Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

AWS::WAFv2::RuleGroup ForwardedIPConfiguration

Focus mode
AWS::WAFv2::RuleGroup ForwardedIPConfiguration - AWS CloudFormation
Filter View

The configuration for inspecting IP addresses in an HTTP header that you specify, instead of using the IP address that's reported by the web request origin. Commonly, this is the X-Forwarded-For (XFF) header, but you can specify any header name.

Note

If the specified header isn't present in the request, AWS WAF doesn't apply the rule to the web request at all.

This configuration is used for GeoMatchStatement and RateBasedStatement. For IPSetReferenceStatement, use IPSetForwardedIPConfig instead.

AWS WAF only evaluates the first IP address found in the specified HTTP header.

Syntax

To declare this entity in your AWS CloudFormation template, use the following syntax:

JSON

{ "FallbackBehavior" : String, "HeaderName" : String }

YAML

FallbackBehavior: String HeaderName: String

Properties

FallbackBehavior

The match status to assign to the web request if the request doesn't have a valid IP address in the specified position.

Note

If the specified header isn't present in the request, AWS WAF doesn't apply the rule to the web request at all.

You can specify the following fallback behaviors:

  • MATCH - Treat the web request as matching the rule statement. AWS WAF applies the rule action to the request.

  • NO_MATCH - Treat the web request as not matching the rule statement.

Required: Yes

Type: String

Allowed values: MATCH | NO_MATCH

Update requires: No interruption

HeaderName

The name of the HTTP header to use for the IP address. For example, to use the X-Forwarded-For (XFF) header, set this to X-Forwarded-For.

Note

If the specified header isn't present in the request, AWS WAF doesn't apply the rule to the web request at all.

Required: Yes

Type: String

Pattern: ^[a-zA-Z0-9-]+{1,255}$

Update requires: No interruption

On this page

PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.