Loading controls...
Benchmark: Network Firewall
Description
This section contains recommendations for configuring Network Firewall resources.
Usage
Browse dashboards and select Network Firewall:
steampipe dashboard
Or run the benchmarks in your terminal:
steampipe check aws_compliance.benchmark.all_controls_networkfirewall
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share aws_compliance.benchmark.all_controls_networkfirewall
Controls
- Networkfirewall firewall should be in a VPC
- The default stateless action for Network Firewall policies should be drop or forward for fragmented packets
- The default stateless action for Network Firewall policies should be drop or forward for full packets
- Network Firewall policies should have at least one rule group associated
- Stateless network firewall rule group should not be empty