AWS History and Timeline regarding AWS Shield and AWS Firewall Manager - Overview, Functions, Features, Summary of Updates, and Introduction

First Published:
Last Updated:

This article is part of a series exploring the history and timeline of AWS services, following previous articles on Amazon S3, Amazon RDS, AWS Lambda, and AWS WAF, among others. This time, the focus is on two services: AWS Shield and AWS Firewall Manager.

This is the first article in the series to cover two services. There are two reasons for that, and neither of them is the volume of material.

Firstly, a previous article, AWS History and Timeline regarding AWS WAF, explicitly mentions these two services, stating:

> A full history of Shield and Firewall Manager is out of scope for this AWS WAF timeline

However, the second reason is more fundamental. AWS Firewall Manager does not stand on its own as the subject of a timeline. It inspects nothing itself. It is the layer that distributes the defenses of other services across an organization. Write its timeline and most of the entries end up pointing at another service's launch. "When Firewall Manager gained a capability" can only be written as "when Firewall Manager could start distributing something."

The history of AWS Shield takes a different form. Shield does its own protecting, so its history is the list of what it can protect. As of December 2016, it protected Elastic Load Balancing, Amazon CloudFront, and Amazon Route 53. Amazon EC2 instances and Network Load Balancers, both reached through an Elastic IP address, joined that list next, and AWS Global Accelerator standard accelerators followed.

One word, protection, covers both services, and their histories have completely different shapes. This asymmetry is precisely why they are being presented together in a single article.

What AWS Shield Can Protect and What AWS Firewall Manager Can Distribute
What AWS Shield Can Protect and What AWS Firewall Manager Can Distribute
This article is a timeline. The previously published AWS Network and Application Protection Decision Guide handles where the four protection layers sit on a request path and what each one does not stop. This article does not re-explain those relationships; it simply lists when each service gained specific capabilities.

The historical overview of AWS WAF itself is available in the previously published AWS History and Timeline regarding AWS WAF. This article does not reiterate the history of AWS WAF. The fact that Firewall Manager gained the ability to distribute AWS WAF policies belongs to Firewall Manager's history, though, so this article carries it. For the same reason, AWS History and Timeline regarding AWS Network Firewall carries the feature additions to AWS Network Firewall itself, and the previously published AWS History and Timeline regarding Amazon Route 53 carries those to Amazon Route 53 Resolver DNS Firewall. For each of those, this article carries a single entry saying that Firewall Manager could start distributing that policy.

This article does not discuss pricing. It gives no figures, and no amounts that cost protection returns. Where the structure of the arrangement matters, it goes no further than the fact that Shield Advanced is a subscription. It does not cover how attacks are carried out either.

The specifications listed in this article were verified against official AWS documentation as of August 31, 2026. A transition runs across 2026 and 2027 in particular, so the state of these services will move after this article is published. Confirm against primary sources before you make a design decision.

Background and Method of Creating AWS Shield and AWS Firewall Manager Historical Timeline

There are three reasons for creating this timeline.

First, neither of these two services has a timeline of its own. AWS itself combines AWS WAF, AWS Shield Advanced, AWS Shield network security director, and AWS Firewall Manager into a single developer guide, with the histories of all four services intertwined in a single Document history. There is no readily available document that extracts only the entries for Shield and Firewall Manager and arranges them in chronological order.

Second, it is difficult to determine when and how the range of resource types protected by Shield Advanced expanded. The current list includes both "resources that can be directly specified" and "resources protected via Elastic IP addresses," but this distinction originates from a specific announcement in November 2017. The list alone does not say why it takes that shape.

Third, the order in which Firewall Manager's policy categories arrived traces the order AWS's own protection services arrived in, for the four categories that pair with an AWS launch. By listing these additions, it becomes apparent that the interval before the distribution layer caught up has shrunk from years to days.

This article draws upon three primary sources:

  • AWS What's New
  • AWS WAF, AWS Firewall Manager, AWS Shield Advanced, and AWS Shield network security director Developer Guide Document history
  • AWS Security Blog and AWS News Blog

The dates listed for each entry are aligned with the dates indicated in the source document they reference. There are instances where AWS What's New and the Developer Guide Document history provide different dates for the same feature. In those cases the entry takes one of them, and the source it cites is the one that gives that date. The year and month embedded in a What's New URL path is not the publication date, so this article never reads a date from there.

Filtered by tag, What's New returns 44 entries for AWS Shield and 57 for AWS Firewall Manager. The tags alone drop announcements, though. The 2019 announcement that AWS Firewall Manager had gained Shield Advanced policies carries neither tag. The Document history records that change, and from there you can reach the What's New announcement itself. This is why the three sources have to be cross-referenced.

This timeline does not carry every update to AWS Shield and AWS Firewall Manager. As a general rule, it drops announcements that only add Regions. What is kept is the entries where what can be protected changed, where what can be distributed changed, and where the availability state changed.

