View a markdown version of this page

AWS::NetworkSecurityManager::Policy - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::NetworkSecurityManager::Policy

The AWS::NetworkSecurityManager::Policy resource specifies an AWS Network Security Manager policy. A policy combines templates and rules with enforcement settings for a single firewall type, such as AWS WAF or AWS Shield Advanced.

A policy does not protect anything on its own. It takes effect when you associate it with an AWS::NetworkSecurityManager::Deployment resource, which supplies the accounts and resources that the policy applies to.

Note

Policies that you create with CloudFormation are always published. The Status attribute of a CloudFormation-managed policy is ACTIVE, never DRAFT.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::NetworkSecurityManager::Policy", "Properties" : { "AssociatedTemplateAndRuleList" : [ AssociatedTemplateAndRule, ... ], "FirewallType" : String, "PolicyConfiguration" : PolicyConfiguration, "PolicyDescription" : String, "PolicyName" : String, "Priority" : Integer, "Tags" : [ Tag, ... ] } }

YAML

Type: AWS::NetworkSecurityManager::Policy Properties: AssociatedTemplateAndRuleList: - AssociatedTemplateAndRule FirewallType: String PolicyConfiguration: PolicyConfiguration PolicyDescription: String PolicyName: String Priority: Integer Tags: - Tag

Properties

AssociatedTemplateAndRuleList

The templates and rules to associate with the policy. Each entry in the list must specify exactly one of TemplateArn or RuleArn. An entry that sets both, or neither, causes the stack operation to fail.

For AWS WAF policies, specify 1 to 100 templates or rules, of which at most 2 can be templates. For AWS Shield Advanced policies, omit this property or specify an empty list.

Required: No

Type: Array of AssociatedTemplateAndRule

Minimum: 0

Maximum: 100

Update requires: No interruption

FirewallType

The type of firewall that the policy configures. Specify WAF for an AWS WAF policy, or SHIELD_ADVANCED for an AWS Shield Advanced policy.

You can't change the firewall type of a policy after you create it. To use a different firewall type, you must replace the policy.

Allowed Values: WAF | SHIELD_ADVANCED

Required: Yes

Type: String

Allowed values: WAF | SHIELD_ADVANCED

Update requires: Replacement

PolicyConfiguration

The configuration settings that control how the policy behaves, including whether remediation is enabled and settings specific to the firewall type.

Required: Yes

Type: PolicyConfiguration

Update requires: No interruption

PolicyDescription

A description of the policy.

Required: No

Type: String

Pattern: ^[a-zA-Z0-9 _.:/=+\-@]*$

Maximum: 256

Update requires: No interruption

PolicyName

The name of the policy. The name must be unique within your AWS account and AWS Region.

You can't change the name of a policy after you create it. To use a different name, you must replace the policy.

Required: Yes

Type: String

Pattern: ^[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*$

Minimum: 1

Maximum: 128

Update requires: Replacement

Priority

The priority of the policy. A lower number indicates a higher priority. When more than one policy applies to the same resource, Network Security Manager uses the settings of the highest-priority policy to resolve conflicts.

Each priority can be used by only one policy in an AWS account and AWS Region. Creating a policy with a priority that is already in use fails.

Required: Yes

Type: Integer

Minimum: 1

Update requires: No interruption

Tags

The tags to add to the resource when it is created.

Required: No

Type: Array of Tag

Update requires: No interruption

Return values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the policy. For example:

{ "Ref": "myPolicy" }

For a policy with the logical ID myPolicy, Ref returns a value such as arn:aws:network-security-manager:us-east-1:123456789012:policy:a1b2c3d4e5f6.

For more information about using the Ref function, see Ref.

Fn::GetAtt

The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.

For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.

PolicyArn

The Amazon Resource Name (ARN) of the policy.

PolicyId

The service-generated ID of the policy. For example: a1b2c3d4e5f6.

Status

The current status of the policy. Policies that CloudFormation manages are always published, so this attribute returns ACTIVE.

Allowed Values: DRAFT | ACTIVE

UpdatedAt

The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.

Version

The version of the policy. Network Security Manager increments this value each time the policy is published. For example: 3.

Examples

Apply a template with automatic remediation

YAML

AWSTemplateFormatVersion: "2010-09-09" Description: Combines a Network Security Manager template with enforcement settings. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' BaselineTemplate: Type: AWS::NetworkSecurityManager::Template Properties: TemplateName: waf-baseline FirewallType: WAF AssociatedRuleList: - RuleArn: !GetAtt AllowByDefaultRule.RuleArn BaselinePolicy: Type: AWS::NetworkSecurityManager::Policy Properties: PolicyName: waf-baseline-policy PolicyDescription: Applies the baseline template and remediates resources automatically. FirewallType: WAF Priority: 100 AssociatedTemplateAndRuleList: - TemplateArn: !GetAtt BaselineTemplate.TemplateArn PolicyConfiguration: RemediationEnabled: true ResourcesCleanUp: false WafConfig: ExistingCustomerWebACLResolution: RETROFIT ConflictResolution: MERGE_WHERE_APPLICABLE Outputs: PolicyArn: Value: !GetAtt BaselinePolicy.PolicyArn