Lesson 180 · AWS Learning Path

AWS 180: AWS WAF, Shield and Network Firewall

· Published · 9 min read

Labelled process diagram for AWS 180: Network or HTTP flow to Correct protection and inspection point to Allowed or blocked destination to Logs, metrics, and false-positive evidence, with decision, proof and...

Why this lesson matters

Place application-layer filtering, DDoS protection, and VPC network inspection at their correct traffic layers and routing points.

What you will be able to do

By the end, you can:

  • explain aws waf, shield and network firewall in plain language;
  • locate the current service controls in the AWS Management Console;
  • run the matching CloudShell or AWS CLI queries and explain every important field;
  • draw the identity, network, data, failure, and monitoring path;
  • choose the service from requirements and reject it when those requirements are absent;
  • diagnose a failed or misleading result from evidence;
  • state the cost owner and prove cleanup or a no-create result.

Before you start

  • Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
  • CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
  • The course example Region is ap-south-1. Global services and services with a required control Region are called out in their commands.
  • Run aws sts get-caller-identity privately. Redact the account number before sharing evidence.
  • Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
  • This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
  • Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.

The core model

QuestionWhat it means in this lesson
PurposePlace application-layer filtering, DDoS protection, and VPC network inspection at their correct traffic layers and routing points.
Scope and boundaryThe learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS WAFV2, Shield, and Network Firewall.
Evidence of successSuccess means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS WAFV2, Shield, and Network Firewall.
Cost modelNetwork Firewall endpoints and traffic, Shield Advanced subscription, WAF ACLs and requests, logs, NAT, and transfer can be expensive. Use instructor evidence only.
Safe rejection ruleAvoid routing asymmetry around Network Firewall, expecting WAF to inspect arbitrary TCP, or deploying hourly firewall endpoints in a personal lab.

How the request flows

+------------------------+
|  Network or HTTP flow  |
+------------------------+
            |
            v
+-------------------------------------------+
|  Correct protection and inspection point  |
+-------------------------------------------+
                     |
                     v
+----------------------------------+
|  Allowed or blocked destination  |
+----------------------------------+
                 |
                 v
+----------------------------------------------+
|  Logs, metrics, and false-positive evidence  |
+----------------------------------------------+

Put each control at the correct layer

ServiceInspection pointUnderstandsDoes not replace
AWS WAFAssociated CloudFront, ALB, API Gateway, AppSync, Cognito user pool and other supported web resourcesHTTP(S) request fields, labels, rate and managed/custom web rulesSecurity groups, host patching, authorization or general VPC firewalling
Shield StandardAutomatically protects supported AWS edges/resourcesCommon infrastructure and transport-layer DDoS eventsWeb application rules or application capacity design
Shield AdvancedSubscription protection for enrolled resources, enhanced detection/mitigation, response and cost-protection features under documented conditionsDDoS events and protected-resource contextWAF tuning, origin hardening or automatic enrollment of every resource
Network FirewallRouted traffic through an AZ-specific firewall endpointStateless packet fields and stateful flow/application patterns using Suricata-compatible inspectionWAF's HTTP application context, endpoint host controls or IAM

Security groups and NACLs remain separate: security groups are stateful resource-interface allow rules; NACLs are stateless subnet boundary rules; Network Firewall is managed inspection inserted by routes; WAF is attached to supported web entry points.

WAF evaluation model

A web ACL has a default action and ordered rules or rule groups. Lower numeric priority evaluates first. A terminating Allow or Block stops evaluation; Count observes and continues. CAPTCHA and Challenge behavior depends on token validity. Labels let one rule classify a request and a later rule act on that classification.

Start new managed rules in Count with sampled requests and logs, measure false positives, then promote deliberately. Scope-down statements reduce cost/noise and prevent a broad managed group from evaluating irrelevant traffic. Rate-based rules approximate request rate over a moving window and aggregate by IP or supported custom keys; they are not exact per-second quotas and do not replace API Gateway throttling.

Forwarded IP logic is trustworthy only when requests arrive through controlled proxies and the configured header/fallback behavior is correct. Otherwise clients can spoof a header. Protect the origin so traffic cannot bypass CloudFront/WAF, for example with CloudFront origin access controls for S3 or controlled origin-facing rules/headers where applicable.

WAF logs can contain headers, URIs and request data. Configure redaction and data-protection controls, encrypted destination, retention and least privilege. CloudWatch metrics, sampled requests and full logs answer different questions; samples are not a complete audit stream.

Shield design and response

Shield Standard is automatic and has no enrollment console workflow. Shield Advanced requires an active subscription and explicit supported-resource protections or Firewall Manager policy. Build a response plan before an event: protected resource inventory, health checks, escalation contacts, SRT access procedure, application runbook, scaling limits and evidence retention. Cost protection has eligibility and engagement requirements; it is not a promise that every DDoS-related charge disappears.

