A Config rule that checks if Web Application Firewall (WAF) is enabled on Application Load Balancers (ALBs). This rule is NON_COMPLIANT if key: waf.enabled is set to false.

This config rule supports the following parameters:

  • wafWebAclIds
    • Required: No
    • Type: CSV
    • Description:Comma separated list of web ACL ID (for WAF) or web ACL ARN (for WAFV2) checking for ALB association.

ConfigRule
AWS::Config::ConfigRule


Scope

ComplianceResourceTypes

Source *
CustomPolicyDetails
SourceDetails

CloudFormation Template

Share Template