如何在AWS CDK WAF中禁用NonBrowserUserAgent规则?
解决AWS CDK默认WAF规则拦截非浏览器客户端请求的问题
问题描述
使用AWS CDK的WafwebaclToApiGateway构造配置WAF时,默认集成的AWS托管规则集中包含SignalNonBrowserUserAgent规则,该规则会拦截所有带有非浏览器标识的请求,导致应用、Postman、Python Requests等非浏览器客户端无法正常调用API接口,排查耗时数日才解决,现将配置及解决方案记录如下。
初始WAF配置代码
from aws_solutions_constructs.aws_wafwebacl_apigateway import WafwebaclToApiGateway my_waf = WafwebaclToApiGateway(scope, waf_id, existing_api_gateway_interface=gateway)
解决方案
方案1:排除默认规则集中的SignalNonBrowserUserAgent规则
通过构造参数指定webacl_props,覆盖默认托管规则集配置,排除目标规则,保留其他安全防护逻辑:
from aws_solutions_constructs.aws_wafwebacl_apigateway import WafwebaclToApiGateway from aws_cdk import aws_wafv2 as wafv2 my_waf = WafwebaclToApiGateway( scope, waf_id, existing_api_gateway_interface=gateway, webacl_props={ "rules": [ wafv2.CfnWebACL.RuleProperty( name="AWSManagedRulesCommonRuleSet", priority=0, statement=wafv2.CfnWebACL.StatementProperty( managed_rule_group_statement=wafv2.CfnWebACL.ManagedRuleGroupStatementProperty( name="AWSManagedRulesCommonRuleSet", vendor_name="AWS", # 排除拦截非浏览器请求的规则 excluded_rules=[ wafv2.CfnWebACL.ExcludedRuleProperty(name="SignalNonBrowserUserAgent") ] ) ), override_action=wafv2.CfnWebACL.OverrideActionProperty(none={}), visibility_config=wafv2.CfnWebACL.VisibilityConfigProperty( cloud_watch_metrics_enabled=True, metric_name="AWSManagedRulesCommonRuleSet", sampled_requests_enabled=True ) ) ] } )
方案2:自定义规则允许特定非浏览器User-Agent
若需兼顾安全与业务需求,可添加优先级更高的允许规则,仅放行指定的合法非浏览器客户端请求:
from aws_solutions_constructs.aws_wafwebacl_apigateway import WafwebaclToApiGateway from aws_cdk import aws_wafv2 as wafv2 my_waf = WafwebaclToApiGateway( scope, waf_id, existing_api_gateway_interface=gateway, webacl_props={ "rules": [ # 优先级1:放行指定的非浏览器客户端 wafv2.CfnWebACL.RuleProperty( name="AllowApprovedNonBrowserAgents", priority=1, statement=wafv2.CfnWebACL.StatementProperty( or_statement=wafv2.CfnWebACL.OrStatementProperty( statements=[ # 允许Postman请求 wafv2.CfnWebACL.StatementProperty( byte_match_statement=wafv2.CfnWebACL.ByteMatchStatementProperty( field_to_match=wafv2.CfnWebACL.FieldToMatchProperty( single_header={"Name": "User-Agent"} ), positional_constraint="CONTAINS", search_string="PostmanRuntime", text_transformations=[ wafv2.CfnWebACL.TextTransformationProperty( priority=0, type="LOWERCASE" ) ] ) ), # 允许Python Requests请求 wafv2.CfnWebACL.StatementProperty( byte_match_statement=wafv2.CfnWebACL.ByteMatchStatementProperty( field_to_match=wafv2.CfnWebACL.FieldToMatchProperty( single_header={"Name": "User-Agent"} ), positional_constraint="CONTAINS", search_string="python-requests", text_transformations=[ wafv2.CfnWebACL.TextTransformationProperty( priority=0, type="LOWERCASE" ) ] ) ) ] ) ), action=wafv2.CfnWebACL.RuleActionProperty(allow={}), visibility_config=wafv2.CfnWebACL.VisibilityConfigProperty( cloud_watch_metrics_enabled=True, metric_name="AllowApprovedNonBrowserAgents", sampled_requests_enabled=True ) ), # 优先级2:保留默认安全规则集 wafv2.CfnWebACL.RuleProperty( name="AWSManagedRulesCommonRuleSet", priority=2, statement=wafv2.CfnWebACL.StatementProperty( managed_rule_group_statement=wafv2.CfnWebACL.ManagedRuleGroupStatementProperty( name="AWSManagedRulesCommonRuleSet", vendor_name="AWS" ) ), override_action=wafv2.CfnWebACL.OverrideActionProperty(none={}), visibility_config=wafv2.CfnWebACL.VisibilityConfigProperty( cloud_watch_metrics_enabled=True, metric_name="AWSManagedRulesCommonRuleSet", sampled_requests_enabled=True ) ) ] } )
说明
- 方案1适合需要完全放行所有非浏览器客户端请求的场景;
- 方案2更安全,仅放行指定合法客户端,平衡业务需求与安全防护。
内容的提问来源于stack exchange,提问作者RooterTooter
相关产品推荐
相关产品推荐

