Description
An API Gateway REST API stage without an AWS WAF association does not receive the request inspection and blocking of that web ACL. Where controls against abusive web requests are needed, review WAF configuration against the API’s purpose and existing protections.
WAF processes requests according to its rules. It does not replace caller authentication, application permission checks or vulnerability fixes, and attaching a web ACL does not block every attack.
Potential impact
- Without required request filtering, malicious inputs or repeated requests can reach the application.
- Unsuitable blocking rules can reject legitimate customer requests.
Remediation
Associate a REGIONAL web ACL in the same Region with the REST API stage that needs protection. Select managed and custom rules appropriate for the API, assess their impact using options such as Count mode, then apply required blocking. Verify the actual association, request records and legitimate traffic, and retain authentication and application security controls.
Examples
The REST API, deployment and web ACL are separate inputs. Supply the ARN of a REGIONAL web ACL in the same Region through ApiWebAclArn. Rule definitions and logging configuration are omitted.
Before
Resources:
ProdStage:
Type: AWS::ApiGateway::Stage
Properties:
StageName: Prod
RestApiId: !Ref MyRestApi
DeploymentId: !Ref ApiDeployment
This excerpt contains no stage-to-web-ACL association. Check separately applied protections and the actual association state.
After
Resources:
ProdStage:
Type: AWS::ApiGateway::Stage
Properties:
StageName: Prod
RestApiId: !Ref MyRestApi
DeploymentId: !Ref ApiDeployment
ProdStageWebAclAssociation:
Type: AWS::WAFv2::WebACLAssociation
Properties:
WebACLArn: !Ref ApiWebAclArn
ResourceArn: !Sub arn:${AWS::Partition}:apigateway:${AWS::Region}::/restapis/${MyRestApi}/stages/${ProdStage}
This associates the web ACL using MyRestApi and ProdStage in the current Region. Configure web ACL rules and actions, and verify results for legitimate and malicious requests.