AWS WAF
AWS WAF is a web application firewall that inspects the HTTP and HTTPS requests that reach your applications and allows, blocks or counts them according to rules that you define. It protects against common attacks such as SQL injection, cross-site scripting (XSS), bad bots and floods of requests.
Key concepts #
- Web ACL: the list of rules and the default action. It is associated with a resource: an Application Load Balancer, CloudFront, API Gateway REST API, AppSync, Amazon Cognito or App Runner.
- Rules match IP addresses and ranges, geographic origin, headers, URI, query string, body size, regular expressions and more. Rate-based rules limit the number of requests per client.
- Managed rule groups: sets of rules maintained by AWS and by security vendors (core rule set, known bad inputs, SQL database, IP reputation, bot control).
- Count mode lets you test a rule and see what it would block before enforcing it.
- Logging to S3, CloudWatch Logs or Amazon Data Firehose, and metrics in CloudWatch.
- WAF works at layer 7. For network-level filtering see security groups and Network ACLs; AWS Shield protects against DDoS attacks.
- The scope is Regional, or CloudFront (global, created in us-east-1).
Pricing #
Per web ACL, per rule and per million requests inspected, plus the managed rule groups and optional features such as Bot Control. See the WAF pricing.
With Terraform #
The resources are aws_wafv2_web_acl, aws_wafv2_web_acl_association, aws_wafv2_ip_set, aws_wafv2_rule_group and aws_wafv2_web_acl_logging_configuration.