AWS WAF托管规则动作覆盖自定义响应失效问题咨询
问题:AWS WAF托管规则动作覆盖配置自定义响应不生效的原因及解决方案
问题背景
尝试通过CloudFormation配置AWS WAF托管规则的RuleActionOverrides,将默认Block动作替换为带自定义纯文本响应的Block,但配置后仍返回WAF默认403页面,配置代码如下:
Resources: Waf: Type: AWS::WAFv2::WebACL Properties: Scope: CLOUDFRONT DefaultAction: Allow: {} # Allow for requests that don't match any rules CustomResponseBodies: SecurityViolationError: ContentType: TEXT_PLAIN Content: Request blocked due to security concerns as it was detected as malicious. Rules: - Priority: 0 Name: BlockSqlInjection OverrideAction: None: {} Statement: ManagedRuleGroupStatement: VendorName: AWS Name: AWSManagedRulesSQLiRuleSet Version: Version_2.0 RuleActionOverrides: - Name: SQLi_QUERYARGUMENTS ActionToUse: Block: CustomResponse: ResponseCode: 403 CustomResponseBodyKey: SecurityViolationError - Name: SQLi_BODY ActionToUse: Block: CustomResponse: ResponseCode: 403 CustomResponseBodyKey: SecurityViolationError - Name: SQLi_COOKIE ActionToUse: Block: CustomResponse: ResponseCode: 403 CustomResponseBodyKey: SecurityViolationError - Name: SQLiExtendedPatterns_QUERYARGUMENTS ActionToUse: Block: CustomResponse: ResponseCode: 403 CustomResponseBodyKey: SecurityViolationError - Name: SQLiExtendedPatterns_BODY ActionToUse: Block: CustomResponse: ResponseCode: 403 CustomResponseBodyKey: SecurityViolationError
已验证通过标签匹配的方式可以生效(需添加额外规则),但希望通过动作覆盖实现以避免额外成本。
核心结论
直接通过RuleActionOverrides为托管规则配置带自定义响应的Block动作目前AWS WAF不支持,这是配置无效的根本原因。
原因分析
- 功能限制:AWS WAF的
RuleActionOverrides仅支持修改动作类型(如将Block改为Count,或Count改为Block),不支持在动作中附加自定义响应、自定义状态码等扩展配置。 - 文档缺陷:CloudFormation官方文档的属性定义看起来允许该配置,但未明确标注这一功能限制,导致出现语法合法但功能不生效的情况。
当前可行方案(标签匹配法)
这是AWS WAF当前支持自定义响应的唯一合规路径,虽然会增加规则数量,但能实现需求,配置示例如下:
Resources: Waf: Type: AWS::WAFv2::WebACL Properties: Scope: CLOUDFRONT DefaultAction: Allow: {} # Allow for requests that don't match any rules CustomResponseBodies: SecurityViolationError: ContentType: TEXT_PLAIN Content: Request blocked due to security concerns as it was detected as malicious. Rules: - Priority: 0 Name: LabelSqlInjection OverrideAction: Count: {} Statement: ManagedRuleGroupStatement: VendorName: AWS Name: AWSManagedRulesSQLiRuleSet Version: Version_2.0 - Priority: 1 Name: BlockSecurityViolationError Statement: LabelMatchStatement: Scope: NAMESPACE Key: "awswaf:managed:aws:sql-database:" Action: Block: CustomResponse: ResponseCode: 403 CustomResponseBodyKey: SecurityViolationError
疑问解答
- 是否遗漏配置? 没有,你的配置完全符合文档语法,问题出在AWS WAF的功能限制上。
- 能否通过动作覆盖实现自定义响应? 目前不能,该功能未开放。
- 官方文档是否存在缺失? 是的,文档未明确说明
RuleActionOverrides不支持自定义响应配置,存在描述不清晰的问题。
内容的提问来源于stack exchange,提问作者Yves M.
相关产品推荐
相关产品推荐

