NetworkFirewallRuleGroup
Resource Icon

Resource Overview
A reusable set of criteria for inspecting and handling network traffic.
Associated Resources
Parent Resources
Connected Resources
Resource Configuration
Basic Settings
description: Rule group description (maximum 256 characters)rule_group_type: Rule group type -STATEFUL,STATELESSgenerated_rules_type: Rule format -StandardStatefulRules,DomainList,SuricataRuleStringsrule_evaluation_order: Rule evaluation order -STRICT_ORDER,DEFAULT_ACTION_ORDERcapacity: Rule group capacity (WCU) -1~30000
IP Sets (ip_set)
ip_set.cidrs: List of CIDRs used for IP set variables
Port Sets (port_set)
port_set.ports: List of port values
Domain List Rules (domain_list_rule)
domain_list_rule.domain_names: List of domain names to allow or denydomain_list_rule.protocols: Protocols to inspect -HTTP,HTTPSdomain_list_rule.action: Domain rule action -ALLOWLIST,DENYLISTdomain_list_rule.cidr_ranges: Source CIDR ranges to inspect
Suricata Rules (suricata_compatible_rule_string)
suricata_compatible_rule_string: Suricata-compatible rule string
Stateful Rules (stateful_rule)
stateful_rule.protocol: Transport protocolstateful_rule.source_ip_or_cidr: Source IP or CIDRstateful_rule.source_port: Source port or port rangestateful_rule.target_ip_or_cidr: Target IP or CIDRstateful_rule.target_port: Target port or port rangestateful_rule.traffic_direction: Traffic direction -ANY,FORWARDstateful_rule.action: Action on match -ALERT,DROP,PASS,REJECT
Stateless Rules (stateless_rule)
stateless_rule.priority: Rule prioritystateless_rule.protocols: List of protocols to inspectstateless_rule.source_ip_or_cidr: Source IP or CIDRstateless_rule.source_port: Source port or port rangestateless_rule.target_ip_or_cidr: Target IP or CIDRstateless_rule.target_port: Target port or port rangestateless_rule.action: Packet handling action -aws:pass,aws:drop,aws:forward_to_sfe
Encryption Configuration (encryption_configuration)
encryption_configuration.enabled_custom_configuration: Whether AWS managed key encryption is enabled -true,falseencryption_configuration.kms_key_name: Name of the KMS key used
Tags
tag: Tags used to categorize the resource