Deleting a WAF exclusion rule
- In the management console
, select the folder containing the WAF profile. - Navigate
to Smart Web Security. - In the left-hand panel, select WAF profiles.
- Select the profile where you want to delete an exclusion rule.
- Navigate to the Exclusion rules tab.
- Click
→ Delete next to the rule. - Confirm the deletion.
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
-
Open the Terraform configuration file and delete the
exclusion_rulesection defining your WAF exclusion rule from theyandex_sws_waf_profiledescription.Example of configuring WAF profile exclusion rules in your Terraform configuration
# Declaring local variables locals { # In the basic set, rules of this paranoia level and below will be enabled waf_paranoia_level = 1 # OWASP Core Ruleset identification ruleset_name = "OWASP Core Ruleset" ruleset_version = "4.0.0" ruleset_id = "OWASP_CRS_4_0_0" ruleset_type = "CORE" } # OWASP Core Rule Set data source data "yandex_sws_waf_rule_set_descriptor" "source" { name = local.ruleset_name version = local.ruleset_version } # WAF profile resource "yandex_sws_waf_profile" "default" { name = "configure-set-rules" # Basic rule set rule_set { action = "CAPTCHA" is_enabled = true priority = 1 core_rule_set { inbound_anomaly_score = 2 paranoia_level = local.waf_paranoia_level rule_set { name = local.ruleset_name version = local.ruleset_version id = local.ruleset_id type = local.ruleset_type } } } # Exclusion rule exclusion_rule { name = "test-exclusion-1" condition { source_ip { ip_ranges_match { ip_ranges = [ "192.0.2.0/24", "198.51.100.0/24" ] } ip_ranges_not_match { ip_ranges = [ "203.0.113.10/32", "203.0.113.0/24" ] } } } exclude_rules { exclude_all = false rule_ids = [ "owasp-crs-v4.8.0-id942330-attack-sqli", "owasp-crs-v4.8.0-id920202-protocol-enforcement" ] } } }For more on the properties of the
yandex_sws_waf_profileresource, see this provider guide. -
Apply the changes:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
-
You can check the deletion of the resources in the management console
Use the update REST API method for the WafProfile resource or the WafProfile/Update gRPC API call.