceArn":"arn:aws:network-firewall:us-east-1:123456789012:stateful-rule-group/MyStatefulRuleGroup"}]}'
# 2. Create a Firewall (in a specific VPC and subnets)
aws network-firewall create-firewall \
--firewall-name MyVPCFirewall \
--firewall-policy-arn arn:aws:network-firewall:us-east-1:123456789012:firewall-policy/MyFirewallPolicy \
--vpc-id vpc-0abcdef1234567890 \
--subnet-mappings SubnetId=subnet-0a1b2c3d,SubnetId=subnet-0e4f5g6h
⚠️ Common Pitfall: Incorrectly configuring routing to direct traffic through the Network Firewall endpoints. If routes are not updated, traffic will bypass the firewall, rendering it ineffective.
Key Trade-Offs:
- Managed Service vs. Custom Firewall Appliance: Network Firewall is fully managed, reducing operational overhead but offering less granular control over the underlying OS than a self-managed firewall appliance on EC2.
Reflection Question: How does AWS Network Firewall, by providing fully managed network intrusion prevention, web filtering, and granular traffic inspection at the VPC level, fundamentally enable centralized network security and protect resources from advanced threats?