AWS Network Firewall Now Supports Stateful Rule Hit Counts
AWS Network Firewall now provides rule hit counts for stateful rules, showing how often specific firewall policy rules match network traffic. This addition increases visibility into VPC traffic for security engineers and network administrators.
Why it matters
Security teams can use this data to remove obsolete or redundant rules and quickly verify that new security policies are working correctly. This reduces the time needed to respond to incidents by identifying exactly which rules were triggered.
The details
- Metrics refresh at configurable intervals as low as 5 minutes.
- Available in all supported AWS Regions except Middle East (UAE) and Bahrain.
- Rule hit counts are enabled by default for custom and managed rule groups.
Show entities and relationshipsHide entities and relationships
In this article
Key connections
AWS owns AWS Network Firewall
AWS provides the AWS Network Firewall managed service.
AWS Network Firewall uses Stateful Inspection
AWS Network Firewall provides rule hit counts for stateful rules.
AWS Network Firewall uses Virtual Private Cloud
AWS Network Firewall provides inspection and visibility into VPC traffic.
AWS Network Firewall is related to United Arab Emirates
Stateful rule hit counts capability is available across supported regions except the Middle East (UAE) Region.
AWS Network Firewall is related to Bahrain
Stateful rule hit counts capability is available across supported regions except the Middle East (Bahrain) Region.
AWS Network Firewall is related to Cybersecurity
AWS Network Firewall inspects VPC traffic and provides rule-hit intelligence that supports incident response.
Related events
AWS Network Firewall Adds Support for Stateful Rule Hit Counts
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.