Asterrr's Handbook

Network controls

Security groups and network ACLs, ephemeral ports, AWS Network Firewall with Suricata rules and domain lists, Route 53 Resolver DNS Firewall, Gateway Load Balancer with third-party IDS/IPS, and egress filtering.

Exam tasks: 3.3 (network controls that permit or prevent traffic: security groups, network ACLs, Network Firewall; north/south and east/west protection)

The decision: does the control need to understand connections, names or payloads, and must it apply to one workload, one subnet, or every packet leaving the VPC?

Picking the control

Security groups vs network ACLs

Security groupNetwork ACL
Attached toNetwork interface (instance, ALB, RDS, Lambda in VPC, endpoint)Subnet
StateStateful: return traffic is allowed automaticallyStateless: you must allow return traffic explicitly
RulesAllow onlyAllow and deny
EvaluationAll rules together, most permissive winsNumbered, lowest first, first match wins
SourcesCIDR, prefix list, another security groupCIDR only
Default (new custom one)Deny all in, allow all outDeny all in and out. The VPC's default NACL allows everything
Best forLeast-privilege per tierCoarse subnet guardrails, blocking a specific CIDR fast
  • Reference security groups, not CIDRs, between tiers: the app tier allows 8443 only from the ALB's security group. It keeps working as instances scale.
  • Removing a security group rule doesn't cut tracked connections that are already open. They continue until they go idle (up to days for an established TCP session). Only untracked flows stop at once. To cut an attacker's live session immediately, add a NACL deny, because NACLs don't track connections.
  • Default quotas: 60 inbound and 60 outbound rules per security group, 5 security groups per interface (adjustable, but the product of the two is capped). NACLs have 20 rules per direction by default, adjustable to 40.
  • Security Group VPC Associations let you use one security group in several VPCs of the same account and Region, and shared security groups follow shared subnets across accounts.

Exam signal

"Block this one attacking IP range now, including sessions already open" is a NACL deny (or a WAF IP set at the edge). Security groups can't deny. "Only the load balancer may reach the instances" is a security group that references the load balancer's security group.

Ephemeral ports

A client picks a random high source port. Because NACLs are stateless, the reply to that port must be allowed in the NACL facing the client.

ClientEphemeral range it uses
Most Linux kernels32768–60999
Windows Server 2008 and later49152–65535
NAT gateway, ELB, Lambda1024–65535
  • For a web subnet, allow inbound 443 from 0.0.0.0/0 and outbound 1024–65535 to 0.0.0.0/0, or HTTPS replies never leave the subnet.
  • Instances in that subnet that call out (updates, APIs) also need inbound 1024–65535 for the replies.
  • In practice, allow 1024–65535 and add lower-numbered deny rules for specific ports you want blocked.

The NACL looks right but traffic fails

A NACL with inbound 443 allowed and outbound 443 allowed still breaks HTTPS: replies go to the client's ephemeral port, not to 443. When a question shows connections timing out after a NACL change, check the return-path ephemeral range first. Reachability Analyzer names the blocking rule.

AWS Network Firewall

A managed, stateful firewall and IPS that you place in the traffic path. It scales automatically and runs Suricata-compatible rules.

  • Deployment: firewall endpoints in dedicated subnets, one per AZ, with route tables sending traffic through them. Or attach the firewall natively to a transit gateway, where AWS manages the inspection VPC and you route with transit gateway route tables.
  • Stateless engine first: looks at single packets in priority order (like a NACL). Its actions are pass, drop, or forward to the stateful engine. Forward by default unless you have a reason not to.
  • Stateful engine second: understands flows and direction. Rule group types:
    • Domain list: allow or deny by HTTP Host header and TLS SNI, including wildcards like .example.org.
    • Standard stateful (5-tuple) rules, simpler than Suricata.
    • Suricata-compatible IPS rules: match on protocol fields, content and signatures, with pass, drop, reject and alert.
    • AWS managed threat signatures and domain lists (malware, botnet command and control, crypto mining).
  • Rule order: strict order evaluates rule groups in the priority you set and lets you define default actions like "drop established" for anything not explicitly passed. The older action order evaluates all pass rules, then drop, then alert. Use strict order for allow lists.
  • TLS inspection decrypts, inspects and re-encrypts traffic with certificates from ACM, for inbound and outbound flows. Without it, the firewall only sees SNI and certificate metadata, not the payload.
  • Logs: alert and flow logs (and TLS logs) to S3, CloudWatch Logs or Data Firehose.

