Description
AWS WAF applies DefaultAction when earlier rules have not made a terminating allow or block decision. Default allow can suit a public service that uses a blocklist. An allow-list policy that accepts only approved requests needs explicit allow rules and default block.
Potential impact
If an intended allow-list uses default allow, requests outside the list can still reach the application. Conversely, switching to default block without the required allow rules can block legitimate requests.
Remediation
Define the access policy first, then review the default action and rule priorities together. For a service requiring an allow-list, configure rules for approved requests and block the rest. Test both permitted and unwanted requests.
Examples
This REGIONAL web ACL is intended to allow only addresses in an existing IP set. Supply the ARN of a REGIONAL IP set in the same Region as TrustedIPSetArn and associate the web ACL with the protected resource separately. The original allows requests outside the set; the revision blocks them. The examples use the current AWS::WAFv2::WebACL format.
Before
Parameters:
TrustedIPSetArn:
Type: String
Resources:
MyWebACL:
Type: AWS::WAFv2::WebACL
Properties:
Name: WebACL
Scope: REGIONAL
DefaultAction:
Allow: {}
VisibilityConfig:
SampledRequestsEnabled: true
CloudWatchMetricsEnabled: true
MetricName: MyWebACL
Rules:
- Name: MyRule
Priority: 1
Action:
Allow: {}
Statement:
IPSetReferenceStatement:
Arn: !Ref TrustedIPSetArn
VisibilityConfig:
SampledRequestsEnabled: true
CloudWatchMetricsEnabled: true
MetricName: MyRule
After
Parameters:
TrustedIPSetArn:
Type: String
Resources:
MyWebACL:
Type: AWS::WAFv2::WebACL
Properties:
Name: WebACL
Scope: REGIONAL
DefaultAction:
Block: {}
VisibilityConfig:
SampledRequestsEnabled: true
CloudWatchMetricsEnabled: true
MetricName: MyWebACL
Rules:
- Name: MyRule
Priority: 1
Action:
Allow: {}
Statement:
IPSetReferenceStatement:
Arn: !Ref TrustedIPSetArn
VisibilityConfig:
SampledRequestsEnabled: true
CloudWatchMetricsEnabled: true
MetricName: MyRule