AWS_NF_6

Ensure Network firewall status is not FAILED

Description

The network firewall protects the availability zone where it resides. Make sure that the network firewall status is not FAILED, otherwise your VPC won’t be protected.

Remediation

From Portal:
1. Sign in to the AWS console
2. In the console, select the specific region
3. Navigate to the ‘AWS Network Firewall’ service.
4. In the left pane under ‘Network Firewall’ click on Firewall.
5. Select desired firewall and identify the ‘Firewall status’.

From Command Line:
You can identify the status of your network firewall by using the following CLI command:
“`
aws network-firewall describe-firewall –region REGION_NAME –firewall-name FIREWALL_NAME
“`

References:
1. https://docs.aws.amazon.com/network-firewall/latest/APIReference/API_FirewallStatus.html

Service

AWS Network Firewall

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!