A domain allow list without a default drop

Adding a domain list that allows .amazonaws.com and .github.com doesn't block anything else in action order mode, because the stateful default is to pass. Use strict order with a default action of drop established (or a deny-all rule last), or the allow list is decorative.

Route 53 Resolver DNS Firewall

  • Filters DNS queries that instances send to the VPC's Route 53 Resolver (now called Route 53 VPC Resolver). It stops DNS exfiltration and lookups of known-bad domains.
  • Rule groups associated with VPCs contain rules that reference domain lists (your own or AWS managed: malware, botnet C2, aggregate threats). Actions: ALLOW, ALERT, or BLOCK with NODATA, NXDOMAIN or an OVERRIDE answer.
  • DNS Firewall Advanced rules detect DNS tunneling and domain generation algorithm (DGA) patterns rather than fixed names.
  • Choose fail open (keep resolving if DNS Firewall is impaired) or fail closed per VPC.
  • It can't see queries sent straight to an outside resolver like 8.8.8.8. Block outbound 53 and 853 in security groups, NACLs or Network Firewall so everything goes through the VPC Resolver.
  • Firewall Manager can associate DNS Firewall rule groups with every VPC in the organization.

Exam signal

"Allow outbound connections only to approved domains": Network Firewall domain list (or a proxy) filters the connection. "Stop malware resolving command-and-control domains" or "detect DNS tunneling": DNS Firewall. Many answers use both, because each sees a different path.

Gateway Load Balancer and third-party IDS/IPS

  • GWLB sends traffic transparently to a fleet of virtual appliances (Palo Alto, Fortinet, Check Point, open-source Suricata) using GENEVE on port 6081, keeping the original packet intact.
  • Consumers reach it through GWLB endpoints in their route tables, so the appliance fleet can live in a central security account.
  • Keep flows symmetric: enable appliance mode on the transit gateway VPC attachment for the inspection VPC.
  • Pick GWLB when the question names a vendor, requires a specific IPS signature feed, or reuses existing firewall licences. Otherwise Network Firewall is the lower-effort managed answer.
  • Traffic Mirroring copies ENI traffic to an out-of-band IDS for detection only. It can't block.

Egress filtering patterns

PatternWhat it gives youEffort
No route to the internet (isolated subnets + VPC endpoints)Strongest: nothing leaves except to AWS servicesLow, if workloads only need AWS APIs
NAT gateway aloneHides private IPs. Filters nothingLow
Network Firewall (central egress VPC) with domain listsFQDN allow list, IPS signatures, logsMedium
Explicit forward proxy fleet (for example Squid) behind an NLBURL-level allow list, user auth, cachingHigh: you patch and scale it
GWLB + vendor firewallVendor URL categories and threat feedsHigh
  • An explicit proxy only filters clients configured to use it. Pair it with security groups or NACLs that stop direct outbound 80/443, or clients just go around it.
  • A self-managed proxy or NAT instance forwarding traffic needs source/destination check disabled.
  • Use VPC endpoints with endpoint policies so traffic to AWS services never reaches the egress path. See Hybrid and private access.

Scenarios

Scenario
An analytics company runs batch jobs in private subnets that must download packages only from pypi.org and files.pythonhosted.org over HTTPS. All other outbound internet traffic must be blocked and logged. Traffic leaves through NAT gateways. The team doesn't want to run proxy servers. What should the security engineer implement?
Scenario
After a new network ACL is applied to a public subnet holding an internet-facing ALB, users can no longer load the site. The NACL has inbound rule 100 allowing TCP 443 from 0.0.0.0/0 and outbound rule 100 allowing TCP 443 to 0.0.0.0/0, and the ALB's security group allows 443 from anywhere. What is the most likely cause?
Scenario
A bank must inspect all traffic between its 40 spoke VPCs and the internet with a specific vendor's next-generation firewall, because its SOC already uses that vendor's threat feeds and management console. The firewall fleet must scale out and survive the loss of an appliance. What design meets these requirements?

Further reading

On this page