Changing the action used for automatic application layer DDoS mitigation - AWS WAF, AWS Firewall Manager, and AWS Shield Advanced

Changing the action used for automatic application layer DDoS mitigation

You can change the action that Shield Advanced uses for its application layer automatic response in multiple locations in the console:

If you have two protected resources that share a web ACL, and you set the action to Count for one and Block for the other, Shield Advanced sets the action for the rule group's rate-based rule ShieldKnownOffenderIPRateBasedRule to Block.