AWS WAFv2如何通过OR语句引用多IPSet以节省规则成本?
Absolutely, your approach is totally feasible—and it’s a great way to keep your IP sets organized by use case (like home office, regular office, consultants) while avoiding extra monthly rule costs. Here’s how to get it right:
The Issue with Your Current Config
Your YAML is almost there, but you’re missing the explicit OrStatement wrapper around your list of Statements. WAFv2 requires you to specify the logical operator (in this case, OR) that ties your multiple IP set checks together. Without that wrapper, CloudFormation won’t recognize the structure correctly.
Fixed CloudFormation Configuration
Here’s the corrected version of your rule, which will match any request from IPs in any of your referenced IPSets:
Rules: - Name: WafIpRule Priority: 1 Action: Allow: {} VisibilityConfig: SampledRequestsEnabled: false CloudWatchMetricsEnabled: true MetricName: !Sub web${Environment}AllowWhitelistedIps Statement: OrStatement: Statements: - IPSetReferenceStatement: Arn: !GetAtt IpStuff1.Arn - IPSetReferenceStatement: Arn: !GetAtt IpStuff2.Arn # Add more IPSetReferenceStatement entries here for additional IP sets
How This Works
- The
OrStatementtells WAF to evaluate all the nestedStatementsand trigger theAllowaction if any of them match (i.e., the request IP is in IpStuff1 or IpStuff2 or any other IP set you add). - This counts as a single rule, so you’ll only pay the $1 monthly fee for this one rule—no extra costs for your separate IP sets.
- This aligns exactly with the console workflow you mentioned, where you can combine multiple IP sets under a single rule using OR logic.
Should You Merge IPSets Instead?
Merging your IPs into a single set would work, but it defeats the purpose of organizing them by use case. Keeping them separate makes it easier to update specific groups of IPs later (e.g., adding/removing consultant IPs without touching your office IPs) while still keeping your rule count (and costs) low.
Quick Checks to Ensure Success
- Verify that each IP set’s ARN is correct (use
!GetAttor hardcode the ARN if you’re referencing existing sets). - Make sure your WAF and IP sets are in the same AWS Region (for regional WAFs) or that the IP sets are configured for global use (for CloudFront WAFs).
- Confirm the rule’s
Priorityis set so this allow rule runs before any deny rules (you don’t want a deny rule blocking the request before this allow rule evaluates it).
内容的提问来源于stack exchange,提问作者Zanndorin

