-
Automated capactiy calculation via API - CheckCapacity
-
Algorithm to split Rules into RuleGroups
-
Automated update of RuleGroup if capacity changed
-
Add ManagedRuleGroups via configuration file
-
Automated generation of draw.io diagram for each WAF
-
Checking of the softlimit quota for WCU set in the AWS account (stop deployment if calculated WCU is above the quota)
-
Easy configuration of WAF rules trough Typescript file.
-
Deploy same WAF more than once for testing and/or blue/green deployments.
-
Stopping deployment if soft limit will be exceeded: Firewall Manager policies per organization per Region (L-0B28E140) - Maximum number of web ACL capacity units in a web ACL in WAF for regional (L-D9F31E8A)
-
You can name your rules. If you define a name in your RulesArray, the name + a Base36 timestamp will be used for the creation of your rule - otherwise a name will be generated. This will help you to query your logs in Athena.
-
Support for Captcha - You can add Captcha as an action to your WAFs. This helps you block unwanted bot traffic by requiring users to successfully complete challenges before their web request are allowed to reach AWS WAF protected resources. AWS WAF Captcha is available in the US East (N. Virginia), US West (Oregon), Europe (Frankfurt), South America (Sao Paulo), and Asia Pacific (Singapore) AWS Regions and supports Application Load Balancer, Amazon API Gateway, and AWS AppSync resources.
-
Added S3LoggingBucketName to Configuration. You need to specify the S3 Bucket where logs should be placed in. We also added a prefix for the logs to be AWS conform (Prefix: AWSLogs/AWS_ACCOUNTID/FirewallManager/AWS_REGION/).
-
Added testing your WAF with GoTestWAF. To be able to check your WAF we introduced the SecuredDomain parameter in the Configuration (which should be your domain) which will be checked using the WAF tool.
-
TaskFileParameters:
Parameter Value SKIP_QUOTA_CHECK true (Stop deployment if calculated WCU is above the quota)
false (Skipping WCU Check)WAF_TEST true (testing your waf with GoTestWAF)
false (Skipping WAF testing)CREATE_DIAGRAM true (generating a diagram using draw.io)
false (Skipping diagram generation)PREQUISITES true (deploys Prerequisites Stack)
false (deployment of WAF)TOOL_KIT_STACKNAME To Specify The name of the bootstrap stack (see Bootstrapping your AWS environment) -
Validation of your ConfigFile using schema validation - if you miss a required parameter in your config file the deployment will stop automatically and show you the missing path.
-
PreProcess- and PostProcessRuleGroups - you can decide now where the Custom or ManagedRules should be added to.
- New Structure see example Configuration.
-
RuleLabels - A label is a string made up of a prefix, optional namespaces and a name. The components of a label are delimited with a colon. Labels have the following requirements and characteristics:
-
Labels are case-sensitive.
-
Each label namespace or label name can have up to 128 characters.
-
You can specify up to five namespaces in a label.
-
Components of a label are separated by a colon ( : ).
-
-
While Deployment the Price for your WAF will be calculated using the Pricing API
-
Dashboard - The Firewall Factory is able to provision a CloudWatch Dashboard per Firewall. The Dashboard shows:
- Where the WAF is deployed to [AWS Region and Account(s)]
- Which resource type you are securing
- Which Managed Rule Groups in which version are in use
- Link to Managed Rule Groups documentation
- Direct Link to your secured Application / Endpoint
- AWS Firewall Factory version
- Check if the AWS Firewall Factory version is the latest or not during rollout
- Allowed / Blocked and Counted Requests
- Bot vs Non-bot Requests
-
Example Configurations
- Example WAF Configuration againts: OWASP Top Ten
- Example Configuration for Prerequisite Stack
- Function to generate Skeleton for WAF Configuration
-
Centralized IPSets management - No more we'll have to be manually updating ipsets across multiple AWS accounts, it can be defined in code and replicated for use by WAF rules everywhere its needed. Check the examples for defining ipsets and using them in the WebACLs on
values/examples/ip-sets-managed-test.ts
. -
Centralized management of RegexPatternSets - No longer will there be a need for manual updates of RegexPatternSets across multiple AWS accounts. These can now be defined in code and replicated for use by WAF rules wherever needed.
-
Automated identification and notification system in Firewall Factory to manage unused WAFs, leveraging Lambda and notification services to streamline infrastructure, optimize costs, and enhance security by addressing WAF sprawl proactively and ensuring efficient resource utilization.
-
Support Advanced Shield policy deployment through AWS Firewall Manager. AWS Shield Advanced provides customized detection based on traffic patterns to your protected resources, detects and alerts on smaller DDoS attacks, and identifies application layer attacks by baselining traffic and spotting anomalies.
-
Add Grafana Dashbording - The Firewall Factory is able to provision prequsistes and a Central Grafana Dashboard. The Dashboard shows:
-
Shield Cloudwatch Dashboard - The Firewall Factory is able to provision a centralized CloudWatch Dashboard. The Dashboard shows the ammount of DDoS attacks detected
-
Cloudwatch Cross-Account association - The Firewall Factory offers CloudFormation templates for associating the monitoring account with source accounts:
-
Add Cloudwatch Alarms - The prerequisite stack contains Cloudwatch Alarm resource that can be used to trigger the SNS topics incase of DDoS.