Automations for AWS Firewall Manager
Centrally configure, manage, and audit firewall rules across all your accounts and resources
Overview
Automations for AWS Firewall Manager allows you to centrally configure, manage, and audit firewall rules across all your AWS Organizations accounts and resources in an automated way. By using this AWS Solution, you can maintain a consistent security posture across your organization.
This solution provides preset rules to configure application-level firewalls for AWS WAF, audit unused and overly permissive Amazon Virtual Private Cloud (Amazon VPC) security groups, and set up a DNS firewall to block queries for bad domains.
This solution optionally helps you create a quick baseline of firewall security rules and protect against distributed denial of service (DDoS) attacks through integration with AWS Shield Advanced. You can also automate proactive event response and health-based detection with this capability.
Note: You can use this solution if you already use Firewall Manager in your organization; however, you must install the solution in your Firewall Manager admin account. If you have not already set up Firewall Manager, refer to the implementation guide for the steps.
Benefits
How it works
You can automatically deploy this architecture using the implementation guide and the accompanying AWS CloudFormation template.

Optional stacks with automations for Shield Advanced
This architecture diagram shows an optional stack with Shield Advanced features.

About this deployment
- Version: 2.1.3
- Released: 4/2025
- Author: AWS
- Est. deployment time: 5 mins
- Estimated cost: See details
Deploy with confidence
Everything you need to launch this AWS Solution in your account is right here
Deployment options
Related content
Did you find what you were looking for today?
Let us know so we can improve the quality of the content on our pages