Skip to content

Runbook 01 Build Enterprise AWS Network Protection

Module: 08 – Network Protection

Enterprise Lab: 01

Estimated Time: 4–5 Hours

Difficulty: ⭐⭐⭐⭐☆

Estimated Cost: AWS Free Tier (AWS WAF, AWS Network Firewall, AWS Shield Advanced and some VPC Endpoint services may incur charges. Always review AWS Pricing and monitor AWS Cost Explorer.)


As a Cloud Security Engineer at CloudNova Technologies, your responsibility is to implement enterprise-grade network protection controls to defend AWS workloads from external threats and unauthorized network access.

By completing this runbook, you will learn how to:

  • Deploy AWS Network Firewall
  • Configure Firewall Policies
  • Configure Stateless Rule Groups
  • Configure Stateful Rule Groups
  • Deploy AWS WAF
  • Configure AWS Managed Rule Groups
  • Create Custom WAF Rules
  • Configure Rate Limiting
  • Enable AWS Shield
  • Configure Amazon Route 53 security
  • Configure VPC Endpoints
  • Configure AWS PrivateLink
  • Validate enterprise network protection

CloudNova Technologies is preparing to launch a global Software-as-a-Service (SaaS) platform.

The application will be accessible over the Internet and must be protected against modern web attacks including:

  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Distributed Denial of Service (DDoS)
  • Port Scanning
  • Malicious Bots
  • Credential Stuffing
  • Data Exfiltration
  • Unauthorized Network Access

As the Cloud Security Engineer, you are responsible for implementing a layered network protection strategy before the platform goes live.


Complete:

  • Module 01 – AWS Security Foundations
  • Module 02 – Identity & Access Management (IAM)
  • Module 03 – AWS Organizations & Multi-Account Security
  • Module 04 – Amazon VPC & Network Security
  • Module 05 – Amazon EC2 Security
  • Module 06 – Data Protection & Encryption
  • Module 07 – Logging, Monitoring & Threat Detection

Required:

  • AWS Account
  • Administrator Access
  • Existing VPC
  • Existing Application Load Balancer
  • Existing EC2 Application
  • AWS CLI Installed
  • Visual Studio Code

Internet
AWS Shield Standard
Amazon Route 53
AWS WAF
Application Load Balancer
AWS Network Firewall
Private Application VPC
Amazon EC2 Application Tier
Amazon RDS Database
Private AWS Service Access
EC2
├── Amazon S3 Endpoint
├── Systems Manager Endpoint
├── CloudWatch Endpoint
└── AWS PrivateLink Services

Navigate to:

AWS Console
AWS Network Firewall
Create Firewall

Configuration

Firewall Name
CloudNova-NetworkFirewall
Deployment Model
Single VPC
VPC
Production VPC
Subnets
Firewall Subnet

Terminal window
aws network-firewall create-firewall

Validate:

  • Firewall Created
  • Firewall Endpoints Available
  • VPC Association Successful

Navigate to:

AWS Network Firewall
Firewall Policies
Create Policy

Configure:

  • Stateless Rule Groups
  • Stateful Rule Groups
  • Default Actions

Review:

  • Drop
  • Pass
  • Alert

Discuss:

  • Layered Network Security
  • Firewall Policy Order
  • Enterprise Segmentation

Step 3 — Configure Stateless Rule Groups

Section titled “Step 3 — Configure Stateless Rule Groups”

Create rules to:

  • Allow HTTP
  • Allow HTTPS
  • Allow DNS
  • Allow NTP
  • Drop unwanted traffic

Review:

  • Rule Priority
  • Actions
  • Stateless Inspection

Create rules to:

  • Block known malicious IP ranges
  • Block outbound unauthorized traffic
  • Restrict database access
  • Restrict administrative ports
  • Detect suspicious traffic

Discuss:

  • Deep Packet Inspection
  • Stateful Inspection
  • Enterprise Firewall Rules

Navigate to:

AWS WAF
Web ACL
Create Web ACL

Associate with:

Application Load Balancer

Validate:

  • Web ACL Created
  • ALB Associated Successfully

Step 6 — Configure AWS Managed Rule Groups

Section titled “Step 6 — Configure AWS Managed Rule Groups”

Enable:

