Perimeter protection: AWS WAF, Shield, Network Firewall and Firewall Manager
8 min read · about 1 h with practice3 quick checks≈3% of the testCore: Core: tested on most papers
Reading is free. Sign in to tick off lessons, keep your place and track your mastery.
Perimeter questions describe an attack, such as SQL injection, an HTTP flood, a volumetric DDoS or unapproved outbound traffic, and offer real security controls that each work at a different layer. To answer them, match the layer of the threat to the layer of the control, and then apply the qualifier. Expect two or three of these items per exam, often combined with CloudFront, ALB or multi-account details.
By the end you’ll be able to
Place AWS WAF web ACLs on CloudFront, ALB, API Gateway or AppSync with managed rule groups, rate-based rules, geo-match and IP sets
Distinguish Shield Standard (automatic L3/L4) from Shield Advanced (L7 support, DDoS response team, cost protection)
Choose AWS Network Firewall (stateful VPC-level inspection, domain filtering) versus security groups, NACLs and WAF
Enforce WAF, Shield and security-group policies across accounts with AWS Firewall Manager
What the exam asks
Block SQL injection, cross-site scripting (XSS), bad bots, abusive IP addresses or specific countries in front of a web application or API.
Automatically throttle an HTTP flood or brute-force login attempts.
Choose between Shield Standard and Shield Advanced for DDoS protection, including response-team access and cost protection.
Inspect or filter traffic inside or leaving a VPC, by domain name or with intrusion-prevention signatures.
Enforce the same firewall rules across many accounts, including accounts created later.
The first 3 of 9 cards for this topic. Sign in and finish the lesson to review them with spaced repetition.
PromptCard 1 of 3
Which resources can an AWS WAF web ACL be associated with?
Deploys and audits the controls above
“All accounts”, “new accounts automatically”
AWS WAF
A web ACL holds ordered rules. Each rule has an action: Allow, Block, Count, CAPTCHA or Challenge. You associate a web ACL with CloudFront distributions, Application Load Balancers, API Gateway REST APIs, AppSync GraphQL APIs, Cognito user pools, App Runner services, Verified Access instances and Amplify apps. You cannot attach one to a Network Load Balancer, an EC2 instance or a NAT gateway.
AWS Managed Rules include a core rule set for common exploits such as XSS, SQL database rules, known bad inputs and IP reputation lists. Bot Control and account takeover prevention are paid add-ons. For “protect against common exploits”, managed rules are the LEAST operational overhead answer.
Rate-based rules count requests per IP address (or per another key, such as a header) over a rolling window and block any source that goes over the limit. A scope-down statement can limit the rule to one path, such as /login.
Match conditions include IP sets, geographic match, string and regex matches, size constraints and labels.
Web ACLs for CloudFront are created in the Global (US East, N. Virginia) Region. A regional web ACL must be in the same Region as its ALB or API.
WAF logs can go to CloudWatch Logs, S3 or Amazon Data Firehose.
CloudFront geographic restrictions allow or block countries for the whole distribution with a single setting. Use WAF geo match when the country rule has to be combined with other conditions, such as applying to only one path.
AWS Shield
Shield Standard
Shield Advanced
Cost
Included automatically for every customer
Paid subscription with a one-year commitment
Protection
Common L3/L4 attacks such as SYN floods and UDP reflection
L3/L4 plus application-layer (L7) detection, with automatic mitigation through WAF rules
Support
None
24/7 Shield Response Team (needs Business or Enterprise Support) and proactive engagement
Extras
—
DDoS cost protection for scaling charges, advanced metrics, health-based detection
Resources
All AWS
CloudFront, Route 53 hosted zones, Global Accelerator, ALB and Classic Load Balancers, EC2 Elastic IP addresses (for example, an NLB’s Elastic IPs)
For automatic application-layer mitigation, the protected CloudFront distribution or ALB must have a WAF web ACL associated with it. Shield Advanced then manages rate-based rules inside that web ACL.
DDoS resilience is also an architecture pattern. Serve traffic through CloudFront and Route 53 at the edge. Put ALBs and Auto Scaling in front of instances in private subnets. Lock down origins: use origin access control (OAC) for S3, and a custom header or the CloudFront managed prefix list for ALBs.
AWS Network Firewall
AWS Network Firewall is a managed, highly available, stateful firewall for VPC traffic. You create firewall endpoints in dedicated subnets and update route tables so that traffic passes through them. It supports:
stateless rules and stateful 5-tuple rules
domain lists that match the HTTP Host header or the TLS SNI, used to allow-list outbound traffic
For many VPCs, build a central inspection VPC that is attached to a transit gateway, with appliance mode enabled on that attachment. East-west and egress traffic is then inspected in one place.
AWS Firewall Manager
Firewall Manager applies policies across an AWS Organizations organization. It can manage WAF, Shield Advanced, security groups (common groups, and audits for overly permissive rules), Network Firewall, DNS Firewall and supported third-party firewalls. It automatically covers new accounts and new resources that match a policy’s scope. It has three prerequisites:
Organizations with all features enabled
a Firewall Manager administrator account
AWS Config enabled in the accounts and Regions in scope
SCPs cannot do this job. They limit permissions, but they cannot create or attach a web ACL.
Worked examples
Exam technique
Name the layer. Payload words (SQL injection, XSS, headers, URI, bots, requests per IP) ⇒ WAF. Volume words (SYN flood, UDP reflection, DDoS) ⇒ Shield. Response team, cost protection or L7 DDoS help from experts ⇒ Shield Advanced.
Check the resource. If the entry point is an NLB or bare EC2 instances, WAF cannot attach. Look for Shield Advanced on the Elastic IP addresses, or for CloudFront or an ALB in front of HTTP traffic.
VPC traffic. Egress filtering by domain, IPS, or inspection between VPCs ⇒ Network Firewall.
Scope words. “Across all accounts” or “automatically for new accounts” ⇒ Firewall Manager.
Common mistakes
Quick recap
WAF protects HTTP front doors at layer 7 (CloudFront, ALB, API Gateway REST APIs, AppSync, Cognito, App Runner, Verified Access and Amplify) with managed rules, rate-based rules, IP sets and geo match.
CloudFront geo restriction applies to the whole distribution. A WAF geo match rule can be limited to one path.
Shield Standard is automatic and free for L3/L4 attacks. Shield Advanced adds L7 mitigation, a 24/7 response team and cost protection, and it covers Elastic IP addresses, Global Accelerator and Route 53.
Network Firewall gives stateful VPC inspection with domain lists and IPS, and is often centralized behind a transit gateway.
Firewall Manager enforces WAF, Shield, security group and Network Firewall policies across Organizations, and it needs AWS Config and an administrator account.