Home icon

Simplifying policy management with URL and Domain Category filtering on AWS Network Firewall

Security Blog



This article explains how to use URL and domain category filtering in AWS Network Firewall to simplify policy management without maintaining manual domain lists.

  • AWS-managed categories automatically stay current as new domains register
  • Domain category filtering uses TLS SNI field without requiring decryption
  • Create rules using console builder or Suricata-compatible rule strings
  • Manage exceptions for approved services within blocked categories
  • Monitor traffic patterns using CloudWatch Logs Insights queries
  • Single domains can belong to multiple categories simultaneously
  • Logs include aws_category field for compliance and usage tracking

Domain category filtering enables organizations to control access to broad website classes like AI services without maintaining individual blocklists, with automatic updates and built-in audit trails.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Feb 21
2025
From log analysis to rule creation: How AWS Network Firewall automates domain-based security for outbound traffic
Feb 19
2025
AWS Network Firewall introduces automated domain lists and insights
Feb 28
2025
AWS Network Firewall simplifies policy management with enhanced console features
Nov 19
2025
Simplify cloud security with managed rules from AWS Marketplace for AWS Network Firewall

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.