AWS WAFv2 IP速率限制规则异常:首次请求未触发拦截
问题分析与解决方案
核心问题定位
你的AWS WAFv2速率限制规则未按预期拦截请求,主要有两个关键原因:
规则动作配置错误
你当前的规则动作使用了count {},该动作仅会统计符合条件的请求数量,不会阻止任何请求。这就是首次调用300次仍全部成功的根本原因。第二次调用返回403,大概率是首次调用的计数累积触发了WAF的速率阈值,但由于动作是count,首次请求不会被拦截,第二次请求时WAF的统计窗口已累积到阈值,可能你后续调整了配置,或者WAF的延迟统计导致了这个现象。异步请求的统计延迟
Postman代码中使用异步方式发送请求,300次请求几乎同时到达WAF,可能导致WAF的1分钟滑动窗口计数未及时累积到阈值,进一步影响拦截触发的时机。
修正方案
1. 修改WAF规则动作为拦截
将Terraform配置中的action { count {} }替换为action { block {} },这样当请求超过速率阈值时,WAF会直接返回403阻止请求:
resource "aws_wafv2_web_acl" "x-account-acl" { name = local.name description = "rate based statement." scope = "REGIONAL" default_action { allow {} } rule { name = "rule-1" priority = 1 # 替换count为block,触发拦截 action { block {} } statement { rate_based_statement { aggregate_key_type = "IP" limit = 100 scope_down_statement { regex_pattern_set_reference_statement { arn = aws_wafv2_regex_pattern_set.url_pattern.arn field_to_match { uri_path {} } text_transformation { priority = 1 type = "NONE" } } } } } visibility_config { cloudwatch_metrics_enabled = false metric_name = "friendly-rule-metric-name" sampled_requests_enabled = false } } visibility_config { cloudwatch_metrics_enabled = false metric_name = "friendly-metric-name" sampled_requests_enabled = false } }
2. 调整Postman请求为同步发送
异步请求会导致大量请求同时到达,WAF的滑动窗口计数可能无法及时响应。改为同步发送请求,确保请求按顺序执行,更容易触发速率限制:
const postRequest = { url: pm.environment.get("URL") + '/connect/token', method: 'POST', header: { 'Content-Type': 'application/x-www-form-urlencoded', }, body: { mode: 'urlencoded', urlencoded: [ {key: "client_id",value: pm.environment.get("Client_Id_userApi")}, {key: "grant_type",value: "client_credentials"}, {key: "client_secret",value: pm.environment.get("Client_Secret_userApi")}, ] } }; // 同步发送请求,确保计数准确累积 async function sendRequests() { for (let i = 0; i < 300; i++) { try { const response = await pm.sendRequest(postRequest); console.log(`请求 ${i+1} 状态码: ${response.code}`); } catch (error) { console.log(`请求 ${i+1} 错误:`, error); } } } sendRequests();
补充说明
AWS WAFv2的速率限制基于1分钟滑动窗口统计请求数,当同一IP在窗口内的请求超过100次时,后续请求会被拦截返回403。修改配置后,重新部署WAF并测试,即可看到第101次请求开始被拦截。
内容的提问来源于stack exchange,提问作者Dilu
相关产品推荐
相关产品推荐

