Migrate your AWS Network Firewall security policies to Cloud NGFW for AWS using the
Strata Cloud Manager policy migration workflow.
| Where Can I Use This? | What Do I Need? |
|
|
- Strata Cloud Manager Essential license
- Superuser, Network Administrator, or Security Administrator
role
- Supported region: Canada, India, United Kingdom, Singapore,
or United States
|
Cloud service provider (CSP) native firewall policy migration enables the automated
transfer of existing security policies from AWS Network Firewall to Cloud NGFW for
AWS through Strata™ Cloud Manager. The migration translates native cloud firewall
logic into next-generation firewall configurations so you can consolidate security
management without manually recreating rules.
The Policy Migration Engine processes your exported cloud configuration files and
converts them into reusable Strata Cloud Manager snippets. You associate these
snippets with folders linked to your Cloud NGFW resources, then push the
configuration to deploy the translated policy.
The following table outlines the AWS Network Firewall policy components supported for
automated migration to Strata Cloud Manager.
| Feature Category | Supported Components | Unsupported or Skipped Items |
| Rules |
- Stateless rules
- Stateful rules (Standard)
- Stateful rules (Domain List)
| Suricata stateful rulegroups |
| Resource Groups | Rules referencing tag-based resources (such as EC2 instances and
elastic network interfaces) via Dynamic Address Groups
(DAG) | — |