Associating or disassociating protection with an AWS resource (original) (raw)

You can use AWS WAF to create the following associations between protection pack or web ACLs and your resources:

You can also associate a protection pack or web ACL with a CloudFront distribution when you create or update the distribution itself. For information, see Using AWS WAF to Control Access to Your Content in the Amazon CloudFront Developer Guide.

Restrictions on multiple associations

You can associate a single protection pack or web ACL with one or more AWS resources, according to the following restrictions:

Additional restrictions

The following additional restrictions apply to protection pack or web ACL associations:

Production traffic risk

Before you deploy your protection pack or web ACL for production traffic, test and tune it in a staging or testing environment until you are comfortable with the potential impact to your traffic. Then test and tune your rules in count mode with your production traffic before enabling them. For guidance, see Testing and tuning your AWS WAF protections.