AWS Network Firewall

C
C tier on Intrusion Detection and Prevention SoftwareScore 5.8 · #23 of 35
Android app
Not listed
Free plan
No
Paid plans from
$0.07/mo
Runs on
api, Web
aws.amazon.com
The AWS Network Firewall homepage

Summary

AWS Network Firewall is a managed service for deploying network protections across Amazon VPCs. Its stateful firewall can inspect packets deeply and apply rules based on IP addresses, ports, protocols, and traffic direction. It also supports filtering by HTTP headers, SNI, and domain, plus an explicit forward proxy for managing outbound internet traffic. AWS-managed intrusion prevention signatures and malicious-domain rule groups are included at no additional cost. TLS inspection can analyze encrypted traffic inside a VPC, with an additional hourly charge for Advanced Inspection. The service integrates with Transit Gateway, VPC, IAM, and CloudWatch, and AWS Firewall Manager can centrally manage policies across accounts and VPCs. Logs can go to Amazon S3, Kinesis, or CloudWatch. Capacity scales automatically, and the service supports high availability across Availability Zones. AWS states a 99.99% uptime commitment under its service-level agreement. It is cloud-based and costs include endpoint-hour and per-GB processing charges that vary by region and Availability Zone. AWS says it is not designed to mitigate volumetric denial-of-service attacks.

Who it is for

It suits organizations protecting VPC boundaries, filtering inbound or outbound traffic, or inspecting traffic between VPCs. Teams seeking centralized policy management across accounts can use AWS Firewall Manager with the service.

What is good

  • Supports deep packet inspection and traffic rules
  • Includes AWS-managed intrusion signatures
  • Scales capacity automatically across Availability Zones
  • Offers centralized policy management through Firewall Manager

What to know first

  • Not designed to mitigate volumetric denial-of-service attacks
  • Advanced Inspection has an additional hourly charge
  • Marketplace managed rules may add seller-set fees

Verdict

AWS Network Firewall combines traffic inspection, filtering, logging, and centralized policy options for VPC environments. Its stated limitation around volumetric denial-of-service attacks is important when evaluating protection needs.

AWS Network Firewall plans and pricing

All plans
Firewall endpoint $0.40/mo $0.395 for each hour the firewall endpoint is provisioned in US East (N. Virginia) Managed firewall endpoint aws.amazon.com · 21 Sept 2026
Traffic processing $0.07/mo $0.065 for 1 GB of data processed in US East (N. Virginia) Network Firewall data processing aws.amazon.com · 21 Sept 2026
Pay-as-you-go Not published Hourly per firewall endpoint, plus per-GB traffic processing; rates vary by region and Availability Zone. Pricing examples show $0.395 per endpoint-hour and $0.065 per GB. Advanced inspection and active threat defense may add charges · AWS Marketplace managed rules may cost extra aws.amazon.com · 30 Sept 2026

Compared on intrusion detection and prevention software

Free plan
Noaws.amazon.com

Facts

Purpose
AWS Network Firewall is a managed service for deploying network protections across Amazon VPCs.aws.amazon.com · 30 Sept 2026
Traffic controls
Its stateful firewall supports deep packet inspection and rules based on IP addresses, ports, protocols, and traffic direction.aws.amazon.com · 30 Sept 2026
Web filtering and proxy
It supports HTTP header, SNI, and domain filtering, and an explicit forward proxy for controlling outbound internet traffic.aws.amazon.com · 30 Sept 2026
Threat protection
AWS-managed intrusion prevention signatures and malicious domain rule groups are included at no additional cost.aws.amazon.com · 30 Sept 2026
Encrypted traffic
TLS inspection can analyze encrypted traffic within the VPC and has an additional hourly charge for Advanced Inspection.aws.amazon.com · 30 Sept 2026
AWS integrations
AWS identifies Transit Gateway, VPC, IAM, and CloudWatch as native service integrations.aws.amazon.com · 30 Sept 2026
Central management and logging
AWS Firewall Manager can centrally manage policies across accounts and VPCs, while alert and flow logs can be stored in Amazon S3, Kinesis, or CloudWatch.aws.amazon.com · 30 Sept 2026
Partner integrations
AWS Marketplace partners offer managed rule groups that can be deployed in Network Firewall policies, with additional seller-set fees.aws.amazon.com · 30 Sept 2026
Availability and scaling
The service automatically scales capacity and supports high availability across Availability Zones.aws.amazon.com · 30 Sept 2026
Support commitment
AWS states that Network Firewall has a 99.99% uptime commitment under its service-level agreement.aws.amazon.com · 30 Sept 2026
Notable limitation
AWS says Network Firewall is not designed to mitigate volumetric denial-of-service attacks.aws.amazon.com · 30 Sept 2026
Intended users
AWS describes use cases including protecting VPC boundaries, filtering inbound and outbound traffic, and inspecting traffic between VPCs.aws.amazon.com · 30 Sept 2026
Maker
Amazon states that its principal corporate offices are in Seattle, Washington, and that it was incorporated in 1994.ir.aboutamazon.com · 30 Sept 2026

Best AWS Network Firewall alternatives

See all 20

Where it ranks on Everything Xiaomi

Is AWS Network Firewall yours?

Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.

Sources