Skip to content

WAF Web ACL

L7 application firewall (rules, rate limits).

edge
category
11
settings
1
inputs
1
outputs
SettingTypeRequiredDefault
ACL nameTextYes
DescriptionText
Scope
Options: Regional (ALB / API GW), CloudFront
ChoiceREGIONAL
Default action
Options: Allow, Block
ChoiceALLOW
AWS managed rule groupsList
Rate limit / 5 minNumber2000
CloudWatch metricsToggletrue
Sampled requestsToggletrue
Logging destination ARNText
Redacted fields (CSV)Text
TagsKey–value
SocketDirectionAcceptsTerraform arg
Protected resourceInputany
Protected resourcesOutputaws.cloudfront, aws.waf-logging-configuration, aws.waf-web-acl-association