Medium
Protect
Regional
The default stateless action for Network Firewall policies should be drop or forward for full packets
NIST 800-53
Description
Confirms that the default stateless action for full packets in Network Firewall policies is drop or forward, not pass.
Remediation
Set the default stateless action for full packets to 'aws:drop' or 'aws:forward_to_sfe'.
Steps
- Navigate to the VPC console
- Select the Network Firewall policy
- Modify the 'Default stateless actions' for full packets
- Set to 'aws:drop' or 'aws:forward_to_sfe'
- Apply the changes
Compliance
NIST 800-53