{"id":11429,"date":"2022-04-22T12:21:46","date_gmt":"2022-04-22T12:21:46","guid":{"rendered":"https:\/\/blog.cloudthat.com\/?p=11429"},"modified":"2024-06-25T11:02:04","modified_gmt":"2024-06-25T11:02:04","slug":"improve-your-network-security-posture-with-amazon-vpc-network-access-analyzer","status":"publish","type":"blog","link":"https:\/\/www.cloudthat.com\/resources\/blog\/improve-your-network-security-posture-with-amazon-vpc-network-access-analyzer","title":{"rendered":"Improve Your Network Security Posture With Amazon VPC Network Access Analyzer"},"content":{"rendered":"<table style=\"height: 334px;\" border=\"3\" width=\"524\">\n<tbody>\n<tr>\n<td>\n<h2><span style=\"color: #000080;\"><strong>TABLE OF CONTENT<\/strong><\/span><\/h2>\n<\/td>\n<\/tr>\n<tr>\n<td><a href=\"#introduction\">1. Introduction<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#overview\">2. Overview of VPC Network Access Analyzer<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#supportedsource\">3. Supported Source and Destination Resources in Findings<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#supportedpath \">4. Supported Path Resources in Findings<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#challenges\">5. Challenges of Using Amazon VPC Network Access Analyzer<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#pricing\">6. Pricing<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#regions\">7. Regions Supported<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#stepbystepguide\">8. Step-by-Step Guide for working with Network Access Analyzer<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#samplereports\">9. Sample Reports<\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#conclusion\">10. Conclusion <\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#aboutcloudthat\">11. About CloudThat <\/a><\/td>\n<\/tr>\n<tr>\n<td><a href=\"#faqs\">12. FAQs<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2 id=\"introduction\">1. Introduction to\u00a0VPC Network Access Analyzer<\/h2>\n<p>VPC Network Access Analyzer is used to specify the desired connection between our AWS resources. We can use scopes created by Amazon, create a new scope from scratch, or copy or customize the existing scope.<\/p>\n<p>Network Access Analyzer can help us to verify the following requirements:<\/p>\n<ol>\n<li>Network Segmentation<\/li>\n<li>Internet Accessibility<\/li>\n<li>Trusted Network Path<\/li>\n<li>Trusted Network Access<\/li>\n<\/ol>\n<h3 id=\"overview\">2. Overview of VPC Network Access Analyzer:<\/h3>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc1.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11434\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc1.png\" alt=\"VPC Network Access Analyzer\" width=\"626\" height=\"255\" \/><\/a><\/p>\n<p><em>Source: amazon.docs<\/em><\/p>\n<p>Network Access Analyzer uses automated inference algorithms to analyze the network paths that packets can follow between resources on our AWS network. It then produces the results for the path that corresponds to the customer-defined network access area. It performs a static analysis on our network configuration. That is, no packets are sent within the network as part of this analysis. Network Access Analyzer only considers the network conditions described in the network configuration, so packet loss due to temporary network interruptions or service outages is not included in this analysis.<\/p>\n<h3 id=\"supportedsource\">3. Supported Source and Destination Resources in Findings:<\/h3>\n<p>Network Access Analyzer finding is a network path that a packet can take in a network. Network Access Analyzer can only produce findings for network paths that start or end at the following types of resources:<\/p>\n<ol>\n<li>Network Interfaces<\/li>\n<li>VPC Interface Endpoints<\/li>\n<li>VPC Service Endpoints<\/li>\n<li>Virtual Private Gateways<\/li>\n<li>Internet Gateways<\/li>\n<li>Transit Gateway Attachments<\/li>\n<li>VPC gateway endpoints<\/li>\n<li>VPC peering connections<\/li>\n<\/ol>\n<h3 id=\"supportedpath\">4. Supported Path Resources in Findings:<\/h3>\n<p>A Network Access Analyzer network path can pass through multiple resources from the start to the end of the network path.<\/p>\n<ol>\n<li>Internet gateways<\/li>\n<li>Load balancers (except for Gateway Load Balancers)<\/li>\n<li>NAT gateways<\/li>\n<li>Network ACLs<\/li>\n<li>Network firewalls<\/li>\n<li>Network interfaces<\/li>\n<li>VPC route tables<\/li>\n<li>Security groups<\/li>\n<li>Target groups<\/li>\n<li>Transit gateway route tables<\/li>\n<li>Transit gateway attachments<\/li>\n<li>VPC interface endpoints<\/li>\n<li>VPC gateway endpoints<\/li>\n<li>VPC endpoints services<\/li>\n<li>VPC peering connections<\/li>\n<li>Virtual private gateways<\/li>\n<\/ol>\n<h3 id=\"challenges\">5. Challenges of using Amazon VPC Network Access Analyzer:<\/h3>\n<ol>\n<li>Internet Gateway and Virtual Private Gateways<\/li>\n<li>Application Load Balancer<\/li>\n<li>Network Load Balancer<\/li>\n<li>Network Firewall<\/li>\n<li>Amazon VPC Transit Gateways<\/li>\n<li>IPv4 Only<\/li>\n<\/ol>\n<h3 id=\"pricing\">6. Pricing:<\/h3>\n<p>There is no additional charge for creating VPC. We only must pay for optional VPC capabilities as per our usage.