When creating a Cloud NGFW resource, you can add one or more of your AWS accounts
to its allow-list. From then on, a VPC endpoint service, corresponding to the
Cloud NGFW resource, will manifest in your (allow-listed) AWS account(s). You
can then create
endpoints in your VPC to redirect
traffic to the Cloud NGFW resources.