Review a web ACL default-allow policy

Choose a web ACL default action that matches the service’s access policy.

Description

AWS WAF applies DefaultAction when earlier rules have not made a terminating allow or block decision. Default allow can suit a public service that uses a blocklist. An allow-list policy that accepts only approved requests needs explicit allow rules and default block.

Potential impact

If an intended allow-list uses default allow, requests outside the list can still reach the application. Conversely, switching to default block without the required allow rules can block legitimate requests.

Remediation

Define the access policy first, then review the default action and rule priorities together. For a service requiring an allow-list, configure rules for approved requests and block the rest. Test both permitted and unwanted requests.

Examples

This REGIONAL web ACL is intended to allow only addresses in an existing IP set. Supply the ARN of a REGIONAL IP set in the same Region as TrustedIPSetArn and associate the web ACL with the protected resource separately. The original allows requests outside the set; the revision blocks them. The examples use the current AWS::WAFv2::WebACL format.

Before

yaml
Parameters:
  TrustedIPSetArn:
    Type: String
Resources:
  MyWebACL:
    Type: AWS::WAFv2::WebACL
    Properties:
      Name: WebACL
      Scope: REGIONAL
      DefaultAction:
        Allow: {}
      VisibilityConfig:
        SampledRequestsEnabled: true
        CloudWatchMetricsEnabled: true
        MetricName: MyWebACL
      Rules:
        - Name: MyRule
          Priority: 1
          Action:
            Allow: {}
          Statement:
            IPSetReferenceStatement:
              Arn: !Ref TrustedIPSetArn
          VisibilityConfig:
            SampledRequestsEnabled: true
            CloudWatchMetricsEnabled: true
            MetricName: MyRule

After

yaml
Parameters:
  TrustedIPSetArn:
    Type: String
Resources:
  MyWebACL:
    Type: AWS::WAFv2::WebACL
    Properties:
      Name: WebACL
      Scope: REGIONAL
      DefaultAction:
        Block: {}
      VisibilityConfig:
        SampledRequestsEnabled: true
        CloudWatchMetricsEnabled: true
        MetricName: MyWebACL
      Rules:
        - Name: MyRule
          Priority: 1
          Action:
            Allow: {}
          Statement:
            IPSetReferenceStatement:
              Arn: !Ref TrustedIPSetArn
          VisibilityConfig:
            SampledRequestsEnabled: true
            CloudWatchMetricsEnabled: true
            MetricName: MyRule

References