Release 602 - #940
Merged
Merged
Release 602#940
Conversation
…lvable country (SYNSD-2758) The geo-restriction rule ORs two GeoMatchStatements: one against the request's raw source IP, one against the IP in X-Forwarded-For with FallbackBehavior set to MATCH. When that header contains an address AWS WAF can't geolocate (e.g. a private/reserved-range IP inserted by an intermediate proxy), MATCH treats the unresolvable header as if it matched a restricted country and blocks the request, even though the raw source IP resolves to an unrestricted country. Switching this statement's FallbackBehavior to NO_MATCH removes that false positive without weakening the restriction: the source-IP-based statement is independent and still blocks any request whose actual origin geolocates to a restricted country.
… geo-restriction rule (SYNSD-2758) The prior fix set the forwarded-IP GeoMatchStatement's FallbackBehavior to NO_MATCH, which let ANY unresolvable X-Forwarded-For value bypass that statement, not just the private-IP-behind-a-corporate-proxy case from this ticket. Revert FallbackBehavior to MATCH and instead wrap it in an AndStatement with NOT(IPSetReferenceStatement against a new RFC1918 IPSet), so only forwarded IPs we can positively confirm are private get excused. Everything else unresolvable is still blocked, same as before this ticket. The IPSetReferenceStatement checks X-Forwarded-For (via IPSetForwardedIPConfig) rather than the raw connection IP, since that's where the private address actually appears; its own FallbackBehavior is NO_MATCH so an unparseable header is never assumed private. The raw-source-IP GeoMatchStatement is untouched and remains the backstop against genuine restricted-country traffic regardless of header manipulation.
…ed-IP check (SYNSD-2758) AWS WAF can't geolocate 127.0.0.0/8 (RFC1122 3.2.1.3) any more than it can geolocate RFC1918 private space, so add it to the IPSet the geo-restriction rule's NOT(IPSetReferenceStatement) checks against. No production traffic has been observed hitting this yet, but it's the same class of non-geolocatable address as the RFC1918 case this ticket was opened for, so exclude it preemptively. Renamed the IPSet resource from *Rfc1918PrivateIpSet* to *NonRