AWS Network Firewall: Flow-Based Control Improves Security

The managed, stateful network firewall and intrusion detection and prevention service is called AWS Network Firewall

The AWS Network Firewall API and AWS Management Console provide access to these functions

AWS Network Firewall makes use of Suricata, an open-source intrusion detection and prevention system (IDS/IPS)

Within the same VPC, traffic between subnets 10.0.1.0/24 and 10.0.2.0/24 is set up to pass via AWS Network Firewall for examination

Additionally, flushed flows are seen in the flow logs if you have AWS Network Firewall flow logs set up for the stateful engine of your firewall

Organizations can now monitor network traffic, respond quickly to security issues, and apply updated security policies to all active connections