Introducing a new console experience for AWS WAF
You can now use the updated experience to access AWS WAF functionality anywhere in the console. For more details, see Working with the console.
Creating an AWS Firewall Manager policy
The steps for creating a policy vary between the different policy types. Make sure to use the procedure for the type of policy that you need.
Important
AWS Firewall Manager doesn't support Amazon RouteĀ 53 or AWS Global Accelerator. If you want to protect these resources with Shield Advanced, you can't use a Firewall Manager policy. Instead, follow the instructions in Adding AWS Shield Advanced protection to AWS resources.
Topics
Creating an AWS Firewall Manager policy for AWS Shield Advanced
Creating an AWS Firewall Manager common security group policy
Creating an AWS Firewall Manager content audit security group policy
Creating an AWS Firewall Manager usage audit security group policy
Creating an AWS Firewall Manager policy for AWS Network Firewall
Creating an AWS Firewall Manager policy for Amazon RouteĀ 53 Resolver DNS Firewall
Creating an AWS Firewall Manager policy for Palo Alto Networks Cloud NGFW
Creating an AWS Firewall Manager policy for Fortigate Cloud Native Firewall (CNF) as a Service
Creating an AWS Firewall Manager policy for AWS WAF
In a Firewall Manager AWS WAF policy, you can use managed rule groups, which AWS and AWS Marketplace sellers create and maintain for you. You can also create and use your own rule groups. For more information about rule groups, see AWS WAF rule groups.
If you want to use your own rule groups, create those before you create your Firewall Manager AWS WAF policy. For guidance, see Managing your own rule groups. To use an individual custom rule, you must define your own rule group, define your rule within that, and then use the rule group in your policy.
For information about Firewall Manager AWS WAF policies, see Using AWS WAF policies with Firewall Manager.
To create a Firewall Manager policy for AWS WAF (console)
-
Sign in to the AWS Management Console using your Firewall Manager administrator account, and then open the Firewall Manager console at https://console.aws.amazon.com/wafv2/fmsv2
. For information about setting up a Firewall Manager administrator account, see AWS Firewall Manager prerequisites. Note
For information about setting up a Firewall Manager administrator account, see AWS Firewall Manager prerequisites.
-
In the navigation pane, choose Security policies.
-
Choose Create policy.
-
For Policy type, choose AWS WAF.
-
For Region, choose an AWS Region. To protect Amazon CloudFront distributions, choose Global.
To protect resources in multiple Regions (other than CloudFront distributions), you must create separate Firewall Manager policies for each Region.
-
Choose Next.
-
For Policy name, enter a descriptive name. Firewall Manager includes the policy name in the names of the web ACLs that it manages. The web ACL names have
FMManagedWebACLV2-followed by the policy name that you enter here,-, and the web ACL creation timestamp, in UTC milliseconds. For example,FMManagedWebACLV2-MyWAFPolicyName-1621880374078. -
For Web request body inspection, optionally change the body size limit. For information about body inspection size limits, including pricing considerations, see Considerations for managing body inspection in AWS WAF in the AWS WAF Developer Guide.
-
Under Policy rules, add the rule groups that you want AWS WAF to evaluate first and last in the web ACL. To use AWS WAF managed rule group versioning, toggle Enable versioning. The individual account managers can add rules and rule groups in between your first rule groups and your last rule groups. For more information about using AWS WAF rule groups in Firewall Manager policies for AWS WAF, see Using AWS WAF policies with Firewall Manager.
(Optional) To customize how your web ACL uses the rule group, choose Edit. The following are common customization settings:
-
For managed rule groups, override the rule actions for some or all rules. If you don't define an override action for a rule, the evaluation uses the rule action that's defined inside the rule group. For information about this option, see Overriding rule group actions in AWS WAF in the AWS WAF Developer Guide.
-
Some managed rule groups require you to provide additional configuration. See the documentation from your managed rule group provider. For information specific to the AWS Managed Rules rule groups, see AWS Managed Rules for AWS WAF in the AWS WAF Developer Guide.
