Medium Protect Regional

The default stateless action for Network Firewall policies should be drop or forward for full packets

NIST 800-53

Description

Confirms that the default stateless action for full packets in Network Firewall policies is drop or forward, not pass.


Remediation

Set the default stateless action for full packets to 'aws:drop' or 'aws:forward_to_sfe'.

Steps

  1. Navigate to the VPC console
  2. Select the Network Firewall policy
  3. Modify the 'Default stateless actions' for full packets
  4. Set to 'aws:drop' or 'aws:forward_to_sfe'
  5. Apply the changes

Compliance

NIST 800-53