π‘οΈ AWS Network Firewall Subnet Change Protection is not enabledπ’
- Contextual name: π‘οΈ Firewall Subnet Change Protection is not enabledπ’
- ID:
/ce/ca/aws/network-firewall/firewall-subnet-change-protection - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
RELIABILITY
Logicβ
- π§ prod.logic.yamlπ’
Similar Policiesβ
- AWS Security Hub: [NetworkFirewall.10] Network Firewall firewalls should have subnet change protection enabled
Descriptionβ
Descriptionβ
This policy identifies AWS Network Firewalls that do not have Subnet Change Protection enabled.
Rationaleβ
AWS Network Firewall deploys endpoints in specific subnets to inspect network traffic. If these subnets are modified or removed without proper coordination, the firewall may become unreachable, or VPC traffic routing may fail, resulting in service disruption or downtime.
Enabling Subnet Change Protection acts as a safeguard by preventing unintended modifications to the firewallβs subnet associations. Changes to the firewallβs network configuration require that the protection be explicitly disabled, ensuring that subnet updates are intentional and controlled.
Auditβ
This policy flags an AWS NetworkFirewall Firewall as
INCOMPLIANTif the Subnet Change Protection field is set to false.Firewalls that are not in READY
Statusare marked asINAPPLICABLE.
Remediationβ
Remediationβ
Enable Subnet Change Protection for the Firewallβ
To prevent accidental or unauthorized modifications to the firewallβs subnet associations, enable Subnet Change Protection.
From Command Lineβ
Run the following command to enable subnet change protection:
aws network-firewall update-subnet-change-protection \
--firewall-arn {{firewall-arn}} \
--subnet-change-protectionOnce enabled, any attempt to modify the firewallβs subnet associations requires that subnet change protection be explicitly disabled first.