Skip to main content
Route outbound traffic from your Cloud-Prem account through AWS Network Firewall so you can inspect and filter it. The firewall is yours: you choose how it’s deployed and you control its rules. This applies to outbound traffic only. To filter inbound traffic, use custom WAF rule groups.

Choose a setup

You configure Network Firewall with variables in the bootstrap Terraform you run during deployment. The bootstrap README walks you through setting them. Use this page to choose a setup and confirm the right variables are set for it. See the variable reference for every variable. Pick one of three setups: You can add Network Firewall during your initial deployment or later. To add it or change setups later, update the variables and re-apply the bootstrap Terraform. Superblocks wires the firewall into your instance at the next deployment.

Bring your own firewall

Use a Network Firewall you already deploy and manage. Cloud-Prem routes outbound traffic from each availability zone’s public subnet through your firewall endpoint instead of directly to the internet gateway. This applies to both the control plane and Superblocks-managed data planes. The bootstrap Terraform creates the Cloud-Prem VPC, so set up the firewall in this order:
  1. Apply the bootstrap Terraform without any firewall variables. This creates the Cloud-Prem VPC.
  2. Deploy your Network Firewall with an endpoint in the Cloud-Prem VPC for each availability zone Cloud-Prem uses.
  3. Set firewall_endpoint_ids to a map of availability zone ID to firewall endpoint ID. Use AZ IDs such as usw2-az1, not AZ names such as us-west-2a.
  4. Re-apply the bootstrap Terraform. Superblocks wires the firewall into your instance at the next deployment.
Your firewall rules must allow the required outbound domains, or Cloud-Prem can’t reach the services it depends on. Don’t set enable_network_firewall when you bring your own firewall. The two options can’t be combined.

Bootstrap-managed firewall

Have the bootstrap Terraform create the firewall for you. It creates firewall subnets and endpoints in the Cloud-Prem VPC and routes outbound traffic, and the return traffic from the internet gateway, through them. It filters control plane traffic only, not traffic from Superblocks-managed data planes.
  1. Set enable_network_firewall to true.
  2. Add a cidr_firewall entry with exactly one IPv4 CIDR to each availability zone in network.subnets:
  3. Apply the bootstrap Terraform. Superblocks wires the firewall into your instance at the next deployment.
The firewall policy starts by passing all traffic. You manage the rules yourself in AWS, outside Terraform, and re-applying the bootstrap doesn’t overwrite them. Your rules must allow the required outbound domains. To have the bootstrap enforce an allowlist for you instead, use the default allowlist.

Use the default allowlist

With a bootstrap-managed firewall, you can have the bootstrap enforce the Superblocks default allowlist. Outbound control plane traffic is then blocked unless it’s going to an allowed domain. Traffic from Superblocks-managed data planes isn’t filtered.
To see the allowlist the firewall is enforcing, run:

Increase the rule group capacity

AWS fixes a rule group’s capacity when it’s created. Raise network_firewall_default_rule_group_capacity before adding enough extra domains to exceed it. Changing the capacity replaces the rule group, so apply it in two steps:
  1. Set enable_network_firewall_default_rule_groups to false and apply.
  2. Set the new capacity, set enable_network_firewall_default_rule_groups back to true, and apply again.

Required outbound domains

The Cloud-Prem control plane needs to reach these domains. The default allowlist includes all of them. If you manage your own rules, allow them yourself. Replace <region> with your Cloud-Prem AWS region. Also allow the domains your deployment reaches beyond the Superblocks platform, such as your identity provider, the APIs and databases your apps connect to, and any observability destinations you send telemetry to.

Bootstrap variable reference