Description
Associating an AWS WAF web ACL with an internet-facing ALB lets you filter web requests using its configured rules. Without WAF, there are fewer opportunities to block common web attacks and abnormal requests.
Potential impact
Malicious requests or bot traffic may reach the application directly. The protection provided depends on the web ACL rules and their actions.
Remediation
Associate a web ACL with the public ALB using aws_wafv2_web_acl_association. Configure rules appropriate for the service and verify their blocking behavior.
Examples
The example associates a separately defined AWS WAF web ACL with the ALB.
Before
hcl
resource "aws_lb" "alb" {
name = "test-lb-tf"
internal = false
load_balancer_type = "application"
security_groups = [aws_security_group.lb_sg.id]
subnets = [for subnet in aws_subnet.public : subnet.id]
}
After
hcl
resource "aws_lb" "alb" {
name = "test-lb-tf"
internal = false
load_balancer_type = "application"
security_groups = [aws_security_group.lb_sg.id]
subnets = [for subnet in aws_subnet.public : subnet.id]
}
resource "aws_wafv2_web_acl_association" "alb_waf_association" {
resource_arn = aws_lb.alb.arn
web_acl_arn = aws_wafv2_web_acl.example.arn
}