AWS 181: AWS Firewall Manager
Why this lesson matters
Apply central policies for supported security services across AWS Organizations accounts and resources, with scope, remediation, exceptions, and administrator ownership.
What you will be able to do
By the end, you can:
- explain aws firewall manager in plain language;
- locate the current service controls in the AWS Management Console;
- run the matching CloudShell or AWS CLI queries and explain every important field;
- draw the identity, network, data, failure, and monitoring path;
- choose the service from requirements and reject it when those requirements are absent;
- diagnose a failed or misleading result from evidence;
- state the cost owner and prove cleanup or a no-create result.
Before you start
- Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
- CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
- The course example Region is
ap-south-1. Global services and services with a required control Region are called out in their commands. - Run
aws sts get-caller-identityprivately. Redact the account number before sharing evidence. - Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
- This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
- Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.
The core model
| Question | What it means in this lesson |
|---|---|
| Purpose | Apply central policies for supported security services across AWS Organizations accounts and resources, with scope, remediation, exceptions, and administrator ownership. |
| Scope and boundary | The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Firewall Manager. |
| Evidence of success | Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Firewall Manager. |
| Cost model | Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design. |
| Safe rejection rule | Avoid enabling automatic remediation before observing impact or expecting it to be useful in a single isolated personal account. |
How the request flows
+------------------------------------+
| Organization and delegated admin |
+------------------------------------+
|
v
+---------------------------+
| Central security policy |
+---------------------------+
|
v
+------------------------------+
| In-scope account resources |
+------------------------------+
|
v
+---------------------------------------------------+
| Compliance, remediation, and exception evidence |
+---------------------------------------------------+
Firewall Manager is governance, not another packet filter
Firewall Manager uses an AWS Organizations delegated administrator to apply supported security policies across accounts and resources. The underlying services - WAF, Shield Advanced, Network Firewall, Route 53 Resolver DNS Firewall and VPC security groups - still inspect or enforce traffic. Firewall Manager defines scope, deploys/assesses policy and reports compliance.
Prerequisites include an organization with all features, delegated administrator, AWS Config recording required resource types in governed accounts/Regions, and service-specific prerequisites. Never use the Organizations management account as the normal security operations identity. Administrator designation and policy are regional where documented; enumerate every required Region.
Policy anatomy
Every policy needs:
- Policy type and underlying service configuration.
- Account/OU inclusion and exclusion.
- Resource-type scope and tag-based inclusion/exclusion.
- Region scope and administrator ownership.
- Remediation mode: report-only first, then automatic where approved.
- Behavior when a resource or account leaves scope.
- Exception process, expiry, evidence and alert owner.
Tag scope uses exact key/value matching. If workload owners can modify governance tags, they may evade policy. Protect tag mutation with IAM/SCP controls and continuously find untagged resources. New accounts and resources are evaluated as they enter scope, but coverage depends on policy Region, supported resource type and Config visibility.
Policy families and ownership
| Policy | Central result | Design caution |
|---|---|---|
| WAF | Deploys web ACL/rule-group structure to supported resources | Account teams may have a defined middle rule space; understand first/last groups and cleanup behavior. |
| Shield Advanced | Enrolls supported resources and can coordinate WAF for application-layer mitigation | Subscription and protected-resource charges/conditions remain; out-of-scope behavior matters. |
| Security group common policy | Replicates centrally defined baseline groups | Replicated groups and associations can affect reachability; stage changes. |
| Security group audit policy | Finds overly permissive or unused rules/groups | Automatic remediation can remove needed connectivity if scope/evidence is wrong. |
| Network Firewall | Creates/manages firewall policy and deployment resources according to model | Routing is still required; policy existence alone does not insert traffic. |
| DNS Firewall | Applies Resolver DNS Firewall rule groups to in-scope VPCs | Domain rules do not inspect direct IP traffic or external DNS paths. |
Automatic remediation is a mutation engine. Begin with compliance reporting, measure false positives and ownership, test in a sandbox OU, deploy canaries, then expand. For each policy, document resources Firewall Manager creates, who may edit them, and whether cleanup deletes or retains them when the policy is removed.