⚠ Some of the older AWS What's New pages are no longer served. Within this article, five entries fall into this category; clicking their links leads to AWS index pages rather than the original announcement. The original URLs stay as they are. The dates and the wording of those entries were checked against the publication timestamps and bodies that the What's New API still holds.

Each row includes a "Service" column, which takes on one of two values: Shield or Firewall Manager. The table can be sorted by clicking the column headers; sorting by "Service" allows you to read through all entries for a single service at a time.

AWS Shield was initially announced on December 1, 2016, and AWS Firewall Manager was announced on April 4, 2018. The two are one year and four months apart.

AWS Shield and AWS Firewall Manager Historical Timeline (Updates from December 1, 2016)

The following is a timeline of features for AWS Shield and AWS Firewall Manager. It is the tenth year since the first announcement.

Use the following index to jump to a year.

  • 2016 - AWS Shield appears with two tiers
  • 2017 - Protecting a resource through an Elastic IP address is born
  • 2018 - AWS Firewall Manager appears as the layer that distributes AWS WAF
  • 2019 - What it can distribute starts widening beyond AWS WAF
  • 2020 - Network Firewall policies arrive, and Shield's visibility opens to every customer
  • 2021 - DNS Firewall policies arrive, and Shield Advanced starts writing into AWS WAF
  • 2022 - Third-party firewalls join what can be distributed
  • 2023 - Administration can be split up, and automatic mitigation starts narrowing in on known attack sources
  • 2024 - Network ACL policies arrive
  • 2025 - Automatic Layer 7 mitigation moves to an AWS WAF managed rule group, and the network security director arrives in preview
  • 2026 - The network security director widens, and Shield Advanced's automatic mitigation gets an end date

