Skip to main content

πŸ›‘οΈ AWS Network Firewall Policy is not associated with a rule group🟒

  • Contextual name: πŸ›‘οΈ Policy is not associated with a rule group🟒
  • ID: /ce/ca/aws/network-firewall/policy-rule-group-association
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: RELIABILITY

Logic​

Similar Policies​

Description​

Open File

Description​

This policy identifies AWS Network Firewall Policies that are not associated with at least one stateless or stateful rule group.

Rationale​

An AWS Network Firewall policy serves as a container for stateless and stateful rule groups. While the policy defines default actions, such as how traffic is handled when no rules match, the actual inspection, filtering, and enforcement logic is implemented within the rule groups themselves. A firewall policy without any associated rule groups provides minimal security value and may indicate an incomplete or misconfigured firewall setup, potentially allowing network traffic to pass without proper inspection or control.

Audit​

This policy flags an AWS NetworkFirewall Firewall Policy as INCOMPLIANT if it is not associated with at least one AWS Network Firewall Rule Group.

Firewall Policies that are not in ACTIVE Firewall Policy Status are marked as INAPPLICABLE.

Remediation​

Open File

Remediation​

Associate the Network Firewall Policy with a Rule Group​

To ensure effective traffic inspection and enforcement, associate the AWS Network Firewall policy with at least one stateless or stateful rule group.

From Command Line​

When updating a firewall policy, you must supply the current UpdateToken to avoid conflicting updates.

First, retrieve the current update token:

aws network-firewall describe-firewall-policy \
--firewall-policy-arn {{policy-arn}} \
--query UpdateToken \
--output text
Associate a Stateless Rule Group​
aws network-firewall update-firewall-policy \
--update-token {{update-token}} \
--firewall-policy-arn {{firewall-policy-arn}} \
--firewall-policy '{
"StatelessRuleGroupReferences": [
{
"ResourceArn": "{{stateless-rule-group-arn}}",
"Priority": 100
}
]
}'
Associate a Stateful Rule Group​
aws network-firewall update-firewall-policy \
--update-token {{update-token}} \

... [see more](remediation.md)

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό AWS Foundational Security Best Practices v1.0.0 β†’ πŸ’Ό [NetworkFirewall.3] Network Firewall policies should have at least one rule group associated1no data
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό System Configuration61no data
πŸ’Ό FedRAMP High Security Controls β†’ πŸ’Ό CM-2 Baseline Configuration (L)(M)(H)3137no data
πŸ’Ό FedRAMP Low Security Controls β†’ πŸ’Ό CM-2 Baseline Configuration (L)(M)(H)36no data
πŸ’Ό FedRAMP Moderate Security Controls β†’ πŸ’Ό CM-2 Baseline Configuration (L)(M)(H)337no data
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CA-9(1) Internal System Connections _ Compliance Checks43no data
πŸ’Ό NIST SP 800-53 Revision 5 β†’ πŸ’Ό CM-2 Baseline Configuration736no data