CloudFront is not associated with AWS WAF

Apply AWS WAF rules suited to the service through CloudFront.

Description

Without an associated AWS WAF web ACL, WAF rules do not apply to requests handled by the CloudFront distribution.

Potential impact

Without the required request filtering layer, malicious requests or excessive traffic can place a burden on the application.

Remediation

Set DistributionConfig.WebACLId to the ARN of a WAFv2 web ACL for CloudFront. Configure managed or rate-based rules suited to the service and verify their effect.

Examples

CloudFrontWebAclArn is the ARN of a web ACL created in us-east-1 with CLOUDFRONT scope. Configure the rules you need as well as the association.

Before

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Enabled: true
        DefaultCacheBehavior:
          TargetOriginId: myOrigin

After

yaml
Resources:
  WebDistribution:
    Type: AWS::CloudFront::Distribution
    Properties:
      DistributionConfig:
        Enabled: true
        DefaultCacheBehavior:
          TargetOriginId: myOrigin
        WebACLId: !Ref CloudFrontWebAclArn

References