Lesson 181 · AWS Learning Path

AWS 181: AWS Firewall Manager

· Published · 8 min read

Labelled process diagram for AWS 181: Organization and delegated admin to Central security policy to In-scope account resources to Compliance, remediation, and exception evidence, with decision, proof and rejection...

Why this lesson matters

Apply central policies for supported security services across AWS Organizations accounts and resources, with scope, remediation, exceptions, and administrator ownership.

What you will be able to do

By the end, you can:

  • explain aws firewall manager in plain language;
  • locate the current service controls in the AWS Management Console;
  • run the matching CloudShell or AWS CLI queries and explain every important field;
  • draw the identity, network, data, failure, and monitoring path;
  • choose the service from requirements and reject it when those requirements are absent;
  • diagnose a failed or misleading result from evidence;
  • state the cost owner and prove cleanup or a no-create result.

Before you start

  • Use a personal AWS account only when its owner has approved the lesson. Do not use the root user for daily work.
  • CloudShell is the default command environment. AWS028 explains CloudShell; AWS029 and AWS030 explain local AWS CLI installation and profiles.
  • The course example Region is ap-south-1. Global services and services with a required control Region are called out in their commands.
  • Run aws sts get-caller-identity privately. Redact the account number before sharing evidence.
  • Never paste access keys, passwords, secret values, private object data, presigned URLs, or full account-specific ARNs into a submission.
  • This is a no-create lesson. Every Console action and AWS CLI command is read-only. Create the practical artifact locally.
  • Console wording can change. Use the Console service search if a menu label has moved, then confirm the current field in the official documentation.

The core model

QuestionWhat it means in this lesson
PurposeApply central policies for supported security services across AWS Organizations accounts and resources, with scope, remediation, exceptions, and administrator ownership.
Scope and boundaryThe learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Firewall Manager.
Evidence of successSuccess means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Firewall Manager.
Cost modelRequests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.
Safe rejection ruleAvoid enabling automatic remediation before observing impact or expecting it to be useful in a single isolated personal account.

How the request flows

+------------------------------------+
|  Organization and delegated admin  |
+------------------------------------+
                  |
                  v
+---------------------------+
|  Central security policy  |
+---------------------------+
             |
             v
+------------------------------+
|  In-scope account resources  |
+------------------------------+
               |
               v
+---------------------------------------------------+
|  Compliance, remediation, and exception evidence  |
+---------------------------------------------------+

Firewall Manager is governance, not another packet filter

Firewall Manager uses an AWS Organizations delegated administrator to apply supported security policies across accounts and resources. The underlying services - WAF, Shield Advanced, Network Firewall, Route 53 Resolver DNS Firewall and VPC security groups - still inspect or enforce traffic. Firewall Manager defines scope, deploys/assesses policy and reports compliance.

Prerequisites include an organization with all features, delegated administrator, AWS Config recording required resource types in governed accounts/Regions, and service-specific prerequisites. Never use the Organizations management account as the normal security operations identity. Administrator designation and policy are regional where documented; enumerate every required Region.

Policy anatomy

Every policy needs:

  1. Policy type and underlying service configuration.
  2. Account/OU inclusion and exclusion.
  3. Resource-type scope and tag-based inclusion/exclusion.
  4. Region scope and administrator ownership.
  5. Remediation mode: report-only first, then automatic where approved.
  6. Behavior when a resource or account leaves scope.
  7. Exception process, expiry, evidence and alert owner.

Tag scope uses exact key/value matching. If workload owners can modify governance tags, they may evade policy. Protect tag mutation with IAM/SCP controls and continuously find untagged resources. New accounts and resources are evaluated as they enter scope, but coverage depends on policy Region, supported resource type and Config visibility.

Policy families and ownership

PolicyCentral resultDesign caution
WAFDeploys web ACL/rule-group structure to supported resourcesAccount teams may have a defined middle rule space; understand first/last groups and cleanup behavior.
Shield AdvancedEnrolls supported resources and can coordinate WAF for application-layer mitigationSubscription and protected-resource charges/conditions remain; out-of-scope behavior matters.
Security group common policyReplicates centrally defined baseline groupsReplicated groups and associations can affect reachability; stage changes.
Security group audit policyFinds overly permissive or unused rules/groupsAutomatic remediation can remove needed connectivity if scope/evidence is wrong.
Network FirewallCreates/manages firewall policy and deployment resources according to modelRouting is still required; policy existence alone does not insert traffic.
DNS FirewallApplies Resolver DNS Firewall rule groups to in-scope VPCsDomain rules do not inspect direct IP traffic or external DNS paths.

