Before deleting AWS Network Firewall, remove every route and endpoint association that depends on it, then restore the traffic paths your VPC is meant to use. AWS warns that deleting a firewall is irreversible. Inventory the affected VPCs, Availability Zones, route tables, and account owners first; then change dependencies in order.
1. Map the firewall’s traffic paths
Start by identifying every firewall subnet mapping and its Availability Zone. For each one, inspect the route tables for routes targeting that firewall endpoint. Also identify VPC endpoint associations that use the firewall, including associations in VPCs outside its primary VPC.
Record the current routes and the intended destination of each affected traffic flow before editing anything. AWS recommends noting the original route settings in its Network Firewall getting-started tutorial, so they can be restored when removing the example configuration.
- Which VPC and Availability Zone does each firewall subnet mapping cover?
- Which route tables contain a route to a firewall endpoint or association endpoint?
- Who owns each endpoint association, especially across accounts?
- Where should each flow go after it no longer traverses this firewall?
2. Restore intended routes before removing endpoints
Update routes so traffic reaches its intended destination without passing through the firewall. Do not simply delete a route and assume traffic will take the right path: determine the replacement target for each destination based on the VPC design.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
- Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
- High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
- Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
- Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
For the tutorial’s internet-gateway example
AWS’s simple example records the original routes, directs traffic through the firewall endpoint, and then restores the original internet-gateway and customer-subnet route-table entries before removing the route-table configuration created for the endpoint. Treat those entries as an example to adapt, not a universal recipe.
For other VPC designs
Ingress and egress paths involving NAT gateways, Transit Gateway, centralized inspection, or other routing components may require different changes. AWS notes that the exact route updates depend on the architecture. Confirm both sides of each flow—such as forward and return paths—against the design before applying changes. Removing the firewall should not silently bypass another intended inspection or security control.
Rank #2
- 【Professional Firewall & NAS SERVER】OAKNODE 10gbe Firewall Appliance Mini PC-MGNASN, a powerful professional firewall router pc equipped with a 12th Gen Alder Lake N100 4C/4T up to 3.4GHz TDP only 6W with Intel UHD Graphics which maximizes the performance of the 2.5GbE port & SFP+ port, bring you a smooth secured and encrypted network environment.
- 【Rich I/O to meet your needs】Firewall Appliance MGNASN With HDMI 2.0+DP 1.4+TYPE-C(dp 1.2) Support for 3x4K@60Hz together, Dual DDR4 RAM slot support for up to 1x32GB SO-Dimm laptop DDR5 Ram Maximum 5600Mhz and 1xM.2 NVMe/PCIe 3.0x1 2280 SSD slot +1*SATA 3.0 SSD/HDD slots (install externally), also it support boot from TF card slot and it also support PXE/AWOL/Watchdog/GPIO etc. which is perfect for your firewall appliance、VM、Router、home Server needs.
- 【2xSFP+ 10GbE + 4x2.5GbE】This Firewall Router equipped with 2xIntel 82599ES 10gbe network card and 4*Intel i226-V network card speed maximum up to 2.5GbE(need other device like router, cables etc. also support 2.5Gbe/10gbe)which can bring you more faster and professional network usage(some system not release drivers yet) suggest to install version of below systems: pf-sense plus 23.0X or CE 2.7.X, OPNsense 22.1, OpenWrt, ROS7, ESXI 8 , Proxmox, CentOS etc).
- 【4G LTE Function supported】This model also support 4G LTE function(mini PCIE slot for 4G modem) and SIM card slot which you can use it as a IOT devices for your server.
- 【Quality With Warranty】If you have any questions or requirements(like OS installation/ drives/bios updates etc.) on OAKNODE Firewall mini pc MGNASN, PLEASE feel free to contact us. We offered 12 Months warranty for it and WE'LL REPLY YOUR Questions within 12 hours(during Workdays).
AWS’s developer guide says, “You must remove the firewall from any VPC route tables that mention it.” See Deleting a firewall.
3. Remove endpoint associations and coordinate ownership
Find every VPC endpoint association using the firewall. Before deleting an association, remove route-table references to its endpoint; a route reference can prevent deletion. For an association owned by another AWS account, coordinate with that account’s owner and ask them to delete it. Do not assume the firewall owner can remove a resource owned by someone else.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- BUSINESS READY - pfSense+ software updates included for product lifetime. Netgate TAC Lite technical support included. One year hardware warranty included.
- COMPLETE - Pre-loaded with pfSense+ software to get up and running fast. Simply unbox it and start customizing for your secure edge networking needs. Free help with setup from our expert Technical Assistance Center (TAC) available 24/7/365.
