Beyond IPs with AWS Network Firewall at Phoenix Summit 2025
A Blue Team Day session at Phoenix Summit 2025 on improving cloud perimeter controls by combining logging, detection, and automated blocking workflows in AWS Network Firewall.

Topic: Automated domain and geo-based filtering with AWS Network Firewall
Target audience: Security Engineers, Cloud Architects, DevSecOps Teams
Location: Phoenix Summit 2025, Dhaka
Related stack: AWS, AWS Network Firewall, Cloud Security, DevSecOps
Event link: https://www.linkedin.com/feed/update/urn:li:activity:7332857928791588864/
Photo gallery



Session overview
This session covered how teams can move beyond static IP-only controls and adopt adaptive perimeter protection for cloud workloads. The talk focused on practical ways to log, detect, and automatically block risky domain and geo patterns using AWS Network Firewall.
Topics covered
- Limitations of IP-only filtering in modern cloud traffic patterns.
- Domain and geo-based filtering strategies for layered defense.
- Detection patterns from firewall logs and traffic telemetry.
- Automation workflows to convert detections into enforceable blocks.
- Operating guardrails across blue-team workflows and incident response.
Key takeaways
- Effective cloud filtering requires combining visibility, detection logic, and automated response.
- Domain and geo controls can reduce threat exposure when tuned with operational context.
- Security controls are stronger when integrated with repeatable DevSecOps workflows.
Source
Original LinkedIn activity post: https://www.linkedin.com/feed/update/urn:li:activity:7332857928791588864/