Automatic remediation is a mutation engine. Begin with compliance reporting, measure false positives and ownership, test in a sandbox OU, deploy canaries, then expand. For each policy, document resources Firewall Manager creates, who may edit them, and whether cleanup deletes or retains them when the policy is removed.

Read compliance without overclaiming

NON_COMPLIANT should identify policy, account, Region, resource, violation reason and expected remediation. A compliant resource proves alignment with that policy's evaluated configuration, not that the application is secure. Delayed Config recording, unsupported resource types, excluded accounts/tags or disabled Regions are coverage gaps rather than passes.

Send policy findings through Security Hub/EventBridge to an accountable workflow. Suppress only approved exceptions with owner and expiry. Track policy changes through CloudTrail and infrastructure as code; console-only drift weakens auditability.

Architecture decision table

SituationDirectionReason
Requirement matchesUse Firewall Manager when multi-account policy consistency and compliance ownership exist.Select only after scope, behavior, security, recovery, operations, and price evidence agree.
Requirement does not matchAvoid enabling automatic remediation before observing impact or expecting it to be useful in a single isolated personal account.Rejecting an attractive service is a valid architecture result.
No create permission or cost approvalUse supplied evidence and local design workLearning does not depend on creating an hourly resource.
Existing resource is unknown or unownedInspect only, then stopNever change or delete a resource merely because it resembles a course example.

AWS Management Console, step by step

Sign in with the normal non-root learning identity. Write the expected starting state before opening the service.

  1. Use the Console service search and open AWS Firewall Manager, Security policies and Settings; confirm the account and Region before reading the page.
  2. Inspect the supplied or owned resource's status, configuration, permissions, networking, encryption, monitoring, tags, and dependencies without changing it.
  3. Open the related metrics, logs, events, or history view and record one timestamped signal that would prove or disprove the expected behavior.
  4. Return to the resource list, clear filters, and record the final inventory. On the read-only track, do not choose Create, Save, or Delete.

CloudShell and AWS CLI, step by step

Start with a known caller and Region:

export AWS_DEFAULT_REGION="ap-south-1"
aws sts get-caller-identity --query Arn --output text
aws configure list

Redact the account part of the ARN in shared evidence. Now run the topic queries:

aws fms get-admin-account --output json
aws fms list-policies --query 'PolicyList[].{Name:PolicyName,Type:SecurityServiceType,Id:PolicyId,Remediate:RemediationEnabled,Count:ResourceCount}' --output table

Expected interpretation

Policy inventory is meaningful only in an Organizations management or delegated-administrator context. Compliance and automatic remediation require scope and exception review.

Practical work

Design an organization-wide WAFV2 policy. Define administrator, included and excluded accounts/OUs, resource tags, rule groups, remediation mode, exception expiry, findings destination, change rollout, and rollback.

Diagnose this topic from its own evidence

  • Resource absent from compliance: verify account/OU and tag scope, Region, supported type, Config recorder and delegated-admin relationship.
  • Remediation did not occur: inspect remediation setting, service-linked role, underlying service quota/permissions and violation details.
  • Unexpected protection appeared: inspect policy scope and tags before deleting generated resources; direct deletion can be recreated.
  • Connectivity changed: correlate Firewall Manager policy event, replicated SG/Network Firewall resources and route/flow evidence.
  • Policy deletion leaves resources: inspect the configured cleanup choice and underlying-service ownership before manual removal.

Cost and cleanup

Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.

Knowledge check

  1. What operational purpose is this lesson solving?

Expected direction: Apply central policies for supported security services across AWS Organizations accounts and resources, with scope, remediation, exceptions, and administrator ownership.

  1. Which scope or ownership boundary must be proved first?

Expected direction: The learner must identify the account and Region scope, resource boundary, identity path, data or network path, failure behavior, observability, and cleanup ownership for AWS Firewall Manager.

  1. What evidence is strong enough to accept the result?

Expected direction: Success means the Console fields, CLI result, workload behavior, monitoring evidence, and architecture claim agree. An available state alone is not enough for AWS Firewall Manager.

  1. Which tempting design or shortcut must be rejected?

Expected direction: Avoid enabling automatic remediation before observing impact or expecting it to be useful in a single isolated personal account.

  1. Which cost dimensions and retained resources need an owner?

Expected direction: Requests, running capacity, storage, logs, data transfer, retained state, and optional features must be priced for the exact design.

Lesson acceptance

  • Explain delegated administration, Config prerequisites, regional scope and underlying enforcement services.
  • Design account/OU/resource/tag scope that cannot be trivially evaded.
  • Compare supported policy families and identify generated resources and cost owners.
  • Plan report-only, canary and automatic-remediation phases with rollback.
  • Diagnose absent, noncompliant and unexpectedly remediated resources from authoritative evidence.

Official sources

Advertisement