aws-waf-security-automations icon indicating copy to clipboard operation
aws-waf-security-automations copied to clipboard

How to disable managed ruleset options

Open sbe-arg opened this issue 10 months ago • 1 comments

Any way to change from BLOCK to something else, at least COUNT a list of managed rules?

Sometimes there are application that need some of the rules softened or disabled such as Body size and others...

https://docs.aws.amazon.com/waf/latest/developerguide/aws-managed-rule-groups-baseline.html

Somehow a list array to enter rule names that will be set to count?

edited to add context links: we need to allow expand the statement logic with rule action overrides from an array?

https://github.com/aws-solutions/aws-waf-security-automations/blob/main/deployment/aws-waf-security-automations-webacl.template#L473

https://docs.amazonaws.cn/en_us/AWSCloudFormation/latest/UserGuide/aws-properties-wafv2-webacl-managedrulegroupstatement.html

https://docs.amazonaws.cn/en_us/AWSCloudFormation/latest/UserGuide/aws-properties-wafv2-webacl-ruleactionoverride.html

sbe-arg avatar Apr 23 '24 04:04 sbe-arg

Thanks for the post - we have another released planned for this solution in H2 of this year and I'll consider this during our next grooming session. Let me know if you're open for further discussion of other features that you'd like to see for this solution.

kroeter avatar Apr 24 '24 16:04 kroeter