An AWS WAF IP Set is a reusable collection of IP addresses and ranges that you can use to define rules in AWS Web Application Firewall. It allows you to allow, block, or count web requests based on the originating IP addresses. By centralizing IP addresses in an IP Set, you can easily manage and update them without modifying individual rules. This helps simplify security management and ensures consistent protection across multiple web applications and resources.

aws.wafv2_ip_set

Fields

TitleIDTypeData TypeDescription
_keycorestring
account_idcorestring
addressescorearray<string>Contains an array of strings that specifies zero or more IP addresses or blocks of IP addresses that you want WAF to inspect for in incoming requests. All addresses must be specified using Classless Inter-Domain Routing (CIDR) notation. WAF supports all IPv4 and IPv6 CIDR ranges except for /0. Example address strings: For requests that originated from the IP address 192.0.2.44, specify 192.0.2.44/32. For requests that originated from IP addresses from 192.0.2.0 to 192.0.2.255, specify 192.0.2.0/24. For requests that originated from the IP address 1111:0000:0000:0000:0000:0000:0000:0111, specify 1111:0000:0000:0000:0000:0000:0000:0111/128. For requests that originated from IP addresses 1111:0000:0000:0000:0000:0000:0000:0000 to 1111:0000:0000:0000:ffff:ffff:ffff:ffff, specify 1111:0000:0000:0000:0000:0000:0000:0000/64. For more information about CIDR notation, see the Wikipedia entry Classless Inter-Domain Routing. Example JSON Addresses specifications: Empty array: "Addresses": [] Array with one address: "Addresses": ["192.0.2.44/32"] Array with three addresses: "Addresses": ["192.0.2.44/32", "192.0.2.0/24", "192.0.0.0/16"] INVALID specification: "Addresses": [""] INVALID
arncorestringThe Amazon Resource Name (ARN) of the entity.
descriptioncorestringA description of the IP set that helps with identification.
idcorestringA unique identifier for the set. This ID is returned in the responses to create and list commands. You provide it to operations like update and delete.
ip_address_versioncorestringThe version of the IP addresses, either IPV4 or IPV6.
lock_tokencorestringA token used for optimistic locking. WAF returns a token to your <code>get</code> and <code>list</code> requests, to mark the state of the entity at the time of the request. To make changes to the entity associated with the token, you provide the token to operations like <code>update</code> and <code>delete</code>. WAF uses the token to ensure that no changes have been made to the entity since you last retrieved it. If a change has been made, the update fails with a <code>WAFOptimisticLockException</code>. If this happens, perform another <code>get</code>, and use the new token returned by that operation.
namecorestringThe name of the IP set. You cannot change the name of an IPSet after you create it.
tagscorehstore