AWS Network Firewall and VPN Gateway


I want to be able to use FQDN filtering on outbound traffic over the VPN. I can't get it to work. It looks like AWS Network Firewall doesn't support VPN Gateways. Is this correct and is there some way around it? A transit gateway perhaps?

1 Answer

You're correct; the workaround today is to use a Transit Gateway; attach the VPN to the Transit Gateway; and then inspect using Network Firewall either within the source VPC or by using route tables on the Transit Gateway to send traffic to an inspection VPC.

answered 16 days ago

