This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::NetworkSecurityManager::Policy
The AWS::NetworkSecurityManager::Policy resource specifies an
AWS Network Security Manager policy. A policy combines templates and
rules with enforcement settings for a single firewall type, such as
AWS WAF or AWS Shield Advanced.
A policy does not protect anything on its own. It takes effect when you associate it
with an AWS::NetworkSecurityManager::Deployment resource, which supplies
the accounts and resources that the policy applies to.
Note
Policies that you create with CloudFormation are always published. The
Status attribute of a CloudFormation-managed policy is
ACTIVE, never DRAFT.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::NetworkSecurityManager::Policy", "Properties" : { "AssociatedTemplateAndRuleList" :[ AssociatedTemplateAndRule, ... ], "FirewallType" :String, "PolicyConfiguration" :PolicyConfiguration, "PolicyDescription" :String, "PolicyName" :String, "Priority" :Integer, "Tags" :[ Tag, ... ]} }
YAML
Type: AWS::NetworkSecurityManager::Policy Properties: AssociatedTemplateAndRuleList:- AssociatedTemplateAndRuleFirewallType:StringPolicyConfiguration:PolicyConfigurationPolicyDescription:StringPolicyName:StringPriority:IntegerTags:- Tag
Properties
AssociatedTemplateAndRuleList-
The templates and rules to associate with the policy. Each entry in the list must specify exactly one of
TemplateArnorRuleArn. An entry that sets both, or neither, causes the stack operation to fail.For AWS WAF policies, specify 1 to 100 templates or rules, of which at most 2 can be templates. For AWS Shield Advanced policies, omit this property or specify an empty list.
Required: No
Type: Array of AssociatedTemplateAndRule
Minimum:
0Maximum:
100Update requires: No interruption
FirewallType-
The type of firewall that the policy configures. Specify
WAFfor an AWS WAF policy, orSHIELD_ADVANCEDfor an AWS Shield Advanced policy.You can't change the firewall type of a policy after you create it. To use a different firewall type, you must replace the policy.
Allowed Values:
WAF|SHIELD_ADVANCEDRequired: Yes
Type: String
Allowed values:
WAF | SHIELD_ADVANCEDUpdate requires: Replacement
PolicyConfiguration-
The configuration settings that control how the policy behaves, including whether remediation is enabled and settings specific to the firewall type.
Required: Yes
Type: PolicyConfiguration
Update requires: No interruption
PolicyDescription-
A description of the policy.
Required: No
Type: String
Pattern:
^[a-zA-Z0-9 _.:/=+\-@]*$Maximum:
256Update requires: No interruption
PolicyName-
The name of the policy. The name must be unique within your AWS account and AWS Region.
You can't change the name of a policy after you create it. To use a different name, you must replace the policy.
Required: Yes
Type: String
Pattern:
^[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*$Minimum:
1Maximum:
128Update requires: Replacement
Priority-
The priority of the policy. A lower number indicates a higher priority. When more than one policy applies to the same resource, Network Security Manager uses the settings of the highest-priority policy to resolve conflicts.
Each priority can be used by only one policy in an AWS account and AWS Region. Creating a policy with a priority that is already in use fails.
Required: Yes
Type: Integer
Minimum:
1Update requires: No interruption
-
The tags to add to the resource when it is created.
Required: No
Type: Array of Tag
Update requires: No interruption
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the policy. For
example:
{ "Ref": "myPolicy" }
For a policy with the logical ID myPolicy, Ref returns a
value such as
arn:aws:network-security-manager:us-east-1:123456789012:policy:a1b2c3d4e5f6.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
PolicyArn-
The Amazon Resource Name (ARN) of the policy.
PolicyId-
The service-generated ID of the policy. For example:
a1b2c3d4e5f6. Status-
The current status of the policy. Policies that CloudFormation manages are always published, so this attribute returns
ACTIVE.Allowed Values:
DRAFT|ACTIVE UpdatedAt-
The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.
Version-
The version of the policy. Network Security Manager increments this value each time the policy is published. For example:
3.
Examples
Apply a template with automatic remediation
YAML
AWSTemplateFormatVersion: "2010-09-09" Description: Combines a Network Security Manager template with enforcement settings. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' BaselineTemplate: Type: AWS::NetworkSecurityManager::Template Properties: TemplateName: waf-baseline FirewallType: WAF AssociatedRuleList: - RuleArn: !GetAtt AllowByDefaultRule.RuleArn BaselinePolicy: Type: AWS::NetworkSecurityManager::Policy Properties: PolicyName: waf-baseline-policy PolicyDescription: Applies the baseline template and remediates resources automatically. FirewallType: WAF Priority: 100 AssociatedTemplateAndRuleList: - TemplateArn: !GetAtt BaselineTemplate.TemplateArn PolicyConfiguration: RemediationEnabled: true ResourcesCleanUp: false WafConfig: ExistingCustomerWebACLResolution: RETROFIT ConflictResolution: MERGE_WHERE_APPLICABLE Outputs: PolicyArn: Value: !GetAtt BaselinePolicy.PolicyArn