You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS WAFv2 IP速率限制规则异常:首次请求未触发拦截

问题分析与解决方案

核心问题定位

你的AWS WAFv2速率限制规则未按预期拦截请求,主要有两个关键原因:

  1. 规则动作配置错误
    你当前的规则动作使用了count {},该动作仅会统计符合条件的请求数量,不会阻止任何请求。这就是首次调用300次仍全部成功的根本原因。第二次调用返回403,大概率是首次调用的计数累积触发了WAF的速率阈值,但由于动作是count,首次请求不会被拦截,第二次请求时WAF的统计窗口已累积到阈值,可能你后续调整了配置,或者WAF的延迟统计导致了这个现象。

  2. 异步请求的统计延迟
    Postman代码中使用异步方式发送请求,300次请求几乎同时到达WAF,可能导致WAF的1分钟滑动窗口计数未及时累积到阈值,进一步影响拦截触发的时机。

修正方案

1. 修改WAF规则动作为拦截

将Terraform配置中的action { count {} }替换为action { block {} },这样当请求超过速率阈值时,WAF会直接返回403阻止请求:

resource "aws_wafv2_web_acl" "x-account-acl" {
  name        = local.name
  description = "rate based statement."
  scope       = "REGIONAL"

  default_action {
    allow {}
  }

  rule {
    name     = "rule-1"
    priority = 1

    # 替换count为block,触发拦截
    action {
      block {}
    }

    statement {
      rate_based_statement {
        aggregate_key_type = "IP"
        limit              = 100

        scope_down_statement {
          regex_pattern_set_reference_statement {
            arn = aws_wafv2_regex_pattern_set.url_pattern.arn

            field_to_match {
              uri_path {}
            }

            text_transformation {
              priority = 1
              type     = "NONE"
            }
          }
        }
      }
    }

    visibility_config {
      cloudwatch_metrics_enabled = false
      metric_name                = "friendly-rule-metric-name"
      sampled_requests_enabled   = false
    }
  }

  visibility_config {
    cloudwatch_metrics_enabled = false
    metric_name                = "friendly-metric-name"
    sampled_requests_enabled   = false
  }
}

2. 调整Postman请求为同步发送

异步请求会导致大量请求同时到达,WAF的滑动窗口计数可能无法及时响应。改为同步发送请求,确保请求按顺序执行,更容易触发速率限制:

const postRequest = {
  url: pm.environment.get("URL") + '/connect/token',
  method: 'POST',
  header: {
    'Content-Type': 'application/x-www-form-urlencoded',
  },
  body: {
    mode: 'urlencoded',
    urlencoded:
    [
        {key: "client_id",value: pm.environment.get("Client_Id_userApi")},
        {key: "grant_type",value: "client_credentials"},
        {key: "client_secret",value: pm.environment.get("Client_Secret_userApi")},
    ]
  }
};

// 同步发送请求,确保计数准确累积
async function sendRequests() {
  for (let i = 0; i < 300; i++) {
    try {
      const response = await pm.sendRequest(postRequest);
      console.log(`请求 ${i+1} 状态码: ${response.code}`);
    } catch (error) {
      console.log(`请求 ${i+1} 错误:`, error);
    }
  }
}

sendRequests();

补充说明

AWS WAFv2的速率限制基于1分钟滑动窗口统计请求数,当同一IP在窗口内的请求超过100次时,后续请求会被拦截返回403。修改配置后,重新部署WAF并测试,即可看到第101次请求开始被拦截。

内容的提问来源于stack exchange,提问作者Dilu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.04 15:07:44