Medium
Protect
Regional
The default stateless action for Network Firewall policies should be drop or forward for fragmented packets
NIST 800-53
Description
Verifies that the default stateless action for fragmented packets in Network Firewall policies is drop or forward, not pass.
Remediation
Set the default stateless action for fragmented packets to 'aws:drop' or 'aws:forward_to_sfe'.
Steps
- Navigate to the VPC console
- Select the Network Firewall policy
- Modify the 'Default stateless actions' for fragmented packets
- Set to 'aws:drop' or 'aws:forward_to_sfe'
- Apply the changes
Compliance
NIST 800-53