내용으로 건너뛰기

AWS WAF Rate-Based Rule - How to permanently block offending IP addresses?

0

Hi all,

I would like to hear your approaches when applying a rate-based rule via AWS WAF.

What are the best ways to permanently block IP addresses that trigger the RBR? I would also like to send notification to our internal team that:

  1. The rule has been triggered
  2. List the IP (or IPs) that have been blocked

Thanks!

  • please accept the answer if it was useful

2개 답변
1
  • Hi Oleksii, I appreciate the reply, however, in the Solution Overview & Architecture section, it refers to a minimum block period. I would like for it to be permanent until someone reviews it and removes it intentionally. I would be concerned if the same IP is compromised again in the near or long term.

    "It blocks the IP addresses blocked by a rate-based rule for a configurable time period. Minimum supported block period is 6 minutes.

0

Hi Adrian, If your requirement is block specific ip permanently, create an ip set steps: Here and create a new Web ACL/ Rules / "Add my own rules and rule groups” select the IP Set, Source IP Address, Action->Block and save, steps: Here.

AWS

답변함 2년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.