When you're finished with your settings, choose Save rule.
-
-
Set the default action for the web ACL. This is the action that AWS WAF takes when a web request doesn't match any of the rules in the web ACL. You can add custom headers with the Allow action, or custom responses for the Block action. For more information about default web ACL actions, see Setting the protection pack (web ACL) default action in AWS WAF. For information about setting custom web requests and responses, see Customized web requests and responses in AWS WAF.
-
For Logging configuration, choose Enable logging to turn on logging. Logging provides detailed information about traffic that is analyzed by your web ACL. Choose the Logging destination, and then choose the logging destination that you configured. You must choose a logging destination whose name begins with
aws-waf-logs-. For information about configuring an AWS WAF logging destination, see Using AWS WAF policies with Firewall Manager. (Optional) If you don't want certain fields and their values included in the logs, redact those fields. Choose the field to redact, and then choose Add. Repeat as necessary to redact additional fields. The redacted fields appear as
REDACTEDin the logs. For example, if you redact the URI field, the URI field in the logs will beREDACTED.-
(Optional) If you don't want to send all requests to the logs, add your filtering criteria and behavior. Under Filter logs, for each filter that you want to apply, choose Add filter, then choose your filtering criteria and specify whether you want to keep or drop requests that match the criteria. When you finish adding filters, if needed, modify the Default logging behavior. For more information, see Finding your protection pack (web ACL) records in the AWS WAF Developer Guide.
-
You can define a Token domain list to enable token sharing between protected applications. Tokens are used by the CAPTCHA and Challenge actions and by the application integration SDKs that you implement when you use the AWS Managed Rules rule groups for AWS WAF Fraud Control account takeover prevention (ATP) and AWS WAF Bot Control.
Public suffixes aren't allowed. For example, you can't use
gov.auorco.ukas a token domain.By default, AWS WAF accepts tokens only for the domain of the protected resource. If you add token domains in this list, AWS WAF accepts tokens for all domains in the list and for the domain of the associated resource. For more information, see AWS WAF protection pack (web ACL) token domain list configuration in the AWS WAF Developer Guide.
You can only change the web ACL's CAPTCHA and challenge immunity times when you edit an existing web ACL. You can find these settings under the Firewall Manager Policy details page. For information about these settings, see Setting timestamp expiration and token immunity times in AWS WAF. If you update the Association config, CAPTCHA, Challenge, or Token domain list settings in an existing policy, Firewall Manager will overwrite the your local web ACLs with the new values. However, if you don't update the policy's Association config, CAPTCHA, Challenge, or Token domain list settings, then the values in your local web ACLs will remain unchanged. For information about this option, see CAPTCHA and Challenge in AWS WAF in the AWS WAF Developer Guide.
-
Under Web ACL management, choose how Firewall Manager manages web ACL creation and clean up.
-
For Manage unassociated web ACLs, choose whether Firewall Manager manages unassociated web ACLs. With this option, Firewall Manager creates web ACLs for the accounts within policy scope only if the web ACLs will be used by at least one resource. When an account comes into policy scope, Firewall Manager automatically creates a web ACL in the account if at least one resource will use it.
When you enable this option, Firewall Manager performs a one-time cleanup of unassociated web ACLs in your account. The cleanup process can take several hours. If a resource leaves policy scope after Firewall Manager creates a web ACL, Firewall Manager disassociates the resource from the web ACL, but doesn't clean up the unassociated web ACL. Firewall Manager only cleans up unassociated web ACLs when you first enable management of unassociated web ACLs in the policy.
-
For Web ACL source, specify whether to create all new web ACLs for in-scope resources or to retrofit existing web ACLs where possible. Firewall Manager can retrofit web ACLs that are owned by in-scope accounts.
