A large enterprise has several applications deployed on Amazon EC2 instances within a single VPC. These applications frequently communicate with each other, but the current network configuration relies heavily on security groups, which have become complex and difficult to manage as the number of applications grows. The enterprise wants to improve its network security posture by implementing a more centralized and granular traffic inspection and filtering mechanism. The solution must provide visibility into inter-application traffic and allow for dynamic policy updates without modifying individual application security groups. Which AWS service should be used to achieve this?
- AVPC Flow Logs with Amazon GuardDuty.
- BAWS WAF (Web Application Firewall) on an Application Load Balancer.
- CNACLs (Network Access Control Lists) at the subnet level.
- DAWS Network Firewall.
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Network Firewall.
AWS Network Firewall is a fully managed network firewall service that allows you to deploy and manage network protections across all your Amazon VPCs. It provides centralized traffic inspection (L3-L7), granular filtering rules, intrusion prevention, and can be integrated with AWS Firewall Manager for policy enforcement across multiple accounts. This directly addresses the need for centralized, granular inspection and dynamic policy updates for inter-application traffic.
Why the other options are wrong
- A. VPC Flow Logs provide visibility into network traffic, and GuardDuty is a threat detection service. While useful for monitoring and detection, neither service provides active, preventative, centralized traffic inspection and filtering capabilities as requested.
- B. AWS WAF operates at Layer 7 (HTTP/S) and is typically integrated with Application Load Balancers or CloudFront to protect web applications. It is not designed for inspecting and filtering general inter-application network traffic within a VPC.
- C. NACLs are stateless and operate at the subnet level (L3/L4). While they offer some filtering, they are not suitable for granular, centralized, stateful inspection or dynamic policy updates across applications, and can become complex quickly.
AWS Network Firewall
AWS Network Firewall is a managed service that makes it easy to deploy essential network protections for all of your Amazon Virtual Private Clouds (VPCs). It provides stateful inspection, intrusion prevention, and web filtering.
- Fully managed network firewall service.
- Provides stateful inspection (L3-L7).
- Centralized deployment across VPCs via a firewall endpoint.
- Integrates with AWS Firewall Manager for multi-account policy management.
- Supports flexible rule-sets for granular control.
Memory trick: Network Firewall is the 'Guard Tower' for your VPC, inspecting all traffic entering and leaving.