π‘οΈ AWS Network Firewall Delete Protection is not enabledπ’
- Contextual name: π‘οΈ Firewall Delete Protection is not enabledπ’
- ID:
/ce/ca/aws/network-firewall/firewall-delete-protection - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
RELIABILITY
Logicβ
- π§ prod.logic.yamlπ’
Similar Policiesβ
- AWS Security Hub: [NetworkFirewall.9] Network Firewall firewalls should have deletion protection enabled
Descriptionβ
Descriptionβ
This policy identifies AWS Network Firewalls that do not have Delete Protection enabled.
Rationaleβ
AWS Network Firewall often serves as a critical control point for network traffic entering or leaving a VPC. Accidental deletion of a firewall can result in significant operational and security risks, including:
- Traffic Disruption: If routing configurations continue to reference firewall endpoints that no longer exist, network traffic may be disrupted or fail entirely.
- Security Gaps: If the firewall is removed and traffic is allowed to bypass inspection due to routing behavior, network traffic may flow without enforcement, increasing exposure to malicious or unauthorized activity.
Enabling Delete Protection introduces an additional safeguard by requiring explicit action to disable the protection before a firewall can be deleted, reducing the risk of accidental or unauthorized removal.
Auditβ
This policy flags an AWS NetworkFirewall Firewall as
INCOMPLIANTif the Delete Protection field is set to false.... see more
Remediationβ
Remediationβ
Enable Delete Protection for the Firewallβ
To prevent accidental or unauthorized deletion, enable Delete Protection on the AWS Network Firewall.
From Command Lineβ
Run the following command to enable delete protection:
aws network-firewall update-firewall-delete-protection \
--firewall-arn {{firewall-arn}} \
--delete-protection-enabledOnce enabled, delete protection must be explicitly disabled before the firewall can be deleted.