Layer 7 automatic mitigation uses Shield detection together with WAF. Establish a traffic baseline and monitor generated mitigations. DDoS resilience still needs distributed edge entry, origin isolation, cacheability, quotas, autoscaling/backpressure and dependency protection.

Network Firewall packet path

Creating a firewall does nothing until route tables send traffic symmetrically through the correct firewall endpoint in each Availability Zone. Typical centralized or distributed designs must preserve AZ affinity and return-path symmetry. Gateway Load Balancer is a different service for inserting virtual appliances.

Stateless rules inspect packets independently and can pass, drop or forward to the stateful engine. Stateful rules understand flows and use standard/domain-list/Suricata-compatible groups. Rule-order mode, default actions and capacity units affect behavior. Alert is observation, not prevention. Enable flow and alert logs before enforcing a policy, and account for log cost.

TLS inspection terminates and re-establishes selected TLS sessions using configured certificates, creating privacy, trust, performance and protocol limitations. It is not equivalent to seeing encrypted payload by default. QUIC and newer TLS features can require explicit handling; validate current documented support before rollout.

Architecture decision table

SituationDirectionReason
Requirement matchesUse layered controls when different threats and protocol visibility require them.Select only after scope, behavior, security, recovery, operations, and price evidence agree.
Requirement does not matchAvoid routing asymmetry around Network Firewall, expecting WAF to inspect arbitrary TCP, or deploying hourly firewall endpoints in a personal lab.Rejecting an attractive service is a valid architecture result.
No create permission or cost approvalUse supplied evidence and local design workLearning does not depend on creating an hourly resource.
Existing resource is unknown or unownedInspect only, then stopNever change or delete a resource merely because it resembles a course example.

AWS Management Console, step by step

Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.

  1. Use the Console service search and open WAF and Shield plus VPC, Network Firewall; confirm the account and Region before reading the page.
  2. Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
  3. Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
  4. Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.

CloudShell and AWS CLI, step by step

Start with a known caller and Region:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account part of the ARN in shared evidence. Now run the topic queries:

aws wafv2 list-web-acls --scope REGIONAL --query 'WebACLs[].Name' --output table
aws shield list-protections --region us-east-1 --output table
aws network-firewall list-firewalls --query 'Firewalls[].{Name:FirewallName,Vpc:VpcId,Status:FirewallStatus}' --output table

Expected interpretation

WAF inspects supported HTTP requests, Shield protects supported resources from DDoS, and Network Firewall requires deliberate subnet routing for inspected VPC traffic.

Practical work

Draw internet-to-ALB HTTP, private-subnet egress, and east-west inspection. Place WAFV2, Shield, and Network Firewall; add route tables, TLS visibility, rule ownership, logs, HA, bypass tests, and cost.

Diagnose this topic from its own evidence

  • WAF false positive: identify web ACL, rule priority, terminating action, labels, request ID and sampled/log record; tune scope or exclusion rather than disabling the whole ACL.
  • WAF bypass: compare public DNS/origin reachability and prove the origin accepts only the intended front door.
  • Network Firewall sees no traffic: inspect subnet route tables in both directions, endpoint/AZ, TGW/NAT path and flow logs.
  • Asymmetric failures: trace forward and return routes per AZ; stateful inspection requires both directions of the flow.
  • DDoS alarm without mitigation confidence: inspect protected-resource enrollment, health checks, Shield event timeline, WAF actions, capacity and escalation runbook.

Cost and cleanup

Network Firewall endpoints and traffic, Shield Advanced subscription, WAF ACLs and requests, logs, NAT, and transfer can be expensive. Use instructor evidence only.

Knowledge check

  1. What operational purpose is this lesson solving?

Expected direction: Place application-layer filtering, DDoS protection, and VPC network inspection at their correct traffic layers and routing points.

  1. Which scope or ownership boundary must be proved first?

Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS WAFV2, Shield, and Network Firewall.

  1. What evidence is strong enough to accept the result?

Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS WAFV2, Shield, and Network Firewall.

  1. Which tempting design or shortcut must be rejected?

Expected direction: Avoid routing asymmetry around Network Firewall, expecting WAF to inspect arbitrary TCP, or deploying hourly firewall endpoints in a personal lab.

  1. Which cost dimensions and retained resources need an owner?

Expected direction: Network Firewall endpoints and traffic, Shield Advanced subscription, WAF ACLs and requests, logs, NAT, and transfer can be expensive. Use instructor evidence only.

Lesson acceptance

  • Place WAF, Shield, Network Firewall, SGs and NACLs on a packet/request diagram.
  • Explain WAF priority, terminating/non-terminating actions, labels, managed-rule staging, rate rules and forwarded-IP trust.
  • Distinguish Shield Standard from Advanced enrollment, operations and cost ownership.
  • Trace a symmetric multi-AZ Network Firewall route and separate stateless from stateful processing.
  • Diagnose one false positive and one routing bypass from logs and configuration evidence.

Official sources

Advertisement