Overview
AWS Firewall Manager is a security management service that centrally configures and manages firewall rules across your AWS accounts and applications within AWS Organizations. It simplifies security policy enforcement and ensures compliance.
How It Works
- Central Administration: Use a master account to manage firewall rules across multiple AWS accounts.
- Managed Rules: Deploy pre-configured WAF rules and enforce security policies.
- Baseline Security Groups: Centrally deploy security group rules to protect your VPCs.
Benefits
- Granular Control: Fine-tune security group rules for different resources.
- Cross-Account Access: Trust roles across AWS accounts for seamless management.
- Temporary Permissions: Roles allow short-term access via session tokens.
- Continual Auditing: Identify and clean up unused or risky security groups.
Limitations
- No User Groups as Principals: Groups relate to permissions, not authentication.
- No Wildcards in Principal Names: Exact matches required for principal names.
Features
- Role Trust Policies: Specify who can assume an IAM role.
- Resource-Based Policies: Define permissions for resources (e.g., S3 buckets).
- Cross-Account Access: Trust roles across different AWS accounts.
- Federated User Sessions: Temporary access for external identities.
- Service Principals: Allow AWS services to act on your behalf.