Updating a firewall - Amazon Network Firewall
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Updating a firewall

To make changes to your firewall settings through the console, use the following procedure:


If your firewall update changes your stateful rule evaluation order type, you will experience an interruption of in-flight traffic through the firewall for a few seconds during the reset. This is the only type of update that has this effect. For more information about stateful rule evaluation order types, see Evaluation order for stateful rule groups.

To update a firewall
  1. Sign in to the Amazon Web Services Management Console and open the Amazon VPC console at https://console.amazonaws.cn/vpc/.

  2. In the navigation pane, under Network Firewall, choose Firewalls.

  3. In the Firewalls page, choose the name of the firewall that you want to edit. This takes you to the firewall's details page.

  4. Choose the tab Firewall details, then, in each section where you want to make changes, choose Edit and follow the console guidance to make your changes.

    • In the Details section, you can change the firewall description. The name is fixed after creation.

    • In the Associated policy and VPC section, you can add and remove Availability Zones and subnets and you can associate a different firewall policy. The VPC is fixed after creation.

    • In the Logging section, you can configure logging for alert and flow logs. For information about your logging options and costs, see Logging network traffic from Amazon Network Firewall.

    • In the Firewall tags section, you can change the tags assigned to the Amazon firewall resource. For information about tagging, see Tagging Amazon Network Firewall resources.

  5. Choose Save to save your changes and return to the firewall's detail page.