How to Configure AWS Shield Advanced and AWS WAF Rate-Based Rules
Retrospective: this article looks back at events from December 2016, written in 2026 with the benefit of hindsight.
AWS Shield Standard protects every AWS account against common network-layer DDoS attacks automatically. Application-layer attacks need more work. Here is how to set up Shield Advanced and AWS WAF rate-based rules for an internet-facing application.
Before you start
- Put your public endpoints behind Amazon CloudFront, an Application Load Balancer or API Gateway. WAF attaches to these, not to individual EC2 instances.
- Decide whether Shield Advanced is worth it (see our CIO brief on Standard vs Advanced). It carries a monthly subscription with an annual commitment, so reserve it for revenue-critical applications.
Step 1: Create a web ACL with rate-based rules
- In the AWS WAF console, create a web ACL and associate it with your CloudFront distribution or load balancer.
- Add the AWS Managed Rules baseline rule groups (core rule set and known bad inputs).
- Add a rate-based rule that blocks a single IP address exceeding a request threshold over a rolling window. Start in Count mode.
- Add tighter rate-based rules scoped to sensitive paths such as
/loginor/api/.
Step 2: Tune before you block
Run in Count mode for one to two weeks. Review WAF logs to see what would have been blocked, adjust thresholds above your legitimate peak, then switch to Block.
Step 3: Subscribe to Shield Advanced (if justified)
- Subscribe in the AWS Shield console and add protected resources.
- Configure proactive engagement and emergency contacts so the AWS response team can reach you during an event.
- Enable automatic application-layer DDoS mitigation where available.
Step 4: Alerting
Create CloudWatch alarms on WAF blocked requests and Shield DDoS-detected metrics, and route them to the people who can act.
Common mistakes
- Leaving the origin reachable directly, bypassing CloudFront and WAF. Restrict the origin to CloudFront traffic only.
- Rate limits set below legitimate peaks, such as a marketing campaign or month-end batch traffic.