View a markdown version of this page

AWS::NetworkSecurityManager::Rule - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::NetworkSecurityManager::Rule

The AWS::NetworkSecurityManager::Rule resource specifies an AWS Network Security Manager rule. A rule defines a network security configuration to enforce, such as an AWS WAF rule group or a single web ACL setting.

You reference a rule from a template or a policy, then roll the protections out to the accounts and resources selected by a scope. Rules created with this resource are always published in ACTIVE state; CloudFormation does not create rules in DRAFT state.

For conceptual information and guidance on writing rule configurations, see the AWS Network Security Manager Developer Guide.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::NetworkSecurityManager::Rule", "Properties" : { "Configuration" : String, "FirewallType" : String, "RuleDescription" : String, "RuleName" : String, "RuleType" : String, "Tags" : [ Tag, ... ] } }

YAML

Type: AWS::NetworkSecurityManager::Rule Properties: Configuration: String FirewallType: String RuleDescription: String RuleName: String RuleType: String Tags: - Tag

Properties

Configuration

The firewall configuration for the rule, as a JSON string. The structure depends on the values of FirewallType and RuleType. For an AWS WAFINSPECTION rule, provide an AWS WAF rule group. For an AWS WAFCONFIGURATION rule, provide a single web ACL setting, such as DefaultAction or VisibilityConfig.

Note

This property is a JSON string, not a JSON object. In a template, supply the configuration as a quoted string, or generate it with the Fn::ToJsonString intrinsic function.

This property is required when you create a rule.

For the schema of each setting and complete examples, see Writing rule configurations in the AWS Network Security Manager Developer Guide.

Required: Conditional

Type: String

Update requires: No interruption

FirewallType

The type of firewall that the rule configures. WAF specifies an AWS WAF rule.

This property is required when you create a rule. You can't change the firewall type after you create the rule.

Required: Conditional

Type: String

Allowed values: WAF

Update requires: Replacement

RuleDescription

A description of the rule.

Required: No

Type: String

Pattern: [a-zA-Z0-9 _.:/=+\-@]*

Minimum: 0

Maximum: 256

Update requires: No interruption

RuleName

The name of the rule.

You can't change the name of a rule after you create it.

Required: Yes

Type: String

Pattern: [a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*

Minimum: 1

Maximum: 128

Update requires: Replacement

RuleType

The type of the rule. CONFIGURATION rules contain firewall settings, and INSPECTION rules contain rule groups.

This property is required when you create a rule, and when you update Configuration. You can't change the rule type after you create the rule.

Required: Conditional

Type: String

Allowed values: CONFIGURATION | INSPECTION

Update requires: Replacement

Tags

The tags to assign to the rule. Each tag is a key-value pair. You can add tags when you create the rule and change them afterward without replacing the rule.

For more information, see Tag.

Required: No

Type: Array of Tag

Update requires: No interruption

Return values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the rule. For example:

{ "Ref": "myRule" }

For a rule named block-known-bad-ips, Ref returns a value similar to arn:aws:network-security-manager:us-east-1:123456789012:rule:a1b2c3d4e5f6.

For more information about using the Ref function, see Ref.

Fn::GetAtt

The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.

For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.

RuleArn

The Amazon Resource Name (ARN) of the rule. For example: arn:aws:network-security-manager:us-east-1:123456789012:rule:a1b2c3d4e5f6.

RuleId

The service-generated identifier of the rule. For example: a1b2c3d4e5f6.

Status

The current status of the rule. Rules managed with CloudFormation are always published, so this attribute returns ACTIVE.

Allowed Values: DRAFT | ACTIVE

UpdatedAt

The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.

Version

The version of the resource.

Examples

Create a rule that sets the default action of a web ACL

YAML

AWSTemplateFormatVersion: "2010-09-09" Description: Creates a Network Security Manager rule that sets the default action of a web ACL. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default RuleDescription: Allows requests that no rule group blocks. FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' Tags: - Key: Owner Value: network-security Outputs: RuleArn: Description: The ARN of the rule, for use in a template or policy. Value: !GetAtt AllowByDefaultRule.RuleArn