All Services

Security & IAM

AWS Firewall Manager

AWS Firewall Manager centrally deploys and audits supported network and application security policies across AWS Organizations accounts and resources, including WAF, Shield Advanced, security groups, network ACLs, Network Firewall, and Route 53 Resolver DNS Firewall.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Firewall Manager.

AWS Firewall Manager pricing and cost programs

Pricing model: Policy and account usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Policy scope · Accounts and Regions · Protected resources · Underlying security services

Programs and modes: WAF policies · Shield Advanced policies · Security group policies · Network Firewall policies

Firewall Manager fees are additional to the security services and resources managed by each policy.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS Firewall Manager?

  • Applies a common security baseline across accounts and automatically evaluates new in-scope accounts and resources.
  • Supports multiple protection types and policies with OU, account, resource-type, and tag-based scope.
  • Can report noncompliance before enforcement or automatically remediate supported resources according to the selected policy.

How to implement AWS Firewall Manager

  1. Integrate AWS Organizations and AWS Config as required, choose a delegated security administrator, inventory Regions and resources, and define ownership, exceptions, cleanup, and break-glass procedures.
  2. Create one policy per protection intent, choose precise accounts, OUs, resources and tags, define managed and custom controls, and start with monitoring or automatic remediation disabled where the policy supports it.
  3. Review compliant and noncompliant resources, validate impact in pilot OUs, enable remediation progressively, monitor Config and Firewall Manager status, and test account, resource, tag, and OU lifecycle changes.

AWS Firewall Manager best practices

  • Use a delegated administrator outside the Organizations management account, separate policies by purpose and risk, and keep scope definitions simple enough to audit.
  • Pilot before automatic remediation, understand what happens when a resource leaves scope, and document exceptions rather than using ambiguous tags or broad exclusions.
  • Create policies in every required Region, treat CloudFront as global where applicable, review new service capabilities and accounts, and alert on persistent noncompliance or failed remediation.

AWS Firewall Manager use cases and server impact

  • Organization-wide WAF baselines
  • Central Network Firewall and DNS Firewall policy
  • Security-group, network ACL, and Shield governance

Replaces custom cross-account firewall rollout and compliance controllers, while policy design, exception governance, application testing, network routing, and incident response remain yours.

Official implementation resources

Commonly paired AWS services