usageOfAction
Determines whether to use the AWSManagedRulesAntiDDoSRuleSet
rules ChallengeAllDuringEvent
and ChallengeDDoSRequests
in the rule group evaluation and the related label awswaf:managed:aws:anti-ddos:challengeable-request
.
If usage is enabled:
The managed rule group adds the label
awswaf:managed:aws:anti-ddos:challengeable-request
to any web request whose URL does NOT match the regular expressions provided in theClientSideAction
settingExemptUriRegularExpressions
.The two rules are evaluated against web requests for protected resources that are experiencing a DDoS attack. The two rules only apply their action to matching requests that have the label
awswaf:managed:aws:anti-ddos:challengeable-request
.If usage is disabled:
The managed rule group doesn't add the label
awswaf:managed:aws:anti-ddos:challengeable-request
to any web requests.The two rules are not evaluated.
None of the other
ClientSideAction
settings have any effect.
This setting only enables or disables the use of the two anti-DDOS rules ChallengeAllDuringEvent
and ChallengeDDoSRequests
in the anti-DDoS managed rule group.
This setting doesn't alter the action setting in the two rules. To override the actions used by the rules ChallengeAllDuringEvent
and ChallengeDDoSRequests
, enable this setting, and then override the rule actions in the usual way, in your managed rule group configuration.