Amazon Web Services added a managed network firewall service to its security tool chest and says GE and the U.S. Navy are among the customers using AWS Network Firewall.

Customers can enable the service in their Amazon Virtual Private Cloud environments via the AWS Console, and it will automatically scale with network traffic to protect customers’ workloads running on AWS.

The firewall also lets customers define their own custom rules, or they can integrate with security partners and import their existing rules from these third-party vendors. At launch, several security providers have built integrations with AWS Network Firewall. These include Accenture, Alert Logic, Check Point, CrowdStrike, Datadog, Fortinet, Hashicorp, IBM, Palo Alto Networks, Rackspace, Splunk, SumoLogic, Trend Micro, and Tufin. And these integrations allow customers to incorporate the new AWS firewall into their existing security workflows for orchestration, automation, and threat detection and response.

So an integration with CrowdStrike’s Falcon security platform, for example, would allow customers to use CrowdStrike’s detections and events to program the AWS Network Firewall. Additionally, customers can export domain-based indicators of compromise from CrowdStrike’s threat intelligence to streamline incident response and create security policies.

“The integration of CrowdStrike Falcon intelligence feeds and automation capabilities for AWS Network Firewall advances protections for our joint customers across their AWS footprint, by providing a continuous line of defense from the network to the workload,” said Andrew Thomas, AWS general manager for perimeter protection in a statement.

The AWS service is available today in the US East (N. Virginia), US West (Oregon), and Europe (Dublin) regions.

AWS Partners and Competitors?

While AWS is partnering with some traditional firewall providers such as Palo Alto Networks, Fortinet, and CrowdStrike on its AWS Network Firewall, it also competes against these and other vendors like Cisco and Juniper Networks that sell virtual firewalls that run in AWS.

However, the AWS service isn’t likely to cut into these vendors’ firewall profits, said Zeus Kerravala, principal analyst at ZK Research. “People thought that when Amazon started offering virtual load balancers that it would hurt F5, and when they started offering virtual switches it would hurt Cisco, and it didn’t,” he said.

A big reason for this is that the AWS Network Firewall only works across AWS environments, and most customers’ workloads run in multiple public clouds as well as on-premises data centers.

“And security is hard. Maintaining sets of policies cross firewall is very difficult,” Kerravala said. “So if I’m already a Palo Alto or Fortinet or Cisco customer, and I’ve got my firewall rules and policies set up, the amount of work it takes to then replicate that in other firewalls is quite high.”

So while customers may use the AWS Network Firewall for development environments, or in addition to other network firewalls they have already deployed, “I don’t think you’ll see too many customers switching from a traditional one,” Kerravala said. “It’s more complementary than competitive.”