AWSPlatform ChangesRetrospectives

AWS Network Firewall Goes GA (Nov 2020): Managed Stateful Inspection for VPCs

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2020, written in 2026 with the benefit of hindsight.

In November 2020, AWS Network Firewall became generally available — a managed, stateful network firewall and intrusion prevention service for Amazon VPCs.

What it offered

  • Stateful and stateless rules for filtering traffic between VPCs, to and from the internet, and to on-premises networks.
  • Intrusion prevention using Suricata-compatible rules.
  • Domain filtering for outbound traffic (allow or deny lists by domain name).
  • Managed threat intelligence rule groups from AWS.
  • Automatic scaling and high availability, deployed per Availability Zone.

Why it mattered

Before Network Firewall, AWS customers relied on security groups and network ACLs — useful but limited — or deployed third-party firewall appliances on EC2, which required managing instances, scaling and failover. Network Firewall gave a native option for centralized inspection, especially egress filtering: controlling what servers can connect to on the internet.

Why egress filtering matters

Many attacks rely on outbound connections: malware calling home, data exfiltration, crypto mining pools and SSRF attacks reaching external services. Default cloud networks allow all outbound traffic. Restricting egress to known destinations is one of the most effective, and most often skipped, network controls.

In hindsight

Network Firewall became a building block of centralized inspection architectures with AWS Transit Gateway. Its value grew as attack patterns relied increasingly on outbound connectivity — including, by 2026, autonomous AI agents reaching the open internet in ways their operators didn't intend.

aws network firewall2020

More on this story