This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::NetworkSecurityManager::Rule
The AWS::NetworkSecurityManager::Rule resource specifies an AWS Network Security Manager rule. A rule defines a network security configuration to enforce, such as an AWS WAF rule group or a single web ACL setting.
You reference a rule from a template or a policy, then roll the protections out to the accounts and resources selected by a scope. Rules created with this resource are always published in ACTIVE state; CloudFormation does not create rules in DRAFT state.
For conceptual information and guidance on writing rule configurations, see the AWS Network Security Manager Developer Guide.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "Type" : "AWS::NetworkSecurityManager::Rule", "Properties" : { "Configuration" :String, "FirewallType" :String, "RuleDescription" :String, "RuleName" :String, "RuleType" :String, "Tags" :[ Tag, ... ]} }
YAML
Type: AWS::NetworkSecurityManager::Rule Properties: Configuration:StringFirewallType:StringRuleDescription:StringRuleName:StringRuleType:StringTags:- Tag
Properties
Configuration-
The firewall configuration for the rule, as a JSON string. The structure depends on the values of
FirewallTypeandRuleType. For an AWS WAFINSPECTIONrule, provide an AWS WAF rule group. For an AWS WAFCONFIGURATIONrule, provide a single web ACL setting, such asDefaultActionorVisibilityConfig.Note
This property is a JSON string, not a JSON object. In a template, supply the configuration as a quoted string, or generate it with the Fn::ToJsonString intrinsic function.
This property is required when you create a rule.
For the schema of each setting and complete examples, see Writing rule configurations in the AWS Network Security Manager Developer Guide.
Required: Conditional
Type: String
Update requires: No interruption
FirewallType-
The type of firewall that the rule configures.
WAFspecifies an AWS WAF rule.This property is required when you create a rule. You can't change the firewall type after you create the rule.
Required: Conditional
Type: String
Allowed values:
WAFUpdate requires: Replacement
RuleDescription-
A description of the rule.
Required: No
Type: String
Pattern:
[a-zA-Z0-9 _.:/=+\-@]*Minimum:
0Maximum:
256Update requires: No interruption
RuleName-
The name of the rule.
You can't change the name of a rule after you create it.
Required: Yes
Type: String
Pattern:
[a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*Minimum:
1Maximum:
128Update requires: Replacement
RuleType-
The type of the rule.
CONFIGURATIONrules contain firewall settings, andINSPECTIONrules contain rule groups.This property is required when you create a rule, and when you update
Configuration. You can't change the rule type after you create the rule.Required: Conditional
Type: String
Allowed values:
CONFIGURATION | INSPECTIONUpdate requires: Replacement
-
The tags to assign to the rule. Each tag is a key-value pair. You can add tags when you create the rule and change them afterward without replacing the rule.
For more information, see Tag.
Required: No
Type: Array of Tag
Update requires: No interruption
Return values
Ref
When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the rule. For example:
{ "Ref": "myRule" }
For a rule named block-known-bad-ips, Ref returns a value similar to arn:aws:network-security-manager:us-east-1:123456789012:rule:a1b2c3d4e5f6.
For more information about using the Ref function, see Ref.
Fn::GetAtt
The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.
For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.
RuleArn-
The Amazon Resource Name (ARN) of the rule. For example:
arn:aws:network-security-manager:us-east-1:123456789012:rule:a1b2c3d4e5f6. RuleId-
The service-generated identifier of the rule. For example:
a1b2c3d4e5f6. Status-
The current status of the rule. Rules managed with CloudFormation are always published, so this attribute returns
ACTIVE.Allowed Values:
DRAFT|ACTIVE UpdatedAt-
The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.
Version-
The version of the resource.
Examples
Create a rule that sets the default action of a web ACL
YAML
AWSTemplateFormatVersion: "2010-09-09" Description: Creates a Network Security Manager rule that sets the default action of a web ACL. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default RuleDescription: Allows requests that no rule group blocks. FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' Tags: - Key: Owner Value: network-security Outputs: RuleArn: Description: The ARN of the rule, for use in a template or policy. Value: !GetAtt AllowByDefaultRule.RuleArn