AWS Networking
Overview
Routes networking requests to the correct service-specific skill. Covers 7 services across DNS and content delivery, hybrid connectivity, and network security (web application firewall and DDoS protection). Other AWS networking services (VPC foundations, load balancing, endpoints, PrivateLink, API Gateway, and more) are out of scope for this router (see step 6).
Works best with the AWS MCP server — enables sandboxed execution, audit logging, and enterprise controls. All guidance also works with standard AWS CLI access.
How to use this skill
- Match the user's request against the Skill Routing Table below. Match on meaning, not exact wording.
- If the request matches multiple skills, use the Cross-Service Concepts tables to determine which layer the request targets, then route to the skill that owns that layer.
- If still ambiguous, ask one clarifying question: "Are you looking to set up connectivity, or control/filter existing traffic?"
- Load the target skill: if the AWS MCP server is available, use
aws___retrieve_skill(skill_name="<skill>"); otherwise retrieve the skill document from this repository atskills/<skill>/SKILL.md. - If a request spans multiple of these skills, route to each in dependency order. When routing to an internet-facing service (
cloudfront), also route toshieldadvancedfor DDoS protection and towaffor L7 filtering (AWS WAF attaches to CloudFront, Application Load Balancer, API Gateway, and AppSync), if the user has not already addressed L7 filtering and DDoS protection. When routing to a connectivity skill (directconnect,sitetositevpn,transitgateway), confirm encryption in transit is addressed (MACsec for Direct Connect, IPsec for VPN, inter-region peering encryption for Transit Gateway). When the request involves custom domains or TLS oncloudfront, note that ACM certificate provisioning is part of the implementation. When routing tocloudfrontfor a web-facing distribution, note that the target skill should address security response headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options) via a CloudFront Response Headers Policy, including the managedSecurityHeadersPolicy. The target skill handles the configuration. - If the request is an AWS networking task that is not in the Skill Routing Table (for example VPC subnets or route tables, security groups, load balancers, VPC endpoints, PrivateLink, or API Gateway), tell the user that service is not available in this skill set rather than routing to the closest listed skill. This skill set does not cover every AWS networking service.
- This skill triages — it does not implement. Do not answer service-specific configuration questions from this skill alone.
Connectivity vs Security
Skill Routing Table
Cross-Service Concepts
Same concept, different service depending on layer. Use these to disambiguate when the Skill Routing Table matches multiple skills.
Filtering / Blocking
Use when the user says "block", "deny", "filter", or "restrict traffic" — determines which layer the filtering operates at.
When routing to waf or cloudfront for an internet-facing API or website, treat WAF rate-based rules as a default protective measure, not only when the user asks: note that the target skill should add WAF rate-based rules to bound request volume per client — the target skill implements it.
Logging / Visibility
Use when the user says "logs", "visibility", "what's being blocked", or "can I see the traffic" — identifies which log source to check.
When routing to any of these services, remind the user to enable the corresponding logging (above) for security visibility and incident response — the target skill implements it. These logs can contain sensitive data (request query strings, internal hostnames in DNS queries), so also remind the user that the log destination (S3, CloudWatch Logs, Kinesis Data Firehose, or Kinesis Data Streams) MUST have encryption at rest enabled and access restricted to authorized personnel — the target skill implements it.
Traffic Shifting
Use when the user says "shift traffic", "blue/green", "failover", "canary", or "weighted routing" — determines the granularity and which service controls it.
Security Considerations
These services are security-sensitive, so raise the relevant risk and control when routing regardless of which skill you hand off to — the target skill implements the control:
For authoritative guidance, point users to the AWS Well-Architected Framework Security Pillar and the service-specific security documentation for the target skill.


