Medium Protect Regional

The default stateless action for Network Firewall policies should be drop or forward for fragmented packets

NIST 800-53

Description

Verifies that the default stateless action for fragmented packets in Network Firewall policies is drop or forward, not pass.


Remediation

Set the default stateless action for fragmented packets to 'aws:drop' or 'aws:forward_to_sfe'.

Steps

  1. Navigate to the VPC console
  2. Select the Network Firewall policy
  3. Modify the 'Default stateless actions' for fragmented packets
  4. Set to 'aws:drop' or 'aws:forward_to_sfe'
  5. Apply the changes

Compliance

NIST 800-53