All Services

Security & IAM

AWS Network Firewall

AWS Network Firewall provides managed, horizontally scaling stateless and stateful traffic inspection endpoints, firewall policies, rule groups, managed rules, domain filtering, TLS inspection, metrics, and logs for Amazon VPC networks.

Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with AWS Network Firewall.

AWS Network Firewall pricing and cost programs

Pricing model: Firewall endpoint and traffic usage

On-Demand
Available
Reserved Instances or reserved capacity
Not applicable
Savings Plans
Not applicable
Spot
Not applicable

Billing dimensions: Endpoint hours · Data processed · Advanced inspection features · NAT waiver conditions

Programs and modes: Stateful and stateless inspection · TLS inspection · Advanced inspection

Endpoint, processing, and advanced inspection charges depend on architecture and traffic path.

Free Tier: Service-specific — verify current offers

Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.

Official AWS pricing

Official AWS sources reviewed 2026-07-21.

Why implement AWS Network Firewall?

  • Provides managed network inspection without deploying and scaling third-party firewall appliance fleets.
  • Combines stateless packet rules, stateful Suricata-compatible rules, managed rule groups, domain lists, TLS inspection, and centralized Firewall Manager support.
  • Deploys zonal endpoints and exposes flow, alert, TLS, and CloudWatch telemetry for traffic analysis and policy tuning.

How to implement AWS Network Firewall

  1. Model ingress, egress, east-west, hybrid, DNS and encrypted flows; choose VPC-attached or transit-gateway-attached, centralized or distributed inspection; define availability, fail-open or fail-closed, latency, throughput, and cost objectives.
  2. Create dedicated firewall subnets and endpoints per required Availability Zone, build versioned stateless and stateful rule groups and policy defaults, enable encryption and logs, and automate configuration through infrastructure as code.
  3. Change route tables so both directions traverse the same intended endpoint, validate every flow and failure mode in a staging path, canary enforcement, and monitor drops, rejects, alerts, capacity, endpoint health, and route drift.

AWS Network Firewall best practices

  • Maintain symmetric routing: AWS Network Firewall requires forward and return traffic through the same firewall endpoint for stateful inspection to work correctly.
  • Route to the local Availability Zone endpoint where possible, avoid unsupported architectures, test rule evaluation order and default actions, and preserve a controlled recovery path from bad rules or routes.
  • Enable appropriate flow and alert logs, understand that pass rules may need an alert modifier to log, protect log destinations, review managed-rule updates, and centralize policy only after architecture validation.

AWS Network Firewall use cases and server impact

  • VPC ingress and egress filtering
  • Centralized transit inspection
  • Domain, intrusion-signature, and encrypted-traffic policy enforcement

Replaces self-managed network-firewall appliance fleets, while route architecture, rule correctness, TLS trust, logging, failure behavior, and application connectivity testing remain customer responsibilities.

Official implementation resources

Commonly paired AWS services