Description
Without an associated AWS WAF web ACL, WAF rules do not apply to requests handled by an internet-facing ALB.
Potential impact
Without suitable blocking rules, malicious or excessive requests can place a burden on the application.
Remediation
Associate a web ACL in the same Region with the ALB using AWS::WAFv2::WebACLAssociation. Configure rules and exceptions for the service and verify allowed and blocked requests.
Examples
The examples compare ALB configurations with and without a web ACL association. Define the subnets and MyWebACL separately. Association alone does not block every attack.
Before
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
MyLoadBalancer22:
Type: AWS::ElasticLoadBalancingV2::LoadBalancer
Properties:
Type: application
Subnets: !Ref Subnets
Scheme: internet-facing
After
yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
MyLoadBalancer9:
Type: AWS::ElasticLoadBalancingV2::LoadBalancer
Properties:
Type: application
Subnets: !Ref Subnets
Scheme: internet-facing
MyWebACLAssociation:
Type: AWS::WAFv2::WebACLAssociation
Properties:
ResourceArn:
Ref: MyLoadBalancer9
WebACLArn: !GetAtt MyWebACL.Arn