Back

About Custom Rules tab in WAF Config for AWS WAF v2

AWS WAF v2New PlanAdvancedFeature / Spec.

Overview

The Custom Rules tab in WAF Config is a feature to switch custom rules' actions on WafCharm Console if you have custom rules in your web ACL when using the Advanced rule policy. If you are using the Legacy rule policy, if you have not done customization before, or if you have deleted all custom rules, this tab will not be available.

For instructions on how to change the rule action for rules other than custom rules, such as regular expression rules, please refer to How to change rule actions for AWS WAF v2.

For details on customization, please refer to About rule customization (AWS WAF v2).

Displayable Custom Rules

Only the custom rules that meet the following conditions are shown in the Custom Rules tab.

  • Rate-based rules that are applied through customization.
    • Rate-based rules configured through the Rule Configuration tab in WAF Config are not included. Only rate-based rules that were individually applied as a customization upon request to WafCharm Support are shown here.
  • Custom rules that are applied in the position of "Custom rules", under the use case rule section.
    • Rules to detect specific conditions will be applied in the position of "Custom rules", under the use case rule section.
    • For more information about the use case rule section, please refer to About WafCharm rules for AWS WAF v2.
  • Custom rules that apply to special cases.
    • This applies to special rules that are not positioned in "Custom rules" under the use case rule section.

Please note that customization to exclude specific requests from WafCharm rules does not fall under any of the categories above. This customization excludes requests that match the condition from WafCharm's regular expression rules. If you would like to change the rule action of the regular expression rules themselves, please do so from the Rule Configuration tab by following the steps described in the How to change rule actions for AWS WAF v2.

About Each Section

Rate-based Custom Rules

This section contains settings for the following custom rules.

  • Rate-based rules that are applied through customization.
  • Custom rules that apply to special cases.

Custom Rules to Detect Specific Requests

This section contains settings for the following custom rules.

  • Custom rules that are applied in the position of "Custom rules", under the use case rule section.

About Configuration Items

Action

This item displays the current rule action of the custom rule. On the edit screen, you can select either "the intended action of the rule" or "Count" from the pull-down menu. For example, if a custom rule designed to block specific requests is applied, you can select between "Block" and "Count". For details on how to change an action, please also refer to How to change rule actions for AWS WAF v2 - Custom Rules.

Actions other than the intended action and Count are not available for selection. If you wish to change the intended action (e.g., from from Block to CAPTCHA), a separate customization request is required.

Created at

This item displays the date when the custom rule was applied.

Rule updated at

This item displays the date when the custom rule's condition was updated. This date is only updated when the conditions of the custom rule was updated through customization. This date will not be updated by changing the rule action from WafCharm Console.

Notes

This field allows you to add notes about the custom rule, if needed. To add a note, please enter your text in the input field on the edit screen and click the [Add] button. If you do not wish to add a note, you can leave the field blank.

You can enter up to 4,000 characters. Once the character limit is reached, any excess text will be automatically removed. If you paste content from another source, please check on the edit screen to ensure that the end of the text has not been truncated.

View Customized Rules

Click [View Customized Rules] to view the contents of the relevant custom rule in JSON format.

This is not linked to the Action field above, so the action shown in the JSON and the value displayed in the Action field above may differ. For the rule that is actually applied, the value specified in the Action field above is used.