AWS Network Firewall has changed its default stateful action for newly created firewall policies from 'Application drop established (bidirectional)' to 'Application drop established (server-directed only)'. The previous default could silently drop legitimate server-to-client TCP packets like window updates, keep-alives, and resets, causing hard-to-diagnose intermittent connection failures. No action is needed for new policies to benefit. Existing environments using the bidirectional drop for post-quantum cryptography fragmented TLS handshakes should consult documentation to migrate or add the 'to_server' flag to TCP drop rules. The change is available in all AWS regions where Network Firewall is offered.
256 Impressions