Loading...
Loading...
Configures AWS WAF to filter web traffic: creating web access control lists (web ACLs) on CloudFront, Application Load Balancers, API Gateway, and AppSync; AWS Managed Rules tuned in Count mode; rate-based rules for HTTP floods; IP set and geographic match rules; Bot Control (Common and Targeted); turning bot labels into a confidence signal; stripping spoofed inbound x-amzn-waf-* headers; recovering the real client IP behind a CDN; Fraud Control (account takeover and account creation fraud prevention); and logging and request sampling. Use when the user wants to protect a web application or API from common exploits, bots, credential stuffing, fake-account creation, or HTTP floods at the application layer (layer 7). Routes to the right per-task procedure in references. Do NOT use for L3/L4 DDoS protection (shieldadvanced skill), multi-account WAF rollout (firewallmanager skill), CloudFront configuration (cloudfront skill), or Route 53 health checks or records (route53 skill).
npx skill4agent add aws/agent-toolkit-for-aws wafreferences/us-east-1CLOUDFRONTREGIONAL| Goal | Reference |
|---|---|
| Create a web ACL and attach it to a resource | creating a web ACL and associating it with a resource |
| Set up logging and sampling before tuning anything | setting up logging and request sampling |
| Add AWS Managed Rules and tune false positives | adding managed rules and tuning with count mode |
| Throttle HTTP floods and brute force | adding rate-based rules |
| Allow or block by IP range or country | using ip sets and geographic match rules |
| Detect and control bots (the on-ramp) | protecting against bots with bot control |
| Collapse bot labels into one confidence signal | turning bot control labels into a confidence signal |
| Forward all signals to the origin with one rule | forwarding signals with dynamic label interpolation |
| Decide what the app does with the forwarded signal | adaptive mitigation playbook for forwarded signals |
| Stop attackers from spoofing forwarded headers | stripping inbound waf headers before trusting them |
| Recover the real client IP behind a CDN | recovering the real client ip behind a cdn |
| Protect logins and signups from fraud | protecting logins and signups with fraud control |
| See and manage AI and LLM crawler traffic | seeing and managing ai crawler traffic |
CLOUDFRONTus-east-1REGIONALx-amzn-waf-*wafv2:wafv2:CreateWebACLwafv2:GetWebACLwafv2:UpdateWebACLwafv2:AssociateWebACLwafv2:PutLoggingConfigurationwafv2:*AWSWAFFullAccessaws sts assume-rolewafv2DeleteWebACLUpdateWebACLBlockedRequestsCountedRequestsAllowauthorizationcookiex-amzn-waf-*