A new feature in AWS for VPC network protection. It Includes Stateful & Stateless firewall, Intrusion Prevention System (IPS, see also IDS), and Web filtering. It works with AWS Network Firewall manager for centrally applying policies across VPCs / accounts and uses a VPC endpoint and Gateway Load Balancer.
However they do not deploy resources in the firewall subnet and for High availability we must allocate a subnet per AZ.
