AWS Network Firewall now uses “Application drop established (server-directed only)” as the default stateful action for all newly created firewall policies, replacing the previous default of “Application drop established (bidirectional)” (formerly named “Application layer drop established”). No action is required to benefit from this change when creating new policies.
AWS Network Firewall is a managed service that lets you deploy network protections across your Amazon VPCs. Previously, the “Application drop established (bidirectional)” default could silently drop legitimate server-to-client TCP packets, such as window updates, keep-alives, and resets — causing intermittent connection failures that were difficult to diagnose. With the safer default now in place, new policies avoid this issue.
If your existing environment requires “Application drop established (bidirectional)” to support post-quantum cryptography (PQC) fragmented TLS handshakes, refer to our documentation for guidance on on switching to “Application drop established (server-directed only)” or adding the “to_server” flag to your TCP drop rules so legitimate flow control packets are not blocked.
This update is available in all AWS Regions where AWS Network Firewall is offered. To get started, see Managing evaluation order for Suricata compatible rules in the AWS Network Firewall service documentation.
Categories: marketing:marchitecture/security-identity-and-compliance,general:products/aws-network-firewall
Source: Amazon Web Services
Latest Posts
- (Updated) 2026 Microsoft 365 Packaging Update [MC1304290]
![(Updated) 2026 Microsoft 365 Packaging Update [MC1304290] 2 pexels pixabay 39531](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Automatic recording and transcription for Teams Call Queues [MC1401299]
![Automatic recording and transcription for Teams Call Queues [MC1401299] 3 cliff 5826916 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Copilot Cowork generally available today [MC1393471]
![(Updated) Copilot Cowork generally available today [MC1393471] 4 graffiti 6656040 1920](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Teams: Location-Based Routing update blocks OS default location for Operator Connect in India [MC1401300]
![Microsoft Teams: Location-Based Routing update blocks OS default location for Operator Connect in India [MC1401300] 5 pexels inspiredimages 133190](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![(Updated) 2026 Microsoft 365 Packaging Update [MC1304290] 2 pexels pixabay 39531](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-pixabay-39531-150x150.webp)
![Automatic recording and transcription for Teams Call Queues [MC1401299] 3 cliff 5826916 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/cliff-5826916_1920-150x150.webp)
![(Updated) Copilot Cowork generally available today [MC1393471] 4 graffiti 6656040 1920](https://mwpro.co.uk/wp-content/uploads/2025/06/graffiti-6656040_1920-150x150.webp)
![Microsoft Teams: Location-Based Routing update blocks OS default location for Operator Connect in India [MC1401300] 5 pexels inspiredimages 133190](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-inspiredimages-133190-150x150.webp)
