AWS requires that all API requests must be cryptographically
signed using credentials issued by them. In order to enable API
permissions for the VM-Series firewalls that will be deployed as an
HA pair, you must create a policy and attach that policy to a role
in the
AWS Identity and Access Management
(IAM) service. The role must be attached to the VM-Series
firewalls at launch. The policy gives the IAM role permissions for
initiating API actions for detaching and attaching network interfaces
from the active peer in an HA pair to the passive peer when a failover
is triggered.