1 Answer
- Newest
- Most votes
- Most comments
0
Hi suvan,
"You can use an AWS WAF web ACL to protect global or regional resource types. You do this by associating the web ACL with the resources that you want to protect. The web ACL and any AWS WAF resources that it uses must be located in the Region where the associated resource is located. For Amazon CloudFront distributions, this is set to US East (N. Virginia)." https://docs.aws.amazon.com/waf/latest/developerguide/how-aws-waf-works-resources.html
Did you check the region?
answered 15 days ago
Relevant content
- asked 5 months ago
- asked 7 months ago
- Accepted Answerasked 2 years ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 23 days ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated a month ago
Hey Vitor, thanks for your response! I saw that documentation but I also don't have the option to select my cloudfront distribution unless I select the global region. That is if I try to associate it during or after web ACL creation
Hi suvan,
For CloudFront, the associated Web ACL should indeed be global.
Did you create your ACL in the "Global (CloudFront)" scope when setting it up in AWS WAF?
Remember, even though CloudFront is global, you'll still choose a region within the Web ACLs section.
Yup, I only have the option to select the CloudFront distribution if I'm on the global region in the ACL menu
Did you created ACL Globally? You can select it inside ACL creation page.