AWSHow-To & HardeningRetrospectives

How to Deploy AWS Network Firewall in a Centralized Inspection VPC

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2020, written in 2026 with the benefit of hindsight.

A centralized inspection VPC lets one AWS Network Firewall deployment filter traffic for many VPCs. Here is the common architecture and setup sequence.

Architecture

  • Workload VPCs attach to an AWS Transit Gateway.
  • An inspection VPC contains firewall subnets with AWS Network Firewall endpoints in each Availability Zone, plus Transit Gateway attachment subnets.
  • An egress VPC (or the inspection VPC itself) contains NAT gateways and an internet gateway.
  • Transit Gateway route tables send traffic from workload VPCs to the inspection VPC before it reaches the internet or other VPCs.

Step 1: Build the inspection VPC

Create subnets per AZ for Transit Gateway attachments and firewall endpoints. Enable appliance mode on the Transit Gateway attachment to keep flows symmetric.

Step 2: Create the firewall and policy

  • Create a firewall policy with stateful rule groups.
  • Start with AWS managed threat intelligence rule groups.
  • Add a domain allow list for egress (for example, OS update repositories, required SaaS APIs) and set the default action for unmatched traffic.

Step 3: Configure routing

Update Transit Gateway route tables and VPC route tables so all egress and inter-VPC traffic flows through the firewall endpoints.

Step 4: Logging

Send alert and flow logs to S3, CloudWatch Logs or Kinesis, and on to your SIEM.

Step 5: Roll out in monitor mode

Begin with alert-only rules to learn traffic patterns, then enforce the allow list.

Common mistakes

  • Asymmetric routing breaking stateful inspection (missing appliance mode).
  • Allow lists so broad they don't restrict anything.
aws network firewall centralized deploymentAWS Network Firewall2020

More on this story