Firewall Policy Firewall Policy
Constructors
Types
Properties
Set of actions to take on a packet if it does not match any stateful rules in the policy. This can only be specified if the policy has a stateful_engine_options
block with a rule_order
value of STRICT_ORDER
. You can specify one of either or neither values of aws:drop_strict
or aws:drop_established
, as well as any combination of aws:alert_strict
and aws:alert_established
.
Set of actions to take on a packet if it does not match any of the stateless rules in the policy. You must specify one of the standard actions including: aws:drop
, aws:pass
, or aws:forward_to_sfe
. In addition, you can specify custom actions that are compatible with your standard action choice. If you want non-matching packets to be forwarded for stateful inspection, specify aws:forward_to_sfe
.
Set of actions to take on a fragmented packet if it does not match any of the stateless rules in the policy. You must specify one of the standard actions including: aws:drop
, aws:pass
, or aws:forward_to_sfe
. In addition, you can specify custom actions that are compatible with your standard action choice. If you want non-matching packets to be forwarded for stateful inspection, specify aws:forward_to_sfe
.