The default behavior is to create all new web ACLs. If you choose this, all web ACLs managed by Firewall Manager will have names that begin with
FMManagedWebACLV2. If you choose to retrofit existing web ACLs, the retrofitted web ACLs will have their original names and the ones created by Firewall Manager will have names that begin withFMManagedWebACLV2.
-
-
For Policy action, if you want to create a web ACL in each applicable account within the organization, but not apply the web ACL to any resources yet, choose Identify resources that don't comply with the policy rules, but don't auto remediate and don't choose Manage unassociated web ACLs. You can change these options later.
If instead you want to automatically apply the policy to existing in-scope resources, choose Auto remediate any noncompliant resources. If Manage unassociated web ACLs is disabled, the Auto remediate any noncompliant resources option creates a web ACL in each applicable account within the organization and associates the web ACL with the resources in the accounts. If Manage unassociated web ACLs is enabled, the Auto remediate any noncompliant resources option only creates and associates a web ACL in accounts that have resources eligible for association to the web ACL.
When you choose Auto remediate any noncompliant resources, you can also choose to remove existing web ACL associations from in-scope resources, for the web ACLs that aren't managed by another active Firewall Manager policy. If you choose this option, Firewall Manager first associates the policy's web ACL with the resources, and then removes the prior associations. If a resource has an association with another web ACL that's managed by a different active Firewall Manager policy, this choice doesn't affect that association.
-
Choose Next.
-
For AWS accounts this policy applies to, choose the option as follows:
-
If you want to apply the policy to all accounts in your organization, leave the default selection, Include all accounts under my AWS organization.
If you want to apply the policy only to specific accounts or accounts that are in specific AWS Organizations organizational units (OUs), choose Include only the specified accounts and organizational units, and then add the accounts and OUs that you want to include. Specifying an OU is the equivalent of specifying all accounts in the OU and in any of its child OUs, including any child OUs and accounts that are added at a later time.
If you want to apply the policy to all but a specific set of accounts or AWS Organizations organizational units (OUs), choose Exclude the specified accounts and organizational units, and include all others, and then add the accounts and OUs that you want to exclude. Specifying an OU is the equivalent of specifying all accounts in the OU and in any of its child OUs, including any child OUs and accounts that are added at a later time.
You can only choose one of the options.
After you apply the policy, Firewall Manager automatically evaluates any new accounts against your settings. For example, if you include only specific accounts, Firewall Manager doesn't apply the policy to any new accounts. As another example, if you include an OU, when you add an account to the OU or to any of its child OUs, Firewall Manager automatically applies the policy to the new account.
-
-
For Resource type, choose the types of resources that you want to protect.
-
For Resources, you can narrow the scope of the policy using tagging, by either including or excluding resources with the tags that you specify. You can use inclusion or exclusion, and not both. For more information about tags to define policy scope, see Using the AWS Firewall Manager policy scope.
Resource tags can only have non-null values. If you omit the value for a tag, Firewall Manager saves the tag with an empty string value: "". Resource tags only match with tags that have the same key and the same value.
-
Choose Next.
-
For Policy tags, add any identifying tags that you want to add to the Firewall Manager policy resource. For more information about tags, see Working with Tag Editor.
-
Choose Next.
-
Review the new policy settings and return to any pages where you need to any adjustments.
When you are satisfied with the policy, choose Create policy. In the AWS Firewall Manager policies pane, your policy should be listed. It will probably indicate Pending under the accounts headings and it will indicate the status of the Automatic remediation setting. The creation of a policy can take several minutes. After the Pending status is replaced with account counts, you can choose the policy name to explore the compliance status of the accounts and resources. For information, see Viewing compliance information for an AWS Firewall Manager policy
Creating an AWS Firewall Manager policy for AWS WAF Classic
To create a Firewall Manager policy for AWS WAF Classic (console)
-
Sign in to the AWS Management Console using your Firewall Manager administrator account, and then open the Firewall Manager console at https://console.aws.amazon.com/wafv2/fmsv2
. For information about setting up a Firewall Manager administrator account, see AWS Firewall Manager prerequisites. Note