This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.
AWS::NetworkSecurityManager::Policy WafConfig
AWS WAF-specific policy configuration settings. Specify this property
only for policies whose FirewallType is WAF.
Syntax
To declare this entity in your CloudFormation template, use the following syntax:
JSON
{ "ConflictResolution" :String, "ExistingCustomerWebACLResolution" :String}
YAML
ConflictResolution:StringExistingCustomerWebACLResolution:String
Properties
ConflictResolution-
How Network Security Manager combines this policy's settings with the settings of other policies that apply to the same resource.
MERGE_WHERE_APPLICABLEcombines the rule groups of every applicable policy into one configuration. Settings that can hold only a single value, such as the default action, are taken from the highest-priority policy.MERGE_WHERE_APPLICABLEis currently the only supported value.This property is required when
FirewallTypeisWAF.Allowed Values:
MERGE_WHERE_APPLICABLERequired: Conditional
Type: String
Allowed values:
MERGE_WHERE_APPLICABLEUpdate requires: No interruption
ExistingCustomerWebACLResolution-
Determines what Network Security Manager does when a resource in scope is already associated with a web ACL that you created yourself.
Note
This setting applies only to resources that already have your own web ACL. A resource with no web ACL always receives a web ACL that Network Security Manager creates and manages, whatever you set here.
When more than one policy applies to the same resource, Network Security Manager uses the value from the highest-priority policy. Values from lower-priority policies are ignored.
-
RETROFIT -
Network Security Manager adds the policy's rule groups to your existing web ACL. You keep the web ACL and it stays associated with the resource, and the rules you defined in it are preserved. Policy-wide settings, including the default action and the visibility configuration, are replaced with the policy's values.
If your web ACL is also associated with resources that this policy doesn't apply to, Network Security Manager doesn't modify it. The resource is reported as out of sync, with an issue explaining that the web ACL is shared.
When the policy stops applying to the resource, Network Security Manager stops managing your web ACL but doesn't remove the rule groups it added. To remove them, edit the web ACL yourself.
-
OVERRIDE_ASSOCIATION -
Network Security Manager associates a web ACL that it manages with the resource, replacing your association. Your web ACL is detached but is never deleted, and its own configuration is unchanged.
Network Security Manager doesn't record which web ACL it displaced and doesn't restore it. When the policy stops applying to the resource, the managed web ACL is removed and the resource is left with no web ACL. To restore your own web ACL, associate it with the resource again.
-
NO_REMEDIATION -
Network Security Manager leaves the resource and your web ACL unchanged, and doesn't create a managed web ACL for the resource. The policy's rule groups are not applied, so the resource isn't protected by this policy.
The resource is reported as out of sync for as long as this value is in effect, with an issue that names this setting as the reason and suggests changing it to
RETROFITorOVERRIDE_ASSOCIATION.
This property is required when
FirewallTypeisWAF.Allowed Values:
RETROFIT|OVERRIDE_ASSOCIATION|NO_REMEDIATIONRequired: Conditional
Type: String
Allowed values:
RETROFIT | OVERRIDE_ASSOCIATION | NO_REMEDIATIONUpdate requires: No interruption
-