Skip to main content
Cloud / AWS / Products / AWS Network Firewall - VPC Protection

AWS Network Firewall - VPC Protection

AWS Network Firewall provides managed network protection for VPCs with stateful inspection and intrusion prevention.

Security, Identity & Compliance
Pricing Model Pay-per-use: hourly rate per firewall endpoint per region/AZ plus data volume processed; add-ons such as TLS inspection or managed rule groups billed separately
Availability Available in many AWS regions, check regional availability
Data Sovereignty EU regions available
Reliability SLA as published by the provider SLA

What is AWS Network Firewall?

AWS Network Firewall is a stateful, managed firewall and intrusion detection/prevention service for Amazon VPC. It filters traffic at the perimeter of the VPC, including traffic to and from an internet gateway, NAT gateway, or over VPN or AWS Direct Connect. For stateful inspection, the service uses the open source IPS Suricata and supports Suricata-compatible rules.

Network Firewall can be used to allow traffic only to known AWS service domains or endpoints, enforce custom lists of known malicious domains, perform deep packet inspection on incoming and outgoing traffic, and detect and filter protocols such as HTTPS regardless of the port used. The service is supported by AWS Firewall Manager, which allows central management of firewalls across multiple accounts in AWS Organizations.

Core Features

  • Stateful Inspection: Connection tracking across the entire traffic flow
  • Intrusion Prevention: Suricata-compatible rules for deep packet inspection
  • Domain Filtering: Filtering based on SNI and HTTP host headers
  • TLS Inspection: Optional decryption and inspection of HTTPS traffic (billed separately)
  • AWS Firewall Manager: Central policy management across multiple accounts

Typical Use Cases

Central VPC Inspection: In hub-and-spoke architectures, Network Firewall filters traffic between VPCs and to the internet, with central policies simplifying compliance.

Malware Protection: AWS Managed Rules and partner-managed rule groups help detect known threat patterns; optional TLS inspection enables analysis of encrypted traffic as well.

Compliance Logging: Connections can be logged and streamed to destinations such as CloudWatch, S3, or Kinesis Data Firehose, for example for further processing in SIEM systems.

Benefits

  • Firewall functionality without managing your own infrastructure
  • Updatable rule sets via AWS Managed Rules and marketplace partners
  • Central management across multiple VPCs and accounts
  • Integration with AWS Organizations for multi-account management

Integration with innFactory

As an AWS Reseller, innFactory supports you with AWS Network Firewall: We help with network architecture design, Suricata rule development, and migration from on-premises firewalls.

Available Tiers & Options

IPS with AWS Managed Rules

Strengths
  • Suricata-compatible IPS rules
  • Automatic updates by AWS or marketplace partners
Considerations
  • Additional costs for managed rule groups or advanced threat protection

Typical Use Cases

VPC protection
Intrusion prevention
Traffic filtering
Network security

Technical Specifications

Deployment Firewall endpoints per Availability Zone within the VPC
Logging CloudWatch, S3, Kinesis Data Firehose
Protocols TCP, UDP, ICMP, plus protocol-based detection including HTTP/HTTPS
Rule formats Suricata-compatible, stateless (5-tuple) and stateful

Frequently Asked Questions

What is AWS Network Firewall?

AWS Network Firewall is a stateful, managed network firewall and intrusion detection/prevention service for VPCs. It filters traffic at the perimeter of the VPC, such as at an internet gateway, NAT gateway, or over VPN/Direct Connect, using the open source IPS Suricata for stateful inspection.

When should I use Network Firewall instead of Security Groups?

Network Firewall is suited for intrusion prevention with Suricata-compatible rules, domain-based filtering, central policies across multiple VPCs, and compliance requirements with central logging. Security Groups remain responsible for instance-level access control.

Which rule types are supported?

Network Firewall supports stateless rules for fast 5-tuple filtering and stateful rules that consider the context of an entire traffic flow. Stateful rules can also be written as Suricata-compatible rules for deep packet inspection.

How much does AWS Network Firewall cost?

An hourly rate applies per firewall endpoint (per region and Availability Zone), plus a charge per gigabyte of data processed. Add-ons such as TLS inspection, advanced threat protection, and managed rule groups from marketplace partners are billed separately. Current prices are listed on the official pricing page.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of AWS (official documentation). This page does not represent an offer by AWS.

AWS Cloud Expertise

innFactory is an AWS Reseller with certified cloud architects. We provide consulting, implementation, and managed services for AWS.

Comparable Products from Other Clouds

As a multi-cloud partner, we help you choose the right platform for your specific requirements.

Ready to start with AWS Network Firewall - VPC Protection?

Our certified AWS experts help you with architecture, integration, and optimization.

Schedule Consultation