Description
Without an associated AWS WAF web ACL, WAF rules do not apply to requests handled by the CloudFront distribution.
Potential impact
Without the required request filtering layer, malicious requests or excessive traffic can place a burden on the application.
Remediation
Set DistributionConfig.WebACLId to the ARN of a WAFv2 web ACL for CloudFront. Configure managed or rate-based rules suited to the service and verify their effect.
Examples
CloudFrontWebAclArn is the ARN of a web ACL created in us-east-1 with CLOUDFRONT scope. Configure the rules you need as well as the association.
Before
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Enabled: true
DefaultCacheBehavior:
TargetOriginId: myOrigin
After
yaml
Resources:
WebDistribution:
Type: AWS::CloudFront::Distribution
Properties:
DistributionConfig:
Enabled: true
DefaultCacheBehavior:
TargetOriginId: myOrigin
WebACLId: !Ref CloudFrontWebAclArn