ALB is not associated with AWS WAF

Configure required AWS WAF request filtering for public ALBs.

Description

Without an associated AWS WAF web ACL, WAF rules do not apply to requests handled by an internet-facing ALB.

Potential impact

Without suitable blocking rules, malicious or excessive requests can place a burden on the application.

Remediation

Associate a web ACL in the same Region with the ALB using AWS::WAFv2::WebACLAssociation. Configure rules and exceptions for the service and verify allowed and blocked requests.

Examples

The examples compare ALB configurations with and without a web ACL association. Define the subnets and MyWebACL separately. Association alone does not block every attack.

Before

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  MyLoadBalancer22:
    Type: AWS::ElasticLoadBalancingV2::LoadBalancer
    Properties:
      Type: application
      Subnets: !Ref Subnets
      Scheme: internet-facing

After

yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  MyLoadBalancer9:
    Type: AWS::ElasticLoadBalancingV2::LoadBalancer
    Properties:
      Type: application
      Subnets: !Ref Subnets
      Scheme: internet-facing

  MyWebACLAssociation:
    Type: AWS::WAFv2::WebACLAssociation
    Properties:
      ResourceArn:
        Ref: MyLoadBalancer9
      WebACLArn: !GetAtt MyWebACL.Arn

References