---
title: "AWS Network Firewall updates default drop action for improved connection reliability"
url: https://daily.dev/posts/aws-network-firewall-updates-default-drop-action-for-improved-connection-reliability-tri37jef9
source_url: https://aws.amazon.com/about-aws/whats-new/2026/06/aws-network-firewall-updates-default-drop-action
type: article
source: "AWS"
published: 2026-06-22T18:07:30.482Z
updated: 2026-06-22T18:41:27.021Z
tags: ["security", "aws", "quantum-computing"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# AWS Network Firewall updates default drop action for improved connection reliability

**[AWS](https://daily.dev/sources/aws)** · 2 min read · 0 upvotes · 0 comments

## Summary

AWS Network Firewall has changed its default stateful action for newly created firewall policies from 'Application drop established (bidirectional)' to 'Application drop established (server-directed only)'. The previous default could silently drop legitimate server-to-client TCP packets like window updates, keep-alives, and resets, causing hard-to-diagnose intermittent connection failures. No action is needed for new policies to benefit. Existing environments using the bidirectional drop for post-quantum cryptography fragmented TLS handshakes should consult documentation to migrate or add the 'to_server' flag to TCP drop rules. The change is available in all AWS regions where Network Firewall is offered.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://aws.amazon.com/about-aws/whats-new/2026/06/aws-network-firewall-updates-default-drop-action>

## Similar posts on daily.dev

- [Active threat defense now enabled by default in AWS Network Firewall](https://daily.dev/posts/active-threat-defense-now-enabled-by-default-in-aws-network-firewall-ybnzvreeq) · AWS · 0 upvotes · 0 comments
- [AWS Network Firewall announces new price reductions](https://daily.dev/posts/aws-network-firewall-announces-new-price-reductions-xcrc9lqru) · AWS · 3 upvotes · 0 comments
- [\[Preview Announcement\] Re-introducing Forward Proxy as AWS Network Firewall Functionality](https://daily.dev/posts/preview-announcement-re-introducing-forward-proxy-as-aws-network-firewall-functionality-javwejhmn) · AWS · 0 upvotes · 0 comments
- [AWS Network Firewall now supports firewall state change notifications through Amazon EventBridge](https://daily.dev/posts/aws-network-firewall-now-supports-firewall-state-change-notifications-through-amazon-eventbridge-lz0hqnspn) · AWS · 0 upvotes · 0 comments
- [AWS Network Firewall now supports GenAI traffic visibility and enforcement with Web category-based filtering](https://daily.dev/posts/aws-network-firewall-now-supports-genai-traffic-visibility-and-enforcement-with-web-category-based-f-adbvgaizy) · AWS · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#aws](https://daily.dev/tags/aws), [#quantum-computing](https://daily.dev/tags/quantum-computing)

[View this post on daily.dev](https://daily.dev/posts/aws-network-firewall-updates-default-drop-action-for-improved-connection-reliability-tri37jef9)