<\/p>\n<p>We need to pay $0.002 for network assessment analyzed by Network Access Analyzer.<\/p>\n<h3 id=\"regions\">7. Regions Supported:<\/h3>\n<p>Network Access Analyzer is available in the following regions only:<\/p>\n<p><em>US East (N. Virginia), US East (Ohio), US West (N. California), US West (Oregon), Africa (Cape Town), Asia Pacific (Hong Kong), Asia Pacific (Mumbai), Asia Pacific (Seoul), Asia Pacific (Singapore), Asia Pacific (Sydney), Asia Pacific (Tokyo), Canada (Central), Europe (Frankfurt), Europe (Ireland), Europe (London), Europe (Milan), Europe (Paris), Europe (Stockholm), South America (S\u00e3o Paulo), and Middle East (Bahrain)<\/em><\/p>\n<h3 id=\"stepbystepguide\">8. Step-by-Step Guide for working with Network Access Analyzer:<\/h3>\n<p>a. To get started, log in to AWS Management Console and select VPC.<\/p>\n<p>b. Select Network Access Analyzer from Network Analysis.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc2.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11435\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc2.png\" alt=\"VPC Network Access Analyzer\" width=\"626\" height=\"213\" \/><\/a><\/p>\n<p>c. Click on Get Started; you will see pre-configured Network Access Scopes. Click on Create Network Access Scope to create a new scope.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc3.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11436\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc3.png\" alt=\"VPC Network Access Analyzer\" width=\"626\" height=\"150\" \/><\/a><\/p>\n<p>d.\u00a0Select a template to work with. We will select Empty Template and click Next.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc4.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11437\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc4.png\" alt=\"VPC Network Access Analyzer\" width=\"626\" height=\"306\" \/><\/a><\/p>\n<p>e.\u00a0Enter the name of the scope and its description.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc6.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11438\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc6.png\" alt=\"VPC Network Access Analyzer\" width=\"626\" height=\"398\" \/><\/a><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc7.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11439\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc7.png\" alt=\"VPC Network Access Analyzer\" width=\"609\" height=\"421\" \/><\/a><\/p>\n<p>f.\u00a0Select Source and Destination by resource id or type.<\/p>\n<p>We can add multiple match conditions by clicking on Add match condition.<\/p>\n<p>g. Add Tags and click on Next.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc8.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11440\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc8.png\" alt=\"VPC Network Access Analyzer\" width=\"626\" height=\"293\" \/><\/a><\/p>\n<p>h.\u00a0Now review and click on Create Network Access Scope.<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc9.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11441\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc9.png\" alt=\"VPC Network Access Analyzer\" width=\"626\" height=\"117\" \/><\/a><\/p>\n<p>i.\u00a0Select the scope and click on Analyze<\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc10.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11442\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc10.png\" alt=\"Select the scope and click on Analyze.\" width=\"626\" height=\"139\" \/><\/a><\/p>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc11.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11443\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc11.png\" alt=\"Select the scope and click on Analyze.\" width=\"626\" height=\"288\" \/><\/a><\/p>\n<p>j.\u00a0You can see the analysis report in the Latest analysis, and we can also see the Past analysis.<\/p>\n<h3 id=\"samplereports\">9. Sample Reports:<\/h3>\n<p>In our Last Analysis tab, we can see the Last analysis result, it will show No findings detected if we don&#8217;t get any issues. If we encounter any issue, we will get the Findings detected in the Last analysis result.<\/p>\n<h4>Findings:<\/h4>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc12.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11444\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc12.png\" alt=\"Select the scope and click on Analyze.