Description
A REST API stage without an AWS WAF web ACL association does not receive that ACL’s request inspection and blocking. Where filtering is required, configure WAF according to the API’s purpose and existing protections.
WAF handles requests according to its rules; an association alone does not block every attack. It does not replace caller authentication, application permission checks or vulnerability fixes.
Potential impact
- Without required filtering, malicious requests may reach the application.
- Unnecessary traffic can increase backend load.
- Request blocking and rate controls may be insufficient.
Remediation
- Associate the protected REST API stage with a REGIONAL WAFv2 web ACL in the same Region.
- Choose suitable managed and custom rules and exceptions. Assess effects on legitimate requests using options such as Count mode before enforcing necessary blocking.
- Regularly review blocked and allowed requests after applying WAF.
Examples
Configure the REST API, deployment and a REGIONAL WAFv2 web ACL in the same Region separately. These are association excerpts; rules and logging settings are omitted.
Before
hcl
resource "aws_api_gateway_stage" "example" {
deployment_id = aws_api_gateway_deployment.example.id
rest_api_id = aws_api_gateway_rest_api.example.id
stage_name = "example"
}
After
hcl
resource "aws_api_gateway_stage" "example" {
deployment_id = aws_api_gateway_deployment.example.id
rest_api_id = aws_api_gateway_rest_api.example.id
stage_name = "example"
}
resource "aws_wafv2_web_acl_association" "association" {
resource_arn = aws_api_gateway_stage.example.arn
web_acl_arn = aws_wafv2_web_acl.foo.arn
}
Explanation:
- Before: No stage-to-web-ACL association appears in this excerpt. Check other protections and the actual association state.
- After: The stage is associated with a WAFv2 web ACL. Configure its rules and actions, and verify results for legitimate and malicious requests.