- Newest
- Most votes
- Most comments
In AWS Firewall Manager, you can have up to 3 primary security groups per common security group policy by default. This limit is adjustable, meaning you can request an increase if needed.
It's important to note that these primary security groups must be created by the Firewall Manager administrator account, although they can reside in any Amazon VPC instance within that account. When you create a common security group policy, Firewall Manager replicates these primary security groups to every Amazon VPC instance within the policy scope and associates the replicated security groups to in-scope accounts and resources.
If you find that you need more than the default limit of 3 primary security groups in your policy, you can submit a request to increase this quota through the AWS Service Quotas console. This flexibility allows you to adapt the service to your specific security needs as your infrastructure grows or becomes more complex.
Sources
Using common security group policies with Firewall Manager - AWS WAF, AWS Firewall Manager, and AWS Shield Advanced
AWS Firewall Manager endpoints and quotas - AWS General Reference
Relevant content
- asked 4 months ago
- asked 7 months ago
- asked 3 years ago