netfw-policy-default-action-full-packets - AWS Config

netfw-policy-default-action-full-packets

Checks if an AWS Network Firewall policy is configured with a user defined default stateless action for full packets. This rule is NON_COMPLIANT if default stateless action for full packets does not match with user defined default stateless action.

Identifier: NETFW_POLICY_DEFAULT_ACTION_FULL_PACKETS

Resource Types: AWS::NetworkFirewall::FirewallPolicy

Trigger type: Configuration changes

AWS Region: All supported AWS regions

Parameters:

statelessDefaultActions
Type: CSV

Comma-separated list of values. You can select a max of two. Valid values include 'aws:pass', 'aws:drop', and 'aws:forward_to_sfe'.

AWS CloudFormation template

To create AWS Config managed rules with AWS CloudFormation templates, see Creating AWS Config Managed Rules With AWS CloudFormation Templates.