AWS::WAFv2::WebACL RateBasedStatementOne - AWS CloudFormation

AWS::WAFv2::WebACL RateBasedStatementOne

A rate-based rule tracks the rate of requests for each originating IP address, and triggers the rule action when the rate exceeds a limit that you specify on the number of requests in any 5-minute time span. You can use this to put a temporary block on requests from an IP address that's sending excessive requests.

When the rule action triggers, AWS WAF blocks additional requests from the IP address until the request rate falls below the limit.

You can optionally nest another statement inside the rate-based statement, to narrow the scope of the rule so that it only counts requests that match the nested statement. You can't nest a RateBasedStatement, for example for use inside a NotStatement or OrStatement. It can only be referenced as a top-level statement within a rule.

Syntax

To declare this entity in your AWS CloudFormation template, use the following syntax:

JSON

{ "AggregateKeyType" : String, "Limit" : Integer, "ScopeDownStatement" : StatementTwo }

Properties

AggregateKeyType

Setting that indicates how to aggregate the request counts. Currently, you must set this to IP. The request counts are aggregated on IP addresses.

Required: Yes

Type: String

Update requires: No interruption

Limit

Limit on the web request that match any nested statement criteria in any 5 minute period.

Required: Yes

Type: Integer

Update requires: No interruption

ScopeDownStatement

Statement nested inside a rate-based statement to narrow the scope of the requests that AWS WAF counts.

Required: No

Type: StatementTwo

Update requires: No interruption