How to Deploy AWS Network Firewall in a Centralized Inspection VPC
Retrospective: this article looks back at events from November 2020, written in 2026 with the benefit of hindsight.
A centralized inspection VPC lets one AWS Network Firewall deployment filter traffic for many VPCs. Here is the common architecture and setup sequence.
Architecture
- Workload VPCs attach to an AWS Transit Gateway.
- An inspection VPC contains firewall subnets with AWS Network Firewall endpoints in each Availability Zone, plus Transit Gateway attachment subnets.
- An egress VPC (or the inspection VPC itself) contains NAT gateways and an internet gateway.
- Transit Gateway route tables send traffic from workload VPCs to the inspection VPC before it reaches the internet or other VPCs.
Step 1: Build the inspection VPC
Create subnets per AZ for Transit Gateway attachments and firewall endpoints. Enable appliance mode on the Transit Gateway attachment to keep flows symmetric.
Step 2: Create the firewall and policy
- Create a firewall policy with stateful rule groups.
- Start with AWS managed threat intelligence rule groups.
- Add a domain allow list for egress (for example, OS update repositories, required SaaS APIs) and set the default action for unmatched traffic.
Step 3: Configure routing
Update Transit Gateway route tables and VPC route tables so all egress and inter-VPC traffic flows through the firewall endpoints.
Step 4: Logging
Send alert and flow logs to S3, CloudWatch Logs or Kinesis, and on to your SIEM.
Step 5: Roll out in monitor mode
Begin with alert-only rules to learn traffic patterns, then enforce the allow list.
Common mistakes
- Asymmetric routing breaking stateful inspection (missing appliance mode).
- Allow lists so broad they don't restrict anything.
- AWS Network Firewall Goes GA (Nov 2020): Managed Stateful Inspection for VPCs Platform Changes
- VPC Egress Filtering Checklist How-To & Hardening
- CIO Brief: Network Security Still Matters in the Cloud CIO Briefings