本文属于机器翻译版本。若本译文内容与英语原文存在差异,则一律以英文原文为准。
AWSNetworkFirewallFullAccess
描述:授予对 AWS Network Firewall 服务的完全访问权限,包括创建、配置、管理和删除防火墙资源、策略和规则组的权限。此外,还包括修改 VPC 终端节点、S3 存储桶策略、 CloudWatch 日志配置以及为 Network Firewall 和日志传输服务创建服务相关角色的权限
AWSNetworkFirewallFullAccess
是一项 AWS 托管式策略。
使用此策略
您可以将 AWSNetworkFirewallFullAccess
附加到您的用户、组和角色。
策略详细信息
-
类型: AWS 托管策略
-
创建时间:世界标准时间 2025 年 6 月 10 日 21:52
-
编辑时间:世界标准时间 2025 年 6 月 10 日 21:52
-
ARN:
arn:aws:iam::aws:policy/AWSNetworkFirewallFullAccess
策略版本
策略版本:v1(默认)
此策略的默认版本是定义策略权限的版本。当使用该策略的用户或角色请求访问 AWS 资源时, AWS 会检查策略的默认版本以确定是否允许该请求。
JSON 策略文档
{ "Version" : "2012-10-17", "Statement" : [ { "Sid" : "NetworkFirewall", "Effect" : "Allow", "Action" : [ "network-firewall:ListAnalysisReports", "network-firewall:ListFirewallPolicies", "network-firewall:ListFirewalls", "network-firewall:ListFlowOperations", "network-firewall:ListRuleGroups", "network-firewall:ListTagsForResource", "network-firewall:ListTLSInspectionConfigurations", "network-firewall:DescribeFirewall", "network-firewall:DescribeFirewallPolicy", "network-firewall:DescribeFlowOperation", "network-firewall:DescribeLoggingConfiguration", "network-firewall:DescribeResourcePolicy", "network-firewall:DescribeRuleGroup", "network-firewall:DescribeRuleGroupMetadata", "network-firewall:DescribeTLSInspectionConfiguration", "network-firewall:GetAnalysisReportResults", "network-firewall:ListFlowOperationResults", "network-firewall:TagResource", "network-firewall:UntagResource", "network-firewall:AssociateFirewallPolicy", "network-firewall:AssociateSubnets", "network-firewall:CreateFirewall", "network-firewall:CreateFirewallPolicy", "network-firewall:CreateRuleGroup", "network-firewall:CreateTLSInspectionConfiguration", "network-firewall:DeleteFirewall", "network-firewall:DeleteFirewallPolicy", "network-firewall:DeleteResourcePolicy", "network-firewall:DeleteRuleGroup", "network-firewall:DeleteTLSInspectionConfiguration", "network-firewall:DisassociateSubnets", "network-firewall:PutResourcePolicy", "network-firewall:StartAnalysisReport", "network-firewall:StartFlowCapture", "network-firewall:StartFlowFlush", "network-firewall:UpdateFirewallAnalysisSettings", "network-firewall:UpdateFirewallDeleteProtection", "network-firewall:UpdateFirewallDescription", "network-firewall:UpdateFirewallEncryptionConfiguration", "network-firewall:UpdateFirewallPolicy", "network-firewall:UpdateFirewallPolicyChangeProtection", "network-firewall:UpdateLoggingConfiguration", "network-firewall:UpdateRuleGroup", "network-firewall:UpdateSubnetChangeProtection", "network-firewall:UpdateTLSInspectionConfiguration" ], "Resource" : [ "arn:aws:network-firewall:*:*:*" ] }, { "Sid" : "NetworkFirewallEC2", "Effect" : "Allow", "Action" : [ "ec2:DescribeRouteTables", "ec2:DescribeSubnets", "ec2:DescribeVpcEndpoints", "ec2:DescribeVpcs", "ec2:GetManagedPrefixListEntries" ], "Resource" : "*" }, { "Sid" : "NetworkFirewallCreateVpcEndpoint", "Effect" : "Allow", "Action" : [ "ec2:CreateVpcEndpoint" ], "Resource" : "arn:aws:ec2:*:*:*", "Condition" : { "StringEquals" : { "aws:RequestTag/AWSNetworkFirewallManaged" : "true" } } }, { "Sid" : "NetworkFirewallDeleteVpcEndpoints", "Effect" : "Allow", "Action" : [ "ec2:DeleteVpcEndpoints" ], "Resource" : "arn:aws:ec2:*:*:*", "Condition" : { "StringEquals" : { "aws:ResourceTag/AWSNetworkFirewallManaged" : "true" } } }, { "Sid" : "NetworkFirewallLogging", "Effect" : "Allow", "Action" : [ "logs:CreateLogDelivery", "logs:DeleteLogDelivery", "logs:GetLogDelivery", "logs:ListLogDeliveries", "logs:UpdateLogDelivery" ], "Resource" : "*" }, { "Sid" : "NetworkFirewallLoggingCWL", "Effect" : "Allow", "Action" : [ "logs:DescribeLogGroups", "logs:DescribeResourcePolicies", "logs:PutResourcePolicy" ], "Resource" : "arn:aws:logs:*:*:*" }, { "Sid" : "NetworkFirewallLoggingS3", "Effect" : "Allow", "Action" : [ "s3:GetBucketPolicy", "s3:PutBucketPolicy" ], "Resource" : "arn:aws:s3:::*", "Condition" : { "StringEquals" : { "aws:ResourceAccount" : "${aws:PrincipalAccount}" } } }, { "Sid" : "NetworkFirewallLoggingFirehose", "Effect" : "Allow", "Action" : "firehose:TagDeliveryStream", "Resource" : "arn:aws:firehose:*:*:*" }, { "Sid" : "NetworkFirewallSLR", "Effect" : "Allow", "Action" : "iam:CreateServiceLinkedRole", "Resource" : [ "arn:aws:iam::*:role/aws-service-role/network-firewall.amazonaws.com/AWSServiceRoleForNetworkFirewall" ], "Condition" : { "StringEquals" : { "iam:AWSServiceName" : "network-firewall.amazonaws.com" } } }, { "Sid" : "NetworkFirewallLogDeliverySLR", "Effect" : "Allow", "Action" : [ "iam:CreateServiceLinkedRole" ], "Resource" : [ "arn:aws:iam::*:role/aws-service-role/delivery.logs.amazonaws.com/AWSServiceRoleForLogDelivery" ] } ] }