\" width=\"626\" height=\"238\" \/><\/a><\/p>\n<h4>Findings details:<\/h4>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc13.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11446\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc13.png\" alt=\"Select the scope and click on Analyze.\" width=\"1436\" height=\"729\" \/><\/a><\/p>\n<h3>Filter the details by selecting the inner rings of the chart.<\/h3>\n<p><a href=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc141.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-11447\" src=\"https:\/\/content.cloudthat.com\/resources\/wp-content\/uploads\/2022\/11\/vpc141.png\" alt=\"Select the scope and click on Analyze.\" width=\"626\" height=\"214\" \/><\/a><\/p>\n<h3 id=\"conclusion\">10. Conclusion:<\/h3>\n<p>Amazon VPC Network Access Analyzer examines a wide range of AWS resources like Security Groups, Prefix lists, EC2 Instances, <a href=\"https:\/\/blog.cloudthat.com\/everything-about-aws-gateway-load-balancer\/?utm_source=blog-website&amp;utm-medium=text-link&amp;utm_campaign=everything-about-aws-gateway-load-balancer\/\" target=\"_blank\" rel=\"noopener\"><strong>AWS Load Balancer,<\/strong><\/a> VPC, NAT Gateways, Transit Gateways, and Internet Gateways, VPN Gateways, Peering Connections, Network Firewall, VPC Endpoints, VPC Endpoints Services VPC Subnets. We can use Network Access Analyzer to understand, verify and improve our network <a href=\"https:\/\/blog.cloudthat.com\/how-to-build-your-career-as-a-cybersecurity-analyst-in-2021\/\">security<\/a> or demonstrate compliance.<\/p>\n<h3 id=\"aboutcloudthat\">11. About CloudThat:<\/h3>\n<p><a href=\"https:\/\/www.cloudthat.com\/\"><strong>CloudThat\u00a0<\/strong><\/a>is\u00a0the official AWS Advanced Consulting Partner, Microsoft Gold Partner, and Training partner helping people develop knowledge on the cloud and help their businesses aim for higher goals using best in industry cloud computing practices and expertise. We are on a mission to build\u00a0a robust\u00a0cloud computing ecosystem by disseminating\u00a0knowledge on technological intricacies within the cloud space.\u00a0Our blogs, webinars,\u00a0case studies, and white papers\u00a0enable all the stakeholders in the cloud computing sphere.<\/p>\n<p>If you have any queries about or anything related to AWS services, feel free to drop in a comment. We will get back to you quickly. Visit our\u00a0<a href=\"https:\/\/www.cloudthat.com\/consulting\/\" target=\"_blank\" rel=\"noopener\"><strong>Consulting Page<\/strong><\/a>\u00a0for more updates on our customer offerings, expertise, and cloud services.<\/p>\n<h3 id=\"faqs\">12. FAQs:<\/h3>\n<ol>\n<li><span style=\"text-decoration: underline;\"><strong>Why do need a Network Access Analyzer?<br \/>\n<\/strong><\/span>Amazon VPC Network Access Analyzer helps us to identify unintended network access to our resources on AWS. With Network Access Analyzer, we can verify whether network access for our VPC resources meets our security and compliance guidelines. Network Access Analyzer can assess and identify improvements to our cloud security posture.<\/li>\n<li><span style=\"text-decoration: underline;\"><strong>What is &#8216;Findings&#8217; in Network Access Analyzer?<\/strong><\/span><br \/>\nA single Network Access Analyzer scope analysis will produce at most 100 findings. Network Access Analyzer makes a best-effort attempt to return a diverse, representative set of findings from among all possible findings. It does not ensure that the same findings will be produced if the same Network Access Scope is re-analyzed in the same network. Network Access Analyzer might produce new findings for existing Network Access Scope analyses if new configurations are supported in the future.<\/li>\n<\/ol>\n","protected":false},"author":249,"featured_media":11551,"parent":0,"comment_status":"open","ping_status":"open","template":"","blog_category":[3606,3607],"user_email":"rahulk@cloudthat.com","published_by":"324","primary-authors":"","secondary-authors":"","acf":[],"_links":{"self":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/11429"}],"collection":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog"}],"about":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/types\/blog"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/users\/249"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/comments?post=11429"}],"version-history":[{"count":2,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/11429\/revisions"}],"predecessor-version":[{"id":43285,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog\/11429\/revisions\/43285"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/media?parent=11429"}],"wp:term":[{"taxonomy":"blog_category","embeddable":true,"href":"https:\/\/www.cloudthat.com\/resources\/wp-json\/wp\/v2\/blog_category?post=11429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}