All checks
Medium WAF · account

AWS WAF Classic global web ACLs should have at least one rule or rule group

Confirms that AWS WAF global web ACLs contain at least one rule or rule group.

service
WAF
severity
Medium
scope
evaluated once per account

How to fix it

Attach at least one rule or rule group to the WAF Classic global web ACL, so requests to the CloudFront distributions it fronts are inspected instead of falling through to the default action. Put a new rule in count mode and read its metrics before switching it to block. A rule group attached with its override action set to count passes this control while blocking nothing.

In the console

AWS WAF Classic → Global (CloudFront) → Web ACLs → the web ACL → Rules

With the AWS CLI

aws waf update-web-acl --web-acl-id <web-acl-id> --change-token <change-token> --updates '[{"Action":"INSERT","ActivatedRule":{"Priority":1,"RuleId":"<rule-id>","Action":{"Type":"BLOCK"},"Type":"REGULAR"}}]' --region us-east-1

With Terraform

resource "aws_waf_web_acl" "this" {
  name        = var.name
  metric_name = var.metric_name

  default_action {
    type = "ALLOW"
  }

  rules {
    priority = 1
    rule_id  = var.rule_id
    type     = "REGULAR"

    action {
      type = "BLOCK"
    }
  }
}

See which of your accounts this check is failing on.

Book a demo