VPC Egress Filtering Checklist
Retrospective: this article looks back at events from November 2020, written in 2026 with the benefit of hindsight.
Egress filtering is one of the most effective controls against data exfiltration and malware. Use this checklist to put it in place across AWS VPCs.
Visibility first
- VPC Flow Logs enabled on all production VPCs.
- DNS query logging enabled (Route 53 Resolver query logs).
- A baseline of normal outbound destinations per application.
Architecture
- Workloads have no direct internet gateway access unless required.
- Outbound traffic routes through NAT and a firewall (AWS Network Firewall or a third-party appliance).
- VPC endpoints are used for AWS services (S3, DynamoDB, Secrets Manager, etc.) to keep that traffic off the internet.
Policy
- Default-deny for outbound traffic from sensitive workloads, with an allow list of domains and ports.
- Managed threat intelligence rule groups enabled.
- Route 53 Resolver DNS Firewall blocks known malicious domains.
- Non-standard outbound ports blocked by default.
Exceptions
- Each allow-list entry has an owner and justification.
- Temporary exceptions expire.
Monitoring
- Alerts for denied outbound connections from production workloads.
- Alerts for DNS queries to newly registered or suspicious domains.
- Firewall and DNS logs sent to the SIEM.
Special cases
- Build and CI systems restricted to required package repositories.
- AI agents and evaluation sandboxes restricted to specific endpoints, with no general internet access.
- AWS Network Firewall Goes GA (Nov 2020): Managed Stateful Inspection for VPCs Platform Changes
- How to Deploy AWS Network Firewall in a Centralized Inspection VPC How-To & Hardening
- CIO Brief: Network Security Still Matters in the Cloud CIO Briefings