Analyzing stateless rule groups in Amazon Network Firewall
Network Firewall can analzye stateless rule groups for rules that might adversely effect your firewall's functionality. For example, Network Firewall can identify rules that route traffic asymmetrically, which can impact the service's ability to properly process traffic. During analysis, the service includes any identfied rules in a list of analysis results. You can analyze your stateless rule groups and view the analysis results using the console or API.
The following table lists the types of rule behavior that Network Firewall analyzes your rule groups for, as well as the details about the cause and solution.
Rule behavior | Cause | Mitigation |
---|---|---|
Forwarding asymmetrically |
One or more stateless rules with the action |
Make sure that there's an existing return path. For example, if the rule allows traffic from source 10.1.0.0/24 to destination 20.1.0.0/24, you should allow return traffic from source 20.1.0.0/24 to destination 10.1.0.0/24. |
Contains TCP flags |
At least one stateless rule with
the action |
Prevent asymmetric routing issues caused by TCP flags by following these actions:
|