Firewall Manager: Scope-down statements in Managed rule groups

0

Hello,

In WAFv2, we do use a lot of scope-down statements in managed rule groups. Is this supported in security policies distributed by the Firewall Manager as well?

The UI at least doesn't offer support for that. I thought I did manage to add scope-down statements via API, well Terraform, but I cannot be sure as the UI does not show that. Checking the JSON from the ACL, the scope-down statement does not show up.

So, is there support for it but I just cannot see it, or is the config silently disregarded?

Regards, -Kai.

1개 답변
0

Regrettably, AWS Firewall Manager does not currently support scope-down statements. This feature is not available through the API, CloudFormation, or JSON editor, and although the API may indicate success, the scope-down statement will not be reflected in the policy.

We have already raised a feature request for this issue, but we are unable to provide an estimate on when this feature will be released. We encourage you to monitor our What's New [1] and Blog pages [2] for any new feature announcements.

In the meantime, you can implement a workaround by creating a custom rule group to whitelist the traffic that you want to allow, and adding the rule below the AWS managed rule group [3].

[1] https://aws.amazon.com/new/ [2] https://aws.amazon.com/blogs/aws/ [3] https://repost.aws/knowledge-center/waf-detect-false-positives-from-amrs

profile pictureAWS
지원 엔지니어
Rutba_Z
답변함 일 년 전
  • Yeah, I kind of expected to hear that after further experimentation. Thanks for the confirmation.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