Amazon Firewall Manager
AWS Firewall Manager is a security management service that allows you to centrally configure and manage firewall rules across your accounts and applications in AWS Organizations. It makes it easier to bring new applications and resources into compliance with security policies.
APIs
AWS Firewall Manager API
The AWS Firewall Manager API provides programmatic access to create and manage security policies, compliance status, and protection configurations for AWS WAF, Shield, and VPC s...
Capabilities
Amazon Firewall Manager Security Governance
Centrally manage WAF, Shield, Network Firewall, and security group policies across AWS accounts.
Run with NaftikoFeatures
Define and enforce WAF, Shield Advanced, Network Firewall, and security group policies from a single pane of glass across all AWS accounts.
Automatically remediate non-compliant resources so that new accounts and resources are always protected.
Manage security policies across hundreds of AWS accounts within an AWS Organization.
View policy compliance status per account and resource with detailed violation reports.
Group AWS resources by type for targeted policy application and management.
Apply policies to resources based on AWS resource tags for fine-grained scope control.
Deploy and manage third-party firewall appliances through AWS Marketplace with Firewall Manager.
Use Cases
Enforce standard WAF rule sets across all CloudFront distributions and ALBs organization-wide.
Mandate Shield Advanced protection for all internet-facing resources across accounts.
Audit and remediate overly permissive security group rules across EC2 and VPC resources.
Deploy and manage AWS Network Firewall across VPCs in multiple accounts from a central policy.
Monitor and report on firewall policy compliance for SOC 2, PCI DSS, and regulatory requirements.
Automatically apply security policies to new AWS accounts as they join the organization.
Integrations
Manage Firewall Manager policies across all accounts in the organization hierarchy.
Centrally create and deploy WAF rule groups and web ACLs across accounts.
Enable and manage Shield Advanced protection for all DDoS-sensitive resources.
Deploy centrally managed network firewall policies across VPCs.
Manage DNS Firewall rule groups for Route 53 Resolver across accounts.
Monitor compliance metrics and set alarms for non-compliant resources.
Send Firewall Manager compliance findings to Security Hub for centralized security posture management.
Control who can create, modify, and view Firewall Manager policies using IAM permissions.