Restricting access to CloudFront by IP

后端 未结 2 1140
情话喂你
情话喂你 2020-12-30 22:11

I want to restrict bucket access to certain IPs. I know how to create a bucket policy from Restricting Access to Specific IP Addresses.

My question: Can this work wi

相关标签:
2条回答
  • 2020-12-30 22:18

    Web Application Firewall is your friend.

    http://docs.aws.amazon.com/waf/latest/developerguide/web-acl-ip-conditions.html

    Create your rule with your IP Addresses and rest "WAF" will take care.

    You need to apply this to the required CloudFront Distribution.

    You can restrict your bucket policies to CloudFront and restrict to your required IP's through CloudFront.

    0 讨论(0)
  • 2020-12-30 22:35

    I have created the custom rule to whitelist IPs and restrict the application with CloudFront distribution with following steps.

    Steps:

    1. Go to AWS WAF.
    2. Create following IP match conditions under IP Addresses.

      1. staging-appname-whitelist-ips
    3. Create following rules under Rules.

      1. staging-appname-ui-stack-whitelisted-ips
        • with condition (similar for production one)
    4. Finally create following Web ACLs:
      1. staging-appname-acl
        • Please select the correct CloudFront Distribution, above created Rule and IP Address group. *.

    AWS Resource here.

    Hope it helps!

    0 讨论(0)
提交回复
热议问题