Managed Network Firewall across clouds
The managed, stateful inspection appliance - AWS Network Firewall, Azure Firewall, OCI Network Firewall - that sits in the path of traffic, can open TLS and inspect what is inside, and bills by the hour whether or not a rule matches.
3 verified modules - all static-validated and publish-checked; live-test pending.
Compare by provider
| Provider | Module | Verification |
|---|---|---|
| AWS | Network Firewall with a Policy that Fails Closed | static-validated |
| Azure | A Firewall that Blocks rather than Narrates | static-validated |
| Oracle Cloud | A Network Firewall that Prevents rather than Detects | static-validated |
How to choose
Start with the bill: each is priced per hour per deployment plus per gigabyte, and a firewall with no rules costs the same as one with a thousand. Then compare how traffic is made to pass through it (a route table, a hub, a subnet), what it can inspect once TLS is opened, and whether it writes a log anyone reads.
When not to use
An appliance in the path is only a control for the traffic routed through it. Every one of these can be deployed, healthy and inspecting nothing, because the route that sends packets its way is a separate resource.