Remove WAF WebAcl created by Firewall Manager

0

I am trying to delete a AWS WAF WebAcl that was created using Firewall Manager few months ago, but someone has removed the Firewall Manager policy, probably without ticking the "delete all policy resources" checkbox, so after this the webAcl remains existing, but I can't delete it. When I try to remove the webAcl I got the following error message:

Error You don't have permissions to delete the resource because it's managed by Firewall Manager.

Since the firewall manager policy doesn't exist anymore, I couldn't find a way to delete the loose webacl, no matter if I try via console or CLI, I always get this error message. I did a research in AWS docs but didn't find any related topic, so I am wondering if there is a way to delete it.

awsbrz
질문됨 일 년 전630회 조회
2개 답변
2

Hello AWS Customer,

If an account or resource goes out of scope for any reason, AWS Firewall Manager doesn't automatically remove protections or delete Firewall Manager-managed resources unless you select the Automatically remove protections from resources that leave the policy scope check box.[1]

Therefore, in order to delete this WebACL from your account, it has to be done from the "Admin Account".

Hope you will find this information useful.

Have a good day!

profile pictureAWS
지원 엔지니어
Jisoo_K
답변함 일 년 전
0

Hello Jisoo, Thanks for replying. The AWS Organization where this policy lives only contain 1 member account and I tried to delete the loose webacl using the root of the management account, but got the same error. There are anything that I'm missing?

awsbrz
답변함 일 년 전
  • By root of the management account, do you mean the Management account of the AWS Organisation or the Firewall Administrator account?

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