AWS WAF Classic global web ACLs should have at least one rule or rule group
Confirms that AWS WAF global web ACLs contain at least one rule or rule group.
- service
- WAF
- severity
- Medium
- scope
- evaluated once per account
How to fix it
Attach at least one rule or rule group to the WAF Classic global web ACL, so requests to the CloudFront distributions it fronts are inspected instead of falling through to the default action. Put a new rule in count mode and read its metrics before switching it to block. A rule group attached with its override action set to count passes this control while blocking nothing.
In the console
AWS WAF Classic → Global (CloudFront) → Web ACLs → the web ACL → Rules
With the AWS CLI
aws waf update-web-acl --web-acl-id <web-acl-id> --change-token <change-token> --updates '[{"Action":"INSERT","ActivatedRule":{"Priority":1,"RuleId":"<rule-id>","Action":{"Type":"BLOCK"},"Type":"REGULAR"}}]' --region us-east-1With Terraform
resource "aws_waf_web_acl" "this" {
name = var.name
metric_name = var.metric_name
default_action {
type = "ALLOW"
}
rules {
priority = 1
rule_id = var.rule_id
type = "REGULAR"
action {
type = "BLOCK"
}
}
}
See which of your accounts this check is failing on.
Book a demo