Back

Differences between Advanced rule policy and Legacy rule policy

AWS WAF v2Old PlanNew PlanAdvancedLegacyFeature / Spec.

Overview

Advanced rule policy and Legacy rule policy have different rule structures and available features. This article explains the differences between each rule policy.

Comparison table

Features

Advanced rule policy

Legacy rule policy

Rule structures

Regular expressions (regex)

Rate-based rules (*)

Geo-match rules (*)

Bot rules (*)

*If configured in the WafCharm Console.

Regular expression (default) rules

Denylist feature

Dynamic denylist (signature re-matching) feature

Available by enabling WAF log integration (new method)

Available by enabling access log retrieval

Denylist feature

IP reputation feature

Available

Available

Denylist feature

Manual denylist feature

Available by adding IP addresses from the rule configuration page

Available by adding IP addresses from the rule configuration page

Allowlist feature

Manual allowlist feature

Available by adding IP addresses from the rule configuration page

Available by adding IP addresses from the rule configuration page

Rule configuration

IP address: Allowlist, Denylist

Configuration is available from registration/edit pages

Configuration is available from registration/edit pages

Rule configuration

IP address: IP address to use

*This setting determines whether IP addresses in a specific header should be inspected.

Configuration is available from registration/edit pages

Configuration is available from registration/edit pages

Rule configuration

IP address: Change the rule action of Dynamic denylist rule (*)

*This rule contains the Dynamic denylist (signature re-matching) feature and IP reputation feature.

Configuration is available from registration/edit pages

Configuration is not available from registration/edit pages

Rule configuration

Rate-based rules

Configuration is available from registration/edit pages

Configuration is not available from registration/edit pages

Rule configuration

Geo-match rules

Configuration is available from registration/edit pages

Configuration is not available from registration/edit pages

Rule configuration

Bot rules

Configuration is available from registration/edit pages

Configuration is not available from registration/edit pages

Rule configuration

正規表現

Configuration is available from registration/edit pages

Configuration is not available from registration/edit pages

Access log retrieval

Not Applicable

Required

*Except for API Gateway.

WAF log retrieval (new method)

Available if the WAF log destination is set to the S3 bucket

Available if the WAF log destination is set to the S3 bucket or Data Firehose

WAF log transfer (old method)

Not Applicable

Available if the WAF log destination is set to the S3 bucket or Data Firehose

Monthly report

Available by enabling WAF log integration (new method)

Available by enabling WAF log integration (new or old method)

WAF log alert config

Available by enabling WAF log integration (new method)

Available by enabling WAF log integration (new or old method)

WAF log search

Available by enabling WAF log integration (new method)

Available by enabling WAF log integration (new method)

Detection status (dashboard feature)

Available by enabling WAF log integration (new method)

Available by enabling WAF log integration (new method)

Log Intelligence Option

Available (Paid) by enabling WAF log integration (new method)

Not applicable

The WAF Log Storage Format (WAF log retention period)

Eligible when WAF log integration (new method) is enabled and Expanded Mode is used (Paid)

Eligible on the new plan when WAF log integration (new method) is enabled and Expanded Mode is used (Paid)

Note: The old plan is not eligible.

Notes

  • Advanced rule policy can only be used with new plan/MP ver.
    • If you are currently using the old plan, you must be migrated to the new plan or MP ver. before using the Advanced rule policy. If you would like to migrate to the new plan, please contact the WafCharm support team.
    • WafCharm accounts that have WAF Config for AWS WAF Classic registered cannot migrate to the new plan. Please update to AWS WAF v2 before migrating to the new plan.
  • You cannot register multiple WAF Configs with the same web ACL ID on the WafCharm Console.
  • [IP address to use (Specific header)] is an option to select when you want to inspect IP addresses in a specific header. If you choose to use the Specific header option, the following differences apply.
    • For Advanced rule policy: The IP addresses in the specified header will be used in the dynamic denylist (signature re-matching) feature.
    • For Legacy rule policy: The dynamic denylist (signature re-matching) feature will be disabled.
    • For more details, please see the About the [IP address to use] option for AWS WAF v2 page.
  • If both WAF log transfer (old method) and WAF log retrieval (new method) are enabled on a WAF Config with Legacy rule policy, both WAF log alert features will also be enabled. It is recommended that only one method be enabled to avoid receiving duplicate detection notification emails.
  • Due to the structure update, the number of rules applied in the Advanced rule policy is different from that in the Legacy rule policy. In the Advanced rule policy, 49 regular expression rules (default rules responding to common web attacks) are applied.
    • The AWS WAF pricing may change if the number of rules is different. For more information, please refer to the AWS WAF Pricing page.
  • The Log Intelligence Option is available only when your WafCharm account is subscribed to the Log Intelligence Option and you are using the Advanced Rule policy.
  • The WAF Log Storage Format (WAF log retention period) is available only when you are on the new plan and have enabled WAF log integration (new method) using AWS WAF v2. It is not available on the old plan or the Trial Plan. For more information, see About WAF Log Retention Period.