AWS ALB not associated with WAF

Configure AWS WAF protection for internet-facing AWS ALBs.

Description

Associating an AWS WAF web ACL with an internet-facing ALB lets you filter web requests using its configured rules. Without WAF, there are fewer opportunities to block common web attacks and abnormal requests.

Potential impact

Malicious requests or bot traffic may reach the application directly. The protection provided depends on the web ACL rules and their actions.

Remediation

Associate a web ACL with the public ALB using aws_wafv2_web_acl_association. Configure rules appropriate for the service and verify their blocking behavior.

Examples

The example associates a separately defined AWS WAF web ACL with the ALB.

Before

hcl
resource "aws_lb" "alb" {
  name               = "test-lb-tf"
  internal           = false
  load_balancer_type = "application"
  security_groups    = [aws_security_group.lb_sg.id]
  subnets            = [for subnet in aws_subnet.public : subnet.id]
}

After

hcl
resource "aws_lb" "alb" {
  name               = "test-lb-tf"
  internal           = false
  load_balancer_type = "application"
  security_groups    = [aws_security_group.lb_sg.id]
  subnets            = [for subnet in aws_subnet.public : subnet.id]
}

resource "aws_wafv2_web_acl_association" "alb_waf_association" {
  resource_arn = aws_lb.alb.arn
  web_acl_arn  = aws_wafv2_web_acl.example.arn
}

References