networkfirewall
Network Firewall
Overview
Domain expertise for configuring AWS Network Firewall, the managed stateful firewall and intrusion prevention service that filters traffic at the perimeter of a VPC using the Suricata inspection engine. Covers placing a firewall in the traffic path and routing traffic through its endpoints, centralizing inspection across VPCs with a transit gateway-attached firewall, filtering outbound traffic by domain name, logging and rule tuning, TLS inspection of encrypted traffic, and diagnosing why traffic is dropped, passed, or unmatched.
This skill is a router. Each customer task maps to a reference file under references/. Read the
matching reference in full before acting, then follow its constraints and steps. The reference
files are self-contained: each carries its own decision tables, constraints, procedure, and
troubleshooting.