Read compliance without overclaiming
NON_COMPLIANT should identify policy, account, Region, resource, violation reason and expected remediation. A compliant resource proves alignment with that policy's evaluated configuration, not that the application is secure. Delayed Config recording, unsupported resource types, excluded accounts/tags or disabled Regions are coverage gaps rather than passes.
Send policy findings through Security Hub/EventBridge to an accountable workflow. Suppress only approved exceptions with owner and expiry. Track policy changes through CloudTrail and infrastructure as code; console-only drift weakens auditability.
Architecture decision table
| Situation | Direction | Reason |
|---|---|---|
| Requirement matches | Use Firewall Manager when multi-account policy consistency and compliance ownership exist. | Select only after scope, behavior, security, recovery, operations, and price evidence agree. |
| Requirement does not match | Avoid enabling automatic remediation before observing impact or expecting it to be useful in a single isolated personal account. | Rejecting an attractive service is a valid architecture result. |
| No create permission or cost approval | Use supplied evidence and local design work | Learning does not depend on creating an hourly resource. |
| Existing resource is unknown or unowned | Inspect only, then stop | Never change or delete a resource merely because it resembles a course example. |
AWS Management Console, step by step
Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.
- Use the Console service search and open AWS Firewall Manager, Security policies and Settings; confirm the account and Region before reading the page.
- Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
- Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
- Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.
CloudShell and AWS CLI, step by step
Start with a known caller and Region:
export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list
Redact the account part of the ARN in shared evidence. Now run the topic queries:
aws fms get-admin-account --output json
aws fms list-policies --query 'PolicyList[].{Name:PolicyName,Type:SecurityServiceType,Id:PolicyId,Remediate:RemediationEnabled,Count:ResourceCount}' --output table
Expected interpretation
Policy inventory is meaningful only in an Organizations management or delegated-administrator context. Compliance and automatic remediation require scope and exception review.
Practical work
Design an organization-wide WAFV2 policy. Define administrator, included and excluded accounts/OUs, resource tags, rule groups, remediation mode, exception expiry, findings destination, change rollout, and rollback.
Diagnose this topic from its own evidence
- Resource absent from compliance: verify account/OU and tag scope, Region, supported type, Config recorder and delegated-admin relationship.
- Remediation did not occur: inspect remediation setting, service-linked role, underlying service quota/permissions and violation details.
- Unexpected protection appeared: inspect policy scope and tags before deleting generated resources; direct deletion can be recreated.
- Connectivity changed: correlate Firewall Manager policy event, replicated SG/Network Firewall resources and route/flow evidence.
- Policy deletion leaves resources: inspect the configured cleanup choice and underlying-service ownership before manual removal.
Cost and cleanup
Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Knowledge check
- What operational purpose is this lesson solving?
Expected direction: Apply central policies for supported security services across AWS Organizations accounts and resources, with scope, remediation, exceptions, and administrator ownership.
- Which scope or ownership boundary must be proved first?
Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Firewall Manager.
- What evidence is strong enough to accept the result?
Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Firewall Manager.
- Which tempting design or shortcut must be rejected?
Expected direction: Avoid enabling automatic remediation before observing impact or expecting it to be useful in a single isolated personal account.
- Which cost dimensions and retained resources need an owner?
Expected direction: Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Lesson acceptance
- Explain delegated administration, Config prerequisites, regional scope and underlying enforcement services.
- Design account/OU/resource/tag scope that cannot be trivially evaded.
- Compare supported policy families and identify generated resources and cost owners.
- Plan report-only, canary and automatic-remediation phases with rollback.
- Diagnose absent, noncompliant and unexpectedly remediated resources from authoritative evidence.