You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS WAFv2如何通过OR语句引用多IPSet以节省规则成本?

Can I Use Multiple IPSets in a Single WAFv2 Rule via CloudFormation?

Absolutely, your approach is totally feasible—and it’s a great way to keep your IP sets organized by use case (like home office, regular office, consultants) while avoiding extra monthly rule costs. Here’s how to get it right:

The Issue with Your Current Config

Your YAML is almost there, but you’re missing the explicit OrStatement wrapper around your list of Statements. WAFv2 requires you to specify the logical operator (in this case, OR) that ties your multiple IP set checks together. Without that wrapper, CloudFormation won’t recognize the structure correctly.

Fixed CloudFormation Configuration

Here’s the corrected version of your rule, which will match any request from IPs in any of your referenced IPSets:

Rules:
  - Name: WafIpRule
    Priority: 1
    Action:
      Allow: {}
    VisibilityConfig:
      SampledRequestsEnabled: false
      CloudWatchMetricsEnabled: true
      MetricName: !Sub web${Environment}AllowWhitelistedIps
    Statement:
      OrStatement:
        Statements:
          - IPSetReferenceStatement:
              Arn: !GetAtt IpStuff1.Arn
          - IPSetReferenceStatement:
              Arn: !GetAtt IpStuff2.Arn
          # Add more IPSetReferenceStatement entries here for additional IP sets

How This Works

  • The OrStatement tells WAF to evaluate all the nested Statements and trigger the Allow action if any of them match (i.e., the request IP is in IpStuff1 or IpStuff2 or any other IP set you add).
  • This counts as a single rule, so you’ll only pay the $1 monthly fee for this one rule—no extra costs for your separate IP sets.
  • This aligns exactly with the console workflow you mentioned, where you can combine multiple IP sets under a single rule using OR logic.

Should You Merge IPSets Instead?

Merging your IPs into a single set would work, but it defeats the purpose of organizing them by use case. Keeping them separate makes it easier to update specific groups of IPs later (e.g., adding/removing consultant IPs without touching your office IPs) while still keeping your rule count (and costs) low.

Quick Checks to Ensure Success

  • Verify that each IP set’s ARN is correct (use !GetAtt or hardcode the ARN if you’re referencing existing sets).
  • Make sure your WAF and IP sets are in the same AWS Region (for regional WAFs) or that the IP sets are configured for global use (for CloudFront WAFs).
  • Confirm the rule’s Priority is set so this allow rule runs before any deny rules (you don’t want a deny rule blocking the request before this allow rule evaluates it).

内容的提问来源于stack exchange,提问作者Zanndorin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.07 08:52:54