netfw-policy-default-action-full-packets
Checks if an AWS Network Firewall policy is configured with a user defined default stateless action for full packets. This rule is NON_COMPLIANT if default stateless action for full packets does not match with user defined default stateless action.
Identifier: NETFW_POLICY_DEFAULT_ACTION_FULL_PACKETS
Resource Types: AWS::NetworkFirewall::FirewallPolicy
Trigger type: Configuration changes
AWS Region: All supported AWS regions
Parameters:
- statelessDefaultActions
- Type: CSV
-
Comma-separated list of values. You can select a max of two. Valid values include 'aws:pass', 'aws:drop', and 'aws:forward_to_sfe'.
AWS CloudFormation template
To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.