DateServiceSummary
2016-12-01ShieldAWS Shield was announced. It arrived with two tiers: AWS Shield Standard, which is available to all AWS customers at no additional cost, and a subscription-based AWS Shield Advanced. Advanced initially provided protection for Elastic Load Balancing, Amazon CloudFront, and Amazon Route 53, and it was also announced that AWS WAF would be included at no additional cost. References: Introducing AWS Shield
2017-06-01ShieldAWS Shield became a HIPAA-eligible service. In the same announcement, Amazon CloudFront, Amazon S3 Transfer Acceleration, and AWS WAF were also added to the list. References: Amazon CloudFront, Amazon S3 Transfer Acceleration, AWS WAF, and AWS Shield are now HIPAA eligible
2017-11-01ShieldThe global threat environment dashboard was added to Shield Advanced. It provides visibility into the largest attacks, top attack vectors, and relative frequency of large-scale attacks across Amazon CloudFront, Elastic Load Balancing, and Amazon Route 53. This update introduced a feature allowing users to see what's happening outside of their own resources. References: Global Threat Environment Dashboard: View DDoS Attack Trends Across AWS
2017-11-21ShieldShield Advanced could now protect Amazon EC2 instances and Network Load Balancers. The protection works indirectly. When you enable Shield Advanced on an Elastic IP address attached to an internet-facing EC2 instance or Network Load Balancer, Shield Advanced identifies the type of resource behind that Elastic IP address and applies the appropriate defenses. The current list of protected resource types still carries Amazon EC2 instances and Network Load Balancers as protected through association to Amazon EC2 Elastic IP addresses, because this protection method has continued. References: AWS Shield Adds Advanced DDoS Protection for EC2 and Network Load Balancer
2018-02-08ShieldAWS Shield API calls could now be recorded in AWS CloudTrail. References: AWS Shield now Integrated with AWS CloudTrail
2018-03-22ShieldSeveral resources could now be designated for protection at once. Through the "Protected Resources" tab in the console, you can select resources by Region or enter ARNs in bulk. This is the flip side of the fact that Shield Advanced protects only the resources you name explicitly. References: AWS Shield Advanced Now Allows Protecting All Resources At Once
2018-04-04Firewall ManagerAWS Firewall Manager was announced. This management tool allows you to centrally configure AWS WAF rules across multiple accounts within an organization, ensuring that new applications and resources continue to receive the same rules. Initially, it only supported AWS WAF rules, and was limited to Application Load Balancers and Amazon CloudFront. References: Introducing AWS Firewall Manager
2018-06-05ShieldAn onboarding wizard that walks you through subscribing to Shield Advanced was added. This two-step process involves selecting the resources you want to protect and registering emergency contacts, as well as granting IAM permissions to the response team. This announcement refers to the response team as the AWS DDoS Response Team (DRT). References: AWS Shield Advanced Announces New Onboarding Wizard
2018-08-07ShieldAWS Config could now record configuration changes to AWS Shield. The history of settings, including which resources are protected, is now retained for auditing and troubleshooting purposes. References: AWS Config Adds Support for AWS Shield
2018-08-16ShieldThe onboarding wizard could now create rate-based rules and Amazon CloudWatch alarms. References: Now Easily Create Rate-Based Rules and Amazon CloudWatch Alarms with AWS Shield Advanced
2018-09-12Firewall ManagerPolicy scope gained account inclusion and exclusion. You could now apply AWS WAF rules to a subset of accounts within an organization, rather than all accounts. How far to distribute is a design question that a distribution layer carries from its first year. References: AWS Firewall Manager Supports Scoping Policy By Accounts
2018-10-29Firewall ManagerA single policy could now hold multiple rule groups. You can now distribute a combination of managed rules from the AWS Marketplace and your own custom rules. References: AWS Firewall Manager Now Supports Multiple AWS WAF Rule Groups
2018-12-14ShieldShield Advanced could now protect AWS Global Accelerator. When you enable Shield Advanced for an accelerator, it identifies the type of underlying resources and applies protection accordingly. As the current list spells out, this covers standard accelerators only; custom routing accelerators are not included. References: AWS Shield Adds Advanced DDoS Protection for AWS Global Accelerator
2019-02-21ShieldThe default limit rose to 1,000 protected resources per resource type. That default is still in place, and an increase can be requested through the Service Quotas console. References: AWS Shield Increases Default Resource Limits For Advanced Protection
2019-03-28Firewall ManagerThe Shield Advanced policy was added. This is the first day it could distribute something other than AWS WAF. It automatically discovers existing and new resources within your organization and applies Shield Advanced protection, or you can target a subset using tags. Since Shield Advanced only protects explicitly designated resources, this introduces a layer that can assume responsibility for those designations across your organization. The date for this entry follows the What's New documentation. The Developer Guide's Document history records this change as March 15, 2019. References: Announcing AWS Firewall Manager Support For AWS Shield Advanced
2019-10-10Firewall ManagerThe Amazon VPC security group policy was added. This allows you to centrally configure security groups within your organization and continuously audit for overly permissive rules or misconfigurations. The distribution layer moved outside the protection services of AWS WAF and Shield Advanced and began handling the basic building blocks of a VPC. References: AWS Firewall Manager now supports management of Amazon VPC security groups
2019-12-18Firewall ManagerIntegration with AWS Security Hub was added. Findings related to resources not protected by AWS WAF rules or not protected by Shield Advanced are now sent to Security Hub. A distribution layer also has a face that reports what is missing after it has distributed. References: AWS Security Hub integrates with AWS Firewall Manager
2020-02-14ShieldHealth-based detection was added. When associating Amazon Route 53 health checks with protected resources, detection and mitigation accuracy is improved. This mechanism will later serve as a prerequisite for proactive engagement. References: AWS Shield Advanced now supports Health Based Detection
2020-02-17Firewall ManagerPolicies could now be managed through AWS CloudFormation. References: AWS Firewall Manager now supports AWS CloudFormation
2020-03-31Firewall ManagerThe new AWS WAF and AWS Managed Rules became distributable. Existing policies for AWS WAF Classic remain in place, resulting in a single "AWS WAF policy" category that encompasses two generations. This structure continues to be in effect. References: AWS Firewall Manager support for AWS WAF and AWS Managed Rules
