AWS::FMS::Policy
-
Firewall Manager
-
Centrally manage EC2
Security Groups(firewall rules) and AWSShield Advancedacross allAWS accountsin your AWSOrganization: - AWS WAF rules
- AWS Shield Advanced protection
- Security groups
- AWS Network Firewall rules
- Amazon Route 53 Resolver DNS Firewall rules.
Properties
Type: AWS::FMS::Policy
Properties:
DeleteAllPolicyResources: Boolean
ExcludeMap:
IEMap
ExcludeResourceTags: Boolean
IncludeMap:
IEMap
PolicyDescription: String
PolicyName: String
RemediationEnabled: Boolean
ResourcesCleanUp: Boolean
ResourceSetIds:
- String
ResourceTags:
- ResourceTag
ResourceType: String
ResourceTypeList:
- String
SecurityServicePolicyData:
SecurityServicePolicyData
Tags:
- PolicyTag
SecurityServicePolicyData
WAFV2
- Web Application Firewall
- Protect
webappsfrom common exploits (Layer 7) SQL injectionCross-Site Scripting(XSS)- Can be deployed on:
ALBAPI GatewayCloudFront- Web ACL (Access Control List)
- Rules
- IP addresses
- HTTP headers
- HTTP body
- URI strings
- Size constraints, geo-match, etc
SHIELD_ADVANCED
-
Protect against DDoS (
Distributed Denial of Service) attacks -
Tiers
Standard- Free
- Activated by default
Advanced- Optional DDoS
mitigationservice - DDoS
response team24/7 - Reimburse over high fees due to the attack
- Protect against more sophisticated attacks
- Optional DDoS
