Remediation
Enable Subnet Change Protection for the Firewallβ
To prevent accidental or unauthorized modifications to the firewallβs subnet associations, enable Subnet Change Protection.
From Command Lineβ
Run the following command to enable subnet change protection:
aws network-firewall update-subnet-change-protection \
--firewall-arn {{firewall-arn}} \
--subnet-change-protection
Once enabled, any attempt to modify the firewallβs subnet associations requires that subnet change protection be explicitly disabled first.