AWS network-firewall: Clarify when Network Firewall generates final drop rule
Summary
Adds notes explaining that the final drop rule (not matching any HTTP/TLS allowlisted FQDNs) is only generated when the firewall policy uses default action order, not strict order.
Security assessment
The note documents firewall rule evaluation behavior affecting whether a default drop rule is applied, which has security implications for traffic filtering, but it is a documentation clarification with no specific vulnerability referenced.
Evidence
Network Firewall generates the final drop rule in this listing only when the firewall policy evaluates rules in default action order. This drop rule has the message `not matching any HTTP allowlisted FQDNs`. If the policy uses strict order, Network Firewall doesn't generate this drop rule.
Diff
diff --git a/network-firewall/latest/developerguide/suricata-examples.md b/network-firewall/latest/developerguide/suricata-examples.md index f151ecc66..28fc7a04f 100644 --- a//network-firewall/latest/developerguide/suricata-examples.md +++ b//network-firewall/latest/developerguide/suricata-examples.md @@ -517,0 +518,4 @@ The following Suricata rules listing shows the rules that Network Firewall creat +###### Note + +Network Firewall generates the final drop rule in this listing only when the firewall policy evaluates rules in default action order. This drop rule has the message `not matching any HTTP allowlisted FQDNs`. If the policy uses strict order, Network Firewall doesn't generate this drop rule. For more information about rule evaluation order, see [Managing evaluation order for Suricata compatible rules in AWS Network Firewall](./suricata-rule-evaluation-order.html). + @@ -544,0 +549,4 @@ The following Suricata rules listing shows the rules that Network Firewall creat +###### Note + +Network Firewall generates the final drop rule in this listing only when the firewall policy evaluates rules in default action order. This drop rule has the message `not matching any TLS allowlisted FQDNs`. If the policy uses strict order, Network Firewall doesn't generate this drop rule. For more information about rule evaluation order, see [Managing evaluation order for Suricata compatible rules in AWS Network Firewall](./suricata-rule-evaluation-order.html). +