← AWS Advanced Networking: networks and production
13 / 18 · 100 MIN

Network Firewall: rules, scope and evidence

Demonstrate that the right sources traverse the right engines and the applied policy produces the expected result.

1. Follow the decision between engines

A firewall appearing in architecture does not demonstrate that every rule inspects every flow. In Network Firewall, the stateless engine acts first. A pass action passes the packet; forward_to_sfe sends it to the stateful engine. Before investigating an apparently ineffective domain rule, confirm the upstream action. Stateless priorities have two levels: policy groups first, then rules within each group, starting with lower numbers. Do not order all rules as though they belonged to one global list. In the local exercise, matches are supplied as fictional data; the objective is to visualize precedence without parsing packets or replacing the real engine. At handover, retain the expected decision sequence for permitted and prohibited traffic.

2. Define scope before discussing results

In a central inspection VPC, a spoke application can have the correct path while remaining outside HOME_NET. Review required source CIDRs and effective group variables. If group HOME_NET differs from policy, an omitted EXTERNAL_NET still inherits policy value; do not assume its complement was recalculated from the local change. For domains, the engine uses HTTPS SNI or HTTP Host without an external DNS lookup. An exact entry covers that name; a leading dot permits the domain and subdomains. This name comparison neither authenticates the server nor proves correspondence between IP and identity. If those requirements exist, identify additional controls and test every source from the relevant application process.

3. Avoid blocking before identification

Under default action order, pass is evaluated before drop even when drop has a lower priority number. Strict order permits explicit ordering but does not remove the need for application context. The initial SYN does not yet contain SNI. Drop all can prevent the handshake before an HTTPS rule can match. Choose defaults and rules that respect protocol sequence. Application drop established variants differ by direction: the bidirectional variant can block banners and control packets before pass; the server-directed variant preserves server-to-client TCP with its own limits. Do not transfer that exception to UDP DNS or ICMP. Mixing domain Allow groups with Alert under action order can also produce a drop before the expected alert.

4. Plan changes as shared state

A rule group can be referenced by several policies. Before updating it, identify consumers, dependent rules, and impact outside the ticket-owning project. Reserved capacity cannot be changed after creation; an increase may require a new group and reference migration. UpdateToken protects against concurrent changes. If stale, read current state, compare intent, and reapply only the reconciled change. Replacing just the token while sending an old object can erase another team work. DryRun validates the request and permissions without applying changes. After execution, IN_SYNC describes configuration, but the firewall is READY only when endpoints are ready too. Complete verification with representative traffic in each AZ.

5. Explain what logs can prove

Network Firewall traffic logs belong to the stateful engine. Traffic accepted directly by stateless can have metrics without appearing in those flow logs. Within netflow, each event represents one direction; to measure responses, find and correlate the reverse direction. Use firewall name, AZ, time, addresses, and ports to bound the investigation. Alerts depend on actions and configured logging; absence of an alert does not prove absence of traffic. TLS logs require configured TLS inspection and report that engine specific events. In metrics, distinguish DroppedPackets from rule actions, InvalidDroppedPackets from validation, and OtherDroppedPackets from other causes. Some series emit only nonzero values; do not turn a missing sample into universal proof of zero loss.

6. Recover without losing security intent

A mid-session interruption can remove initial context from the engine. Continue applies rules to subsequent traffic without that history; L7 rules may no longer match while other rules still act. Drop retains fail-closed behavior. Reject also blocks and sends a TCP rejection so the client can establish a new session. The choice is a requirements and recovery decision, not merely a way to reduce alerts. Rehearse client behavior, retries, idempotency, and batch reconciliation. To complete handover, associate each source with an allowed and a prohibited test, the applied version, per-AZ results, and an operational owner. An exception needs scope and a deadline; do not hide it in an aggregate availability dashboard.

# Local ordering illustration using precomputed matches, not a packet engine.
def first_action(groups, default="forward_to_sfe"):
 for group in sorted(groups, key=lambda g: g["priority"]):
 for rule in sorted(group["rules"], key=lambda r: r["priority"]):
 if rule["matches"]:
 return rule["action"]
 return default

a = {"priority": 5, "rules": [
 {"priority": 100, "matches": True, "action": "pass"}]}
b = {"priority": 10, "rules": [
 {"priority": 1, "matches": True, "action": "drop"}]}
assert first_action([b, a]) == "pass"
a["rules"][0]["matches"] = False
assert first_action([a, b]) == "drop"
b["rules"][0]["matches"] = False
assert first_action([a, b]) == "forward_to_sfe"
assert first_action([], default="drop") == "drop"
print("four ordering cases passed; no packets inspected")
IN PRACTICE

Group A with priority 5 and rule 100 can be evaluated before group B with priority 10 and rule 1. Group sequence precedes internal rule sequence.

Common pitfalls

Stateless pass treated as stateful pass; assumed EXTERNAL_NET; fresh token with stale object; absent logs treated as absent traffic.

Related topics: Inspection and symmetric routing · Concurrency in network pipelines

Take this idea with you

Scope, order, propagation and functional outcome need separate, consistent evidence.

Create account

Reference: Network Firewall packet processing · ANS-C01

AWS is a trademark of Amazon.com, Inc. or its affiliates. bigsavant.com is an independent preparation platform and is not affiliated with, associated with, sponsored, authorised or endorsed by AWS. Content and questions are original, are not official exam questions, and completing our tests does not award or guarantee any certification. Names are used only to identify the subject. All other trademarks belong to their respective owners.