View a markdown version of this page

AWS::NetworkSecurityManager::Template - AWS CloudFormation

This is the new CloudFormation Template Reference Guide. Please update your bookmarks and links. For help getting started with CloudFormation, see the AWS CloudFormation User Guide.

AWS::NetworkSecurityManager::Template

The AWS::NetworkSecurityManager::Template resource specifies an AWS Network Security Manager template. A template groups one or more rules so that you can reuse the same set of protections across policies. You can also associate rules with a policy directly, without using a template.

You reference a template from a policy, then roll the protections out to the accounts and resources selected by a scope. Templates created with this resource are always published in ACTIVE state; CloudFormation does not create templates in DRAFT state.

For conceptual information and guidance on writing rule configurations, see the AWS Network Security Manager Developer Guide. For the default quotas that apply to your account, see Quotas.

Syntax

To declare this entity in your CloudFormation template, use the following syntax:

JSON

{ "Type" : "AWS::NetworkSecurityManager::Template", "Properties" : { "AssociatedRuleList" : [ AssociatedRule, ... ], "FirewallType" : String, "Tags" : [ Tag, ... ], "TemplateDescription" : String, "TemplateName" : String } }

YAML

Type: AWS::NetworkSecurityManager::Template Properties: AssociatedRuleList: - AssociatedRule FirewallType: String Tags: - Tag TemplateDescription: String TemplateName: String

Properties

AssociatedRuleList

The rules associated with the template.

This property is required when you create a template. You must associate at least one rule; AWS Network Security Manager rejects a template that has no associated rules.

Required: Conditional

Type: Array of AssociatedRule

Minimum: 1

Maximum: 50

Update requires: No interruption

FirewallType

The type of firewall that the template configures. WAF specifies an AWS WAF template. All rules that you associate with the template must use the same firewall type.

This property is required when you create a template. You can't change the firewall type after you create the template.

Required: Conditional

Type: String

Allowed values: WAF | NETWORK_FIREWALL | NETWORK_FIREWALL_V2 | IGW_FIREWALL

Update requires: Replacement

Tags

The tags to assign to the template. Each tag is a key-value pair. You can add tags when you create the template and change them afterward without replacing the template. You can assign up to 200 tags to a template.

For more information, see Tag.

Required: No

Type: Array of Tag

Update requires: No interruption

TemplateDescription

A description of the template.

Required: No

Type: String

Pattern: [a-zA-Z0-9 _.:/=+\-@]*

Minimum: 0

Maximum: 256

Update requires: No interruption

TemplateName

The name of the template.

You can't change the name of a template after you create it.

Required: Yes

Type: String

Pattern: [a-zA-Z0-9][a-zA-Z0-9 _.:/=+\-@]*

Minimum: 1

Maximum: 128

Update requires: Replacement

Return values

Ref

When you pass the logical ID of this resource to the intrinsic Ref function, Ref returns the Amazon Resource Name (ARN) of the template. For example:

{ "Ref": "myTemplate" }

For a template named common-waf-baseline, Ref returns a value similar to arn:aws:network-security-manager:us-east-1:123456789012:template:a1b2c3d4e5f6.

For more information about using the Ref function, see Ref.

Fn::GetAtt

The Fn::GetAtt intrinsic function returns a value for a specified attribute of this type. The following are the available attributes and sample return values.

For more information about using the Fn::GetAtt intrinsic function, see Fn::GetAtt.

Status

The current status of the template. Templates created with this resource are always published, so this value is always ACTIVE.

Allowed Values: DRAFT | ACTIVE

TemplateArn

The Amazon Resource Name (ARN) of the template.

TemplateId

The service-generated id of the template.

UpdatedAt

The time when the resource was last updated. For a snapshot, this is the time when the snapshot was created.

Version

The version of the template. AWS Network Security Manager assigns version 1 when it publishes the template and increments the version each time the template is published again, including each time CloudFormation updates it.

Examples

Group a rule into a reusable template

YAML

AWSTemplateFormatVersion: "2010-09-09" Description: Groups Network Security Manager rules into a reusable template. Resources: AllowByDefaultRule: Type: AWS::NetworkSecurityManager::Rule Properties: RuleName: allow-by-default FirewallType: WAF RuleType: CONFIGURATION Configuration: '{"DefaultAction":{"Allow":{}}}' BaselineTemplate: Type: AWS::NetworkSecurityManager::Template Properties: TemplateName: waf-baseline TemplateDescription: Baseline web ACL settings for every account. FirewallType: WAF AssociatedRuleList: - RuleArn: !GetAtt AllowByDefaultRule.RuleArn Outputs: TemplateArn: Value: !GetAtt BaselineTemplate.TemplateArn