2020-04-22Firewall ManagerPolicy scope could now be set with AWS Organizations organizational units. When an OU is specified, it applies to all child OUs and accounts within that OU, including those added later. References: AWS Firewall Manager now supports organizational units for policy scoping
2020-06-09ShieldProactive engagement was added. If an Amazon Route 53 health check associated with a protected resource becomes unhealthy during a Shield Advanced detection event, the response team will contact you directly. At the time of this announcement, the team was known as the DDoS Response Team (DRT), which has since been renamed to the Shield Response Team (SRT). References: AWS Shield Advanced now supports proactive response to events
2020-07-08Firewall ManagerManaged rules for auditing VPC security groups were added. Using a managed list of applications and protocols, you can identify security groups that are allowing unexpected ports or protocols. References: AWS Firewall Manager launches managed rules to audit VPC security groups
2020-07-30Firewall ManagerAWS WAF logs could now be collected centrally. References: AWS Firewall Manager now supports centralized logging of AWS WAF logs
2020-08-21Firewall ManagerCommon security group policies could now cover Application Load Balancers and Classic Load Balancers. References: AWS Firewall Manager now supports security groups on Application Load Balancers and Classic Load Balancers
2020-10-26ShieldGlobal and per-account event summaries opened to all AWS customers. The preview of the global threat environment dashboard, previously a feature of AWS Shield Advanced, is now accessible from the Getting Started page in the AWS Shield console. This is one of the few entries where visibility widened on the AWS Shield Standard side. References: AWS Shield now provides global and per-account event summaries to all AWS customers
2020-11-16ShieldProtection groups were introduced. These allow you to group multiple protected resources into a single unit, aligning detection and mitigation scope at the application level. Once configured, any newly protected resources will automatically be included. References: Announcing protection groups for AWS Shield Advanced
2020-11-18Firewall ManagerThe Network Firewall policy was added. This allows you to distribute Network Firewall rules across accounts and organizational units within your organization. While AWS Network Firewall was officially announced on November 19, 2020, the distribution layer was announced one day earlier. References: AWS Firewall Manager now supports centralized management of AWS Network Firewall
2021-01-25ShieldMitigation metrics and network traffic timelines were added. References: AWS Shield Advanced now provides mitigation metrics and network traffic timelines
2021-03-05ShieldProtected resources and protection groups could now be tagged. This allows you to restrict changes to the protection settings of critical resources using IAM policies. References: AWS Shield Advanced now supports resource tagging
2021-04-01Firewall ManagerThe Amazon Route 53 Resolver DNS Firewall policy was added. You can now centrally manage DNS Firewall rules for VPCs within your organization. The announcement of DNS Firewall itself was on March 31, 2021, and the general availability announcement was on April 7, 2021. The distribution layer was therefore ready before the defense it distributes became generally available. References: AWS Firewall Manager now supports centralized management of Amazon Route 53 Resolver DNS Firewall
2021-04-02Firewall ManagerAWS WAF Bot Control could now be deployed across an organization from one place. References: AWS Firewall Manager now supports centralized deployment of the new AWS WAF Bot Control across your organization
2021-04-30Firewall ManagerThe administrator account for Firewall Manager became a delegated administrator in AWS Organizations. As a result of this change, the administrator account is required to specify member accounts other than the organization's management account. The distribution layer's dependency on AWS Organizations shows up here in the shape of its permissions. References: Document history - AWS WAF, AWS Firewall Manager, AWS Shield Advanced, and AWS Shield network security director Developer Guide
2021-07-08Firewall ManagerNetwork Firewall policies gained monitoring of the VPC route tables. When the routes are misconfigured, the administrator gets a remediation recommendation. Traffic does not reach Network Firewall unless the route tables are rewritten, so a distribution layer needs a way to check whether what it distributed is actually in the path. References: AWS Firewall Manager now supports central monitoring of VPC routes for AWS Network Firewall
2021-07-09ShieldAWS WAF logging stopped being a requirement for web application layer event response. If proactive engagement is enabled, the response team can begin analyzing AWS WAF request data when Shield detects an event and an unhealthy health check. References: AWS Shield Advanced no longer requires AWS WAF logging for web-application layer event response
2021-08-25Firewall ManagerProtections could now be removed automatically from resources that fall outside the scope of a policy. A distribution layer hands things out, and it also takes back what it handed out. References: Document history - AWS WAF, AWS Firewall Manager, AWS Shield Advanced, and AWS Shield network security director Developer Guide
2021-10-05Firewall ManagerAWS Network Firewall logs could now be centralized. References: AWS Firewall Manager now supports centralized logging of AWS Network Firewall logs
2021-12-01ShieldAutomatic application layer DDoS mitigation was added, with Amazon CloudFront as the first target. When AWS Shield Advanced detects signs of Layer 7 DDoS attacks, it automatically creates AWS WAF rules within the user's web ACLs. It starts in Count mode so that the impact can be watched, and can then be moved to Block. On the same day, the service-linked role AWSServiceRoleForAWSShield and managed policy AWSShieldServiceRolePolicy were also added. This date marks the formalization of the mechanism by which AWS Shield Advanced implements application layer mitigation through AWS WAF. References: AWS Shield Advanced introduces automatic application-layer DDoS mitigation
2022-01-07Firewall ManagerShield Advanced policies could now turn on automatic application layer DDoS mitigation across an organization. The initial target is Amazon CloudFront resources. The distribution layer could hand out the previous month's mechanism one month later. References: AWS Firewall Manager now supports AWS Shield Advanced automatic application layer DDoS mitigation
2022-02-24Firewall ManagerThe Network Firewall policy gained a centralized deployment model. In contrast to the distributed model, which creates a firewall endpoint for each VPC, the centralized model consolidates inspection within a single VPC. References: AWS Firewall Manager now supports AWS Network Firewall Centralized Deployment Model
2022-03-30Firewall ManagerA third-party firewall policy was added. The first product it covers is Palo Alto Networks Cloud Next Generation Firewall (NGFW). The protections of a product you have subscribed to through AWS Marketplace can now be distributed to the VPCs in your organization. This is the entry where the distribution layer began handing out something that is not an AWS service. References: AWS Firewall Manager now supports Palo Alto Networks Cloud Next Generation Firewalls
