Enhance TLS inspection with SNI session holding in AWS Network Firewall
Security Blog
This article discusses a new feature called SNI session holding in AWS Network Firewall that enhances TLS inspection security and control.
- SNI session holding stops TCP/TLS establishment packets from reaching the destination server until TLS inspection rules are applied
- Prevents potential security vulnerabilities by validating Server Name Indication (SNI) before establishing a connection
- Enables more precise control over outbound traffic with minimal latency
- Can be enabled when creating a TLS inspection configuration in Network Firewall
- Only applies to Suricata rules using the TLS.SNI keyword
The feature provides an additional layer of security by ensuring that connection attempts are thoroughly validated before being permitted, reducing risks from potential malicious endpoints.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Sep 25
2025
2025
AWS Network Firewall enhances application layer traffic controls
Sep 17
2025
2025
AWS Network Firewall enhances console, monitoring, and security features
Apr 1
2024
2024
TLS inspection configuration for encrypted egress traffic and AWS Network Firewall
Apr 9
2025
2025
Enhanced Network Security Control: Flow Management with AWS Network Firewall
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.