- POWERFUL - A dual core ARM Cortex-A53 1.2 GHz delivers near gigabit routing of common home iPerf3 traffic and in excess of 650 Mbps of firewall throughput.
- COMPACT - Low power draw, a compact form factor, and silent operation allow it to run unnoticed when placed on a desktop, wall, or rack.
- FLEXIBLE - Three (3) 1 GbE switched (WAN/LAN/OPT) ports allow you to configure three separate 1 GbE switched ports for upto a gigabit of bi-directional traffic.
Review AWS’s guidance for managing VPC endpoint associations alongside the routes in each associated VPC. Clear route dependencies first, then remove the association through the account that owns it.
4. Meet the firewall deletion prerequisites
Before issuing the delete operation, disable the firewall’s logging configuration and confirm that delete protection is off. The DeleteFirewall API reference requires DeleteProtection to be FALSE. If protection is enabled, disable it using the appropriate Network Firewall API operation, then recheck the firewall configuration.
Rank #4
- 【CPU】Intel Pentium J3710 4-Core/4-Thread processor, up to 2.64GHz, with 2MB L2 Cache and 6W TDP. Supports AES-NI and suitable for firewall, router, VPN and other network applications.
- 【Ports & Expansions】Equipped with 4 x 2.5GbE Intel i226-v LAN ports. Includes 2 x USB3.0, 1 x HDMI. 1 x VGA ports.Supports optional Wi-Fi and 3G/4G module expansion, plus a VESA mounting kit.
- 【Fanless & Low-Power Design】6W fanless design with an aluminum alloy chassis for quiet, low-maintenance operation. Design for 24/7 continuous use and suitable for home networks, small office and network labs.
- 【RAM & Storage】Includes 8G DDR3 RAM and a 128GB mSATA SSD. Supports up to 8GB RAM and 512GB mSATA storage. HDD storage is not supported. Compact 5.27 x 4.98 x 1.43-inch design weighs only apporximately 500g.
- 【Warranty & Support】Tested with pfSense, OPNsense, Ubuntu and other popular open-sourse OS. Supports Proxmox VE for virtualization and home lab applications. Includes a 12-month hardware warranty and lifetime technical support. (Press "DEL" to the BIOS)
Also verify that no route table still references a firewall endpoint. AWS identifies route-table references as a dependency that can prevent deleting a firewall or endpoint association. Keep the record of routes you captured earlier until the post-change traffic checks pass.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.5. Delete the firewall, then clean up unused policy resources
Once routes and associations no longer depend on the firewall and the deletion prerequisites are satisfied, delete the firewall. AWS’s API warns: “You can’t revert this operation.” This is not a reversible detach; make sure the route changes and ownership coordination are complete before proceeding.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
- 【CPU Optimized for Firewall Mini PCs】This firewall appliance is powered by Intel Quad-Core Celeron J1900, 64-bit, up to 2.0 GHz, supporting software-based encryption. Energy-efficient and reliable, it runs 24/7 for home or small office networks, handling VPNs, multi-WAN routing, and basic firewall tasks efficiently.
- 【4×Intel i210 Ports】Equipped with four Intel i210 network controllers, each delivering up to 1 GbE for reliable multi-WAN routing, VPN connections, VLAN management, and stable performance in small office or home firewall deployments
- 【Memory & Storage】This Firewall Mini PC comes with 4 GB DDR3L RAM and a 64 GB mSATA SSD, providing reliable performance for basic networking tasks. AMI BIOS with ACPI support ensures stable system operation and energy-efficient 24/7 use
- 【Flexible System Compatibility】Compatible with Windows 10, Linux, and professional firewall systems such as pfSense, OPNsense, and VyOS, ensuring stable network management for home or small office use
- 【After-Sales Support:】This compact, fanless, and silent firewall keeps your network secure. Includes lifetime technical support and a 30-day money-back guarantee!
Afterward, inspect the firewall policy and rule groups created for this deployment. Delete only resources that are no longer referenced. AWS checks policy references, and a policy with associations cannot be deleted. In its tutorial cleanup, AWS deletes the firewall before its policy and rule groups.
6. Verify routing and cleanup
After the changes, recheck affected route tables in every Availability Zone and VPC, and confirm each important traffic flow follows its intended post-firewall path. Check the firewall and association status until the deletion and association cleanup are complete. These are operational checks to tailor to your topology, rather than a single AWS-prescribed checklist for every architecture.
AWS notes that configuration changes can normally propagate within minutes, with brief inconsistency possible. That is general guidance about configuration propagation, not a guaranteed firewall deletion duration; validate actual traffic rather than treating elapsed time as proof of completion.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