2022-04-08ShieldAutomatic application layer DDoS mitigation reached Application Load Balancer. That put automatic mitigation within reach of every application layer protection. References: AWS Shield Advanced now supports Application Load Balancer for automatic application layer DDoS mitigation
2022-07-14Firewall ManagerNetwork Firewall policies gained strict rule order together with alert and drop default actions. References: AWS Firewall Manager now supports AWS Network Firewall strict rule order with alert and drop configurations
2022-08-26Firewall ManagerAWS Managed Rules for AWS Network Firewall became distributable. References: AWS Firewall Manager adds support for AWS Managed Rules for AWS Network Firewall
2022-11-08Firewall ManagerExisting AWS Network Firewall resources could now be imported and managed. A resource set has also been added, allowing you to specify groups of resources to be managed through policies. This import is represented as a separate policy type within the fms API, using the value IMPORT_NETWORK_FIREWALL in addition to NETWORK_FIREWALL. References: AWS Firewall Manager can now import existing AWS Network Firewall resources
2022-12-02Firewall ManagerFortigate Cloud Native Firewall (CNF) joined as the second third-party product. References: AWS Firewall Manager now supports FortiGate Cloud-Native Firewall
2023-04-10Firewall ManagerSix more AWS WAF features reached the AWS WAF policy. These include a managed rule group for Fraud Control account takeover prevention, a managed rule group for Bot Control, an Amazon S3 logging destination, rule action overrides, CAPTCHA and Challenge rule actions, and a token domain list. References: AWS Firewall Manager adds support for six additional AWS WAF features
2023-04-24Firewall ManagerUp to 10 administrator accounts could now be created. Administrative responsibility can be split by scoping it to OUs, accounts, policy types, and Regions. References: AWS Firewall Manager adds support for multiple administrators
2023-05-30ShieldShield Advanced protections could now be created with AWS CloudFormation. References: AWS Shield Advanced now supports AWS CloudFormation
2023-08-30Firewall ManagerSecurity group auditing was expanded. References: AWS Firewall Manager improves auditing capabilities for Security Groups
2023-09-14Firewall ManagerShield Advanced policies with automatic application layer DDoS mitigation turned on could now cover Application Load Balancer resources. This update brings the distribution layer in line with the support introduced by Shield Advanced in April 2022. References: Document history - AWS WAF, AWS Firewall Manager, AWS Shield Advanced, and AWS Shield network security director Developer Guide
2023-10-04Firewall ManagerSecurity group referencing was added. A reference is distributed from a primary security group to its replica security groups. References: AWS Firewall Manager supports referencing of Security Groups
2023-10-31ShieldThe automatic application layer DDoS mitigation rule group gained a rate-based rule that limits requests from IP addresses known to be sources of DDoS attacks. References: Document history - AWS WAF, AWS Firewall Manager, AWS Shield Advanced, and AWS Shield network security director Developer Guide
2024-04-29Firewall ManagerSupport for Amazon VPC network ACL policies was added. It is the most recently added policy category. Organizations can now centrally create and distribute network ACL rules for VPC subnets within their accounts. Compliance status is also reported for each policy. References: AWS Firewall Manager now supports central deployment and management of VPC NACLs with common NACL policies
2024-10-25Firewall ManagerRules could now be added to a web ACL that already existed. By enabling the "retrofit" setting in AWS WAF policies, organizations can centrally define rule groups and log destinations for existing web ACLs, while preserving the web ACL's existing, unique rules. This adds a "blend in" approach, supplementing the previous "distribute and replace" method. References: AWS Firewall Manager now supports retrofitting of existing AWS WAF WebACLs
2025-06-12ShieldAWS WAF released the Anti-DDoS managed rule group. This managed rule group detects and mitigates application-layer DDoS attacks in seconds, and is designed for services such as Amazon CloudFront and Application Load Balancer. This rule group does not require a subscription to Shield Advanced. This marks the beginning of the end for Shield Advanced's exclusive automatic mitigation feature. References: AWS WAF now supports automatic application layer distributed denial of service (DDoS) protection
2025-06-17ShieldAWS Shield network security director was announced in preview. It identifies compute, network, and network security resources within an account, and compares the network topology and configuration against AWS best practices and threat intelligence, highlighting missing protections and misconfigurations with severity ratings. It can be queried using Amazon Q Developer using natural language. This feature does not block traffic; it assesses configurations. This represents a shift for AWS Shield, moving beyond a service solely focused on DDoS defense. References: AWS Shield introduces network security director (preview)
2025-06-27Firewall ManagerThe AWS WAF Layer 7 DDoS managed rules became distributable through Firewall Manager. References: AWS Firewall Manager provides support for AWS WAF L7 DDOS managed rules
2025-12-12ShieldMulti-account analysis was added to network security director, which remains in preview. You can designate a delegated administrator account and begin continuous network analysis across multiple accounts and Organizational Units (OUs) within your organization. References: AWS Shield network security director now supports multi-account analysis
2026-03-05ShieldFindings from AWS Shield network security director reached AWS Security Hub. This is still in preview. References: AWS Shield network security director findings are now available in AWS Security Hub
2026-07-27ShieldA plan was announced to move the automatic application layer DDoS mitigation from Shield Advanced to the AWS WAF Anti-DDoS managed rule groups. Between July 27 and August 7, 2026, the rule group is added to eligible web ACLs in Count mode. A free evaluation period runs to September 30, 2026, the automatic upgrade begins on October 1, 2026, and a guided migration is available through December 31, 2026. On January 1, 2027, the automatic application layer mitigation feature in Shield Advanced will be discontinued. The Challenge action joins the mitigation actions, and the sensitivity becomes selectable as Low, Medium, or High. The consumption of web ACL capacity units will decrease from 150 to 50, and Amazon Route 53 health checks will no longer be required. AWS writes it plainly: AWS Shield Advanced isn't required to use any of these features. References: AWS Shield Advanced is embracing the AWS WAF Anti-DDoS managed rule group: What changes and how to prepare