  • AWS Core Rule Set
  • Known Bad Inputs
  • SQL Injection Protection
  • Linux Protection
  • Anonymous IP Protection
  • Amazon IP Reputation List

Discuss:

  • Managed Rule Benefits
  • Automatic Updates
  • Reduced Operational Overhead

Create rules for:

  • SQL Injection
  • Cross-Site Scripting (XSS)
  • Geo Blocking
  • Rate Limiting
  • IP Reputation
  • User Agent Filtering

Example:

Block Requests
Rate Limit
100 Requests per 5 Minutes

Validate:

  • Rule Matching
  • Blocked Requests
  • WAF Logs

Navigate to:

AWS Shield

Review:

Shield Standard
Enabled

Discuss:

  • DDoS Protection
  • Layer 3 Protection
  • Layer 4 Protection
  • Shield Advanced Features

Create Gateway Endpoints:

  • Amazon S3

Create Interface Endpoints:

  • AWS Systems Manager
  • Amazon CloudWatch
  • AWS Secrets Manager

Validate:

  • Private Connectivity
  • No Internet Gateway Required

Terminal window
aws ec2 describe-vpc-endpoints

Navigate to:

VPC
Endpoint Services

Review:

  • Interface Endpoints
  • Endpoint Policies
  • Private Connectivity

Discuss:

  • Secure Service Access
  • Internal AWS Traffic
  • Reduced Internet Exposure

Perform validation tests.

Verify:

  • SQL Injection blocked
  • XSS blocked
  • Rate Limiting working
  • AWS Managed Rules active
  • Firewall Rules enforced
  • Private AWS Service access working
  • Internet exposure minimized

Review:

  • AWS WAF Logs
  • Firewall Logs
  • CloudWatch Logs

CloudNova Technologies is launching a global e-commerce platform serving customers across multiple regions.

Design a layered network protection architecture that includes:

  • AWS Shield
  • AWS WAF
  • AWS Network Firewall
  • Route 53 DNS Protection
  • VPC Endpoints
  • AWS PrivateLink
  • Layered Firewall Policies
  • High Availability
  • Least Privilege Network Access
  • Secure Private Connectivity

Explain how each security control protects against modern web attacks and reduces the organization’s attack surface.


Capture screenshots of:

  • AWS Network Firewall
  • Firewall Policy
  • Stateless Rule Groups
  • Stateful Rule Groups
  • AWS WAF
  • Web ACL
  • Managed Rule Groups
  • Custom Rules
  • VPC Endpoints
  • AWS PrivateLink

Submit:

  • Network Protection Architecture Diagram
  • Firewall Policy Documentation
  • WAF Configuration Report
  • Endpoint Configuration Report
  • Validation Report

Delete:

  • Test Firewall Policies
  • Test Rule Groups
  • Test Web ACLs
  • Temporary VPC Endpoints
  • Temporary Interface Endpoints
  • Test Resources

Keep:

  • Architecture Documentation
  • Security Design
  • Firewall Configuration Standards
  • Validation Results

Review AWS Cost Explorer to ensure no unnecessary resources remain.


  • AWS Network Firewall Deployed
  • Firewall Policy Configured
  • Stateless Rule Groups Created
  • Stateful Rule Groups Created
  • AWS WAF Configured
  • Managed Rule Groups Enabled
  • Custom WAF Rules Created
  • AWS Shield Reviewed
  • VPC Endpoints Configured
  • AWS PrivateLink Configured
  • Network Protection Validated

Why is a layered network defence strategy more effective than relying on a single security control?

Section titled “Why is a layered network defence strategy more effective than relying on a single security control?”

How do AWS WAF and AWS Network Firewall protect different layers of an application?

Section titled “How do AWS WAF and AWS Network Firewall protect different layers of an application?”
Section titled “Why should AWS services be accessed through VPC Endpoints and PrivateLink whenever possible?”

How would you enhance this network protection architecture for a global production environment?

Section titled “How would you enhance this network protection architecture for a global production environment?”

Enterprise Runbook 02 — Enterprise Network Protection Assessment

In the next runbook, you will assess an enterprise AWS network protection environment by reviewing AWS Network Firewall, AWS WAF, AWS Shield, Route 53, VPC Endpoints, AWS PrivateLink, firewall policies, Web ACLs, and network security controls to produce a comprehensive enterprise network protection assessment report.