Removing any one layer removes protection against a specific attack class.
Network Firewall now attaches natively to Transit Gateway — no dedicated inspection VPC required.
Security GroupsPer-instance, port/protocol
NACLsPer-subnet, coarse and stateless
AWS Network FirewallVPC perimeter, deep packet inspection
AWS WAFLayer 7 HTTP threats at the edge
Shield AdvancedLarge-scale DDoS at the edge