Looking at the timeline as a whole, the entries related to AWS Shield and AWS Firewall Manager refer to different things. The Shield entries refer to Shield's own features, while the Firewall Manager entries refer to the launch of other services. The time it takes for the distribution layer to catch up has shortened from years to days.

How Long AWS Firewall Manager Took to Be Able to Distribute Each Defense
How Long AWS Firewall Manager Took to Be Able to Distribute Each Defense
Three of the seven categories are missing from this diagram. Amazon VPC security groups and network ACLs predate Firewall Manager by years, so there is no arrival date to pair them with. Third-party firewalls are products from other vendors and have no AWS announcement, so the same measure does not apply to them.

Current Overview, Functions, Features of AWS Shield and AWS Firewall Manager

AWS Shield Standard and AWS Shield Advanced

AWS Shield offers two tiers. AWS Shield Standard covers every AWS customer at no additional cost, and there is nothing to turn on. It provides automatic protection against common volumetric attack vectors, such as UDP reflection and TCP SYN floods.

AWS Shield Advanced is a subscription-based tier. The developer documentation currently describes it as a managed service that helps protect an application against external threats such as DDoS attacks, volumetric bots, and vulnerability exploitation attempts. The subscription includes integration with AWS WAF, automatic application layer DDoS mitigation, health-based detection, protection groups, DDoS event visibility, cross-account management through AWS Firewall Manager, support from the Shield Response Team (SRT), proactive engagement, and cost protection. To receive support from the SRT, you must subscribe to a Business or Enterprise support plan. One item on that list has an end date. As the entry for July 27, 2026 records, Shield Advanced's automatic application layer DDoS mitigation stops being available on January 1, 2027, and the AWS WAF Anti-DDoS managed rule group takes over that job.

Simply subscribing does not provide any protection. The official documentation clearly states:

> Shield Advanced protects only resources that you have specified either in Shield Advanced or through an AWS Firewall Manager Shield Advanced policy. It doesn't automatically protect your resources.

You must either explicitly specify the resources or define them within an AWS Firewall Manager Shield Advanced policy. That sentence is where the two services in this article meet.

What AWS Shield Advanced Can Protect

As of August 31, 2026, the resource types that AWS Shield Advanced can protect are as follows:

Resource TypeProtection Method
Amazon CloudFront distributionDirectly specified. In CloudFront continuous deployment, the staging distribution associated with the primary distribution being protected is also protected.
Amazon Route 53 hosted zoneDirectly specified.
AWS Global Accelerator standard acceleratorDirectly specified.
Amazon EC2 Elastic IP addressDirectly specified. Associated resources are also protected.
Amazon EC2 instanceProtected through association with an Amazon EC2 Elastic IP address.
Application Load BalancerDirectly specified.
Classic Load BalancerDirectly specified.
Network Load BalancerProtected through association with an Amazon EC2 Elastic IP address.

That Network Load Balancers can only be protected through an Elastic IP address goes back to an announcement made in November 2017. Network Load Balancers that do not have an Elastic IP address are outside of this tier.

For resource types not listed, AWS provides examples of what is explicitly not supported.

> You can't use Shield Advanced to protect any other resource type. For example, you can't protect AWS Global Accelerator custom routing accelerators or Gateway Load Balancers.

The wording is limited to standard accelerators, so writing that AWS Global Accelerator as a whole is protected would be wrong. Gateway Load Balancers sit outside this tier as well.

The same page also includes details about supported address families and distinctions between inbound and outbound protection.

> Shield Advanced supports IPv4, and does not support IPv6.

> NAT Gateways handle outbound traffic only, whereas Shield Advanced protects against inbound DDoS. For outbound traffic protection, use AWS Network Firewall.

The default number of resources you can protect is 1,000 for each resource type per account. This is the same value announced in February 2019. You can request an increase through the Service Quotas console.

AWS Shield network security director (preview)

As of August 31, 2026, AWS Shield network security director is in public preview. The official documentation says so outright:

> AWS Shield network security director is in public preview release and is subject to change.

This feature does not block traffic. Instead, it identifies resources within your account and organization, evaluates your network topology and configurations, and highlights any missing protections or misconfigurations, assigning severity levels. Its purpose is to identify gaps in your network security services, such as AWS WAF, VPC security groups, and VPC network ACLs.

Since the preview opened in June 2025, the feature has added analysis across multiple accounts and integration with AWS Organizations, and in March 2026 its findings reached AWS Security Hub. It keeps growing while still in preview. The list of supported Regions changes, so this article does not reproduce it. Read the current list from the official documentation.

