Concept and mechanism
A security review should mark where each protection starts and ends. MACsec provides point-to-point protection on the supported segment without itself proving end-to-end application encryption. Direct Connect also does not automatically create an IPsec tunnel that a requirement may demand; combining it with Site-to-Site VPN is an option to design and validate. For ALB, HTTPS to the target provides an encrypted segment, but the load balancer does not validate the certificate presented by the target. Do not infer browser-like identity verification from that connection. Define the backend-identity requirement and the mechanism that actually satisfies it.
Guided application
Confirm endpoint-policy support for the specific service; an intention in a diagram is not an applied control. For DNSSEC, validate the trust chain and parent-domain DS support before enabling the child zone. Signing errors may initially affect only some clients because resolution paths and cache states differ. DNS Firewall adds another decision: in a VPC with an associated rule group, disabled fail open blocks queries it cannot evaluate. Enabling it may improve availability during that failure while accepting queries without expected evaluation. That change needs a risk decision with owners, duration, and reversal conditions rather than a universal recommendation to open or close.
An expired backend certificate can still be accepted by ALB. Review the identity requirement, not just the HTTPS label.
Common pitfalls
MACsec as end to end; private as encrypted; HTTPS as validated identity; undated fail open.
Related topics: Inspection, auditing, and retirement · Addressing, DNS, and connectivity
Write each guarantee’s scope and the decision when the control fails.
Reference: ANS-C01 domain 4 · ANS-C01