View a markdown version of this page

AWS::NetworkSecurityManager::Policy WafConfig - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::NetworkSecurityManager::Policy WafConfig

AWS WAF-specific policy configuration settings. Specify this property only for policies whose FirewallType is WAF.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

Properties

ConflictResolution

How Network Security Manager combines this policy's settings with the settings of other policies that apply to the same resource.

MERGE_WHERE_APPLICABLE combines the rule groups of every applicable policy into one configuration. Settings that can hold only a single value, such as the default action, are taken from the highest-priority policy. MERGE_WHERE_APPLICABLE is currently the only supported value.

This property is required when FirewallType is WAF.

Allowed Values: MERGE_WHERE_APPLICABLE

Required: Conditional

Type: String

Allowed values: MERGE_WHERE_APPLICABLE

Update requires: No interruption

ExistingCustomerWebACLResolution

Determines what Network Security Manager does when a resource in scope is already associated with a web ACL that you created yourself.

Note

This setting applies only to resources that already have your own web ACL. A resource with no web ACL always receives a web ACL that Network Security Manager creates and manages, whatever you set here.

When more than one policy applies to the same resource, Network Security Manager uses the value from the highest-priority policy. Values from lower-priority policies are ignored.

RETROFIT

Network Security Manager adds the policy's rule groups to your existing web ACL. You keep the web ACL and it stays associated with the resource, and the rules you defined in it are preserved. Policy-wide settings, including the default action and the visibility configuration, are replaced with the policy's values.

If your web ACL is also associated with resources that this policy doesn't apply to, Network Security Manager doesn't modify it. The resource is reported as out of sync, with an issue explaining that the web ACL is shared.

When the policy stops applying to the resource, Network Security Manager stops managing your web ACL but doesn't remove the rule groups it added. To remove them, edit the web ACL yourself.

OVERRIDE_ASSOCIATION

Network Security Manager associates a web ACL that it manages with the resource, replacing your association. Your web ACL is detached but is never deleted, and its own configuration is unchanged.

Network Security Manager doesn't record which web ACL it displaced and doesn't restore it. When the policy stops applying to the resource, the managed web ACL is removed and the resource is left with no web ACL. To restore your own web ACL, associate it with the resource again.

NO_REMEDIATION

Network Security Manager leaves the resource and your web ACL unchanged, and doesn't create a managed web ACL for the resource. The policy's rule groups are not applied, so the resource isn't protected by this policy.

The resource is reported as out of sync for as long as this value is in effect, with an issue that names this setting as the reason and suggests changing it to RETROFIT or OVERRIDE_ASSOCIATION.

This property is required when FirewallType is WAF.

Allowed Values: RETROFIT | OVERRIDE_ASSOCIATION | NO_REMEDIATION

Required: Conditional

Type: String

Allowed values: RETROFIT | OVERRIDE_ASSOCIATION | NO_REMEDIATION

Update requires: No interruption