This feature is included in neither tier. The AWS Shield pricing page explicitly states both AWS Shield Standard does not include AWS Shield network security director. and AWS Shield Advanced does not include AWS Shield network security director. Even if you subscribe to AWS Shield Advanced, this feature is not included.

AWS Firewall Manager Policy Types

The user guide lists seven categories of policy that AWS Firewall Manager can distribute: AWS WAF policies, Shield Advanced policies, Amazon VPC security group policies, Amazon VPC network access control list (ACL) policies, Network Firewall policies, Amazon Route 53 Resolver DNS Firewall policies, and policies for third-party firewalls.

The SecurityServicePolicyData object in the fms API, however, lists eleven possible values for the Type field.

WAF | WAFV2 | SHIELD_ADVANCED | SECURITY_GROUPS_COMMON | SECURITY_GROUPS_CONTENT_AUDIT | SECURITY_GROUPS_USAGE_AUDIT | NETWORK_FIREWALL | DNS_FIREWALL | THIRD_PARTY_FIREWALL | IMPORT_NETWORK_FIREWALL | NETWORK_ACL_COMMON

The discrepancy between seven and eleven is not a contradiction. The user guide groups policies by category, while the API lists them based on implementation units. The previously published AWS Network and Application Protection Decision Guide works through that correspondence and through what to watch for when a design document writes down a number of types. This article is a timeline, so it carries the order the seven categories arrived in instead.

Policy categoryWhen it became distributable
AWS WAF policies2018-04-04, as AWS WAF Classic. The new AWS WAF joined the same category on 2020-03-31.
Shield Advanced policies2019-03-28
Amazon VPC security group policies2019-10-10
Network Firewall policies2020-11-18
Amazon Route 53 Resolver DNS Firewall policies2021-04-01
Third-party firewall policies2022-03-30, with Palo Alto Networks Cloud NGFW. Fortigate CNF joined on 2022-12-02.
Amazon VPC network ACL policies2024-04-29

What a third-party firewall policy distributes is the protections of a product you have subscribed to through AWS Marketplace. The user guide lists two such products: Palo Alto Networks Cloud NGFW and Fortigate Cloud Native Firewall (CNF) as a Service. This article does not discuss the features or relative merits of these products. It records only that such a policy type exists for Firewall Manager to distribute.

The AWS WAF Classic Policy Type Is Still Listed

AWS WAF policies are still described as including AWS WAF Classic. The API enumeration also still lists WAF.

This needs care. AWS WAF Classic is inside a planned end-of-life process. The official documentation clearly states that AWS WAF Classic support will end on September 30, 2025. As of the time this article was written, on August 31, 2026, that date has already passed.

Being listed as a Firewall Manager policy type and being a choice you can still make for a new design are two different things. Please check the AWS Health dashboard to confirm the specific dates for each migration stage, as they vary by Region.

What AWS Firewall Manager Requires Before It Can Distribute Anything

Firewall Manager stops nothing itself, and it also does not start working at all until three prerequisites are in place. Specifically, you must join AWS Organizations and configure it for Firewall Manager, create a designated administrator account for Firewall Manager, and enable AWS Config. You enable AWS Config in each member account of the organization, and in each Region that holds resources you want to protect. According to the official documentation, AWS Config is required because:

> In order for Firewall Manager to monitor policy compliance, AWS Config must continuously record configuration changes for protected resources.

The recording frequency must be set to Continuous, which is the default setting.

Furthermore, to deploy Network Firewall policies and DNS Firewall policies, you need AWS Resource Access Manager. Distributing third-party firewall policies needs a subscription through AWS Marketplace.

Since April 2021, Firewall Manager registers its administrator account as a delegated administrator in AWS Organizations, and since April 2023 you can have up to 10 of them.

Frequently Asked Questions about AWS Shield and AWS Firewall Manager History

When was AWS Shield announced, and what protections did AWS Shield Advanced offer at that time?

AWS Shield was announced on December 1, 2016. At that time, it offered two tiers: AWS Shield Standard, which was available to all AWS customers without additional charge, and AWS Shield Advanced, which required a subscription. Initially, AWS Shield Advanced provided protection for Elastic Load Balancing, Amazon CloudFront, and Amazon Route 53.

When did AWS Shield Advanced begin protecting Amazon EC2 instances and Network Load Balancers?

AWS Shield Advanced began protecting Amazon EC2 instances and Network Load Balancers on November 21, 2017. The protection works indirectly. When you enable Shield Advanced on an Elastic IP address attached to an internet-facing EC2 instance or Network Load Balancer, Shield Advanced identifies the type of resource behind that Elastic IP address and applies its defenses accordingly. The current list of protected resource types carries Amazon EC2 instances and Network Load Balancers as protected through association to Amazon EC2 Elastic IP addresses, because that protection method has continued. A Network Load Balancer without an Elastic IP address is outside this tier.

Why does a single article discuss both AWS Shield and AWS Firewall Manager?

There are two reasons. First, the previously published AWS WAF timeline names these two services in its body and says their history is out of scope for that article. Second, AWS Firewall Manager does not stand on its own as the subject of a timeline. Firewall Manager inspects nothing itself; it is the layer that distributes the defenses of other services. Write its timeline and most of the entries end up pointing at another service's launch. It is not a question of volume.

In what order did AWS Firewall Manager gain its policy categories?

AWS Firewall Manager gained its policy categories in this order. AWS WAF policies came first, on April 4, 2018, then Shield Advanced policies on March 28, 2019, Amazon VPC security group policies on October 10, 2019, Network Firewall policies on November 18, 2020, Amazon Route 53 Resolver DNS Firewall policies on April 1, 2021, third-party firewall policies on March 30, 2022, and Amazon VPC network ACL policies on April 29, 2024. The new AWS WAF joined the AWS WAF policy category on March 31, 2020.

Has AWS Firewall Manager always lagged behind the defenses it distributes?

No. The gap is narrowing. AWS WAF Classic arrived in October 2015 and took two and a half years to become distributable. Shield Advanced arrived in December 2016 and took about two years and four months. The new AWS WAF arrived in November 2019 and took about four months. For AWS Network Firewall, by contrast, the distribution layer was announced a day earlier than the defense itself, and for Amazon Route 53 Resolver DNS Firewall the distribution layer was ready before the defense became generally available.

Is AWS Shield still solely focused on DDoS protection?

No. AWS Shield network security director, announced in preview on June 17, 2025, does not block traffic at all. It evaluates network topology and configuration and points at protections that are missing or misconfigured. As of August 31, 2026, this feature remains in public preview, and the official documentation is subject to change.

What is happening to Shield Advanced's automatic application layer DDoS mitigation?

AWS is moving that mitigation to the AWS WAF Anti-DDoS managed rule group. That rule group arrived in June 2025 and does not require a Shield Advanced subscription. The transition will occur in phases, starting on July 27, 2026, and Shield Advanced's automatic application layer mitigation will no longer be offered as of January 1, 2027. Please check the official announcements to confirm whether your web ACL is affected, as the schedule and eligibility criteria may be subject to change.

Is the AWS WAF Classic policy type still usable in AWS Firewall Manager?

Not for anything new. While the policy type is still listed in the user guide and in the fms API enumerations, AWS WAF Classic itself is inside a planned end-of-life process. AWS officially states that AWS WAF Classic support will end on September 30, 2025. Being listed as a policy type and being a choice you can still make for a new design are two different things.

Summary

This article presents a timeline of AWS Shield and AWS Firewall Manager, clarifying their current state.

These two services share one article because the previously published AWS WAF timeline named them and put their history out of its own scope, and because AWS Firewall Manager does not stand on its own as the subject of a timeline.

The history of AWS Shield takes the shape of a widening scope of protection. It opened in December 2016 over Elastic Load Balancing, Amazon CloudFront, and Amazon Route 53. Protection through an Elastic IP address arrived in November 2017, and AWS Global Accelerator standard accelerators joined in December 2018. As far as this article was able to confirm, the resource types themselves have not grown since; Shield's history moves instead toward how deeply it protects. Health-based detection, protection groups, and then the automatic application layer DDoS mitigation of December 2021. That last one fixed the shape in which Shield Advanced delivers its application-layer mitigation: it writes AWS WAF rules into the user's web ACL rather than filtering those requests itself.

The history of AWS Firewall Manager takes a different form. Most of its entries point at another service's launch. It emerged in 2018 as a layer for distributing AWS WAF and has widened what it can distribute ever since, to Shield Advanced, VPC security groups, Network Firewall, DNS Firewall, third-party firewalls, and VPC network ACLs. The order those seven categories arrived in traces the order AWS's own protection services arrived in, for the four that pair with an AWS launch. The interval before the distribution layer caught up shrank from years to days. The Network Firewall policy was announced one day before AWS Network Firewall itself, and the DNS Firewall policy was ready before DNS Firewall became generally available.

Currently, the two services are moving in separate directions. AWS Shield is reaching past DDoS protection with network security director, a preview feature that evaluates configuration and points at missing protections without stopping any traffic. Shield Advanced's automatic application layer DDoS mitigation, meanwhile, is handing its job to the AWS WAF Anti-DDoS managed rule group, and stops being available on January 1, 2027. By decoupling application layer DDoS protection from the subscription, the reasons for choosing Shield Advanced are fundamentally changing.

Read down the timeline and the two services turn out to have taken differently shaped histories, for all that one word covers them both. For one, the list of what it can protect is the history. For the other, the list of what it can distribute is the history. It will be interesting to watch where the two go next. This article will be updated to reflect changes to both AWS Shield and AWS Firewall Manager.

How these two sit alongside the other protection layers, and what each layer does not stop, is the subject of the previously published AWS Network and Application Protection Decision Guide.

There are also timelines available for AWS services and related topics:



References:
Tech Blog with curated related content

Written by Hidekazu Konishi