Advanced Service Networking
Five layers, five jobs
30 / 44

Removing any one layer removes protection against a specific attack class.

Network Firewall now attaches natively to Transit Gateway — no dedicated inspection VPC required.

Security GroupsPer-instance, port/protocol
NACLsPer-subnet, coarse and stateless
AWS Network FirewallVPC perimeter, deep packet inspection
AWS WAFLayer 7 HTTP threats at the edge
Shield AdvancedLarge-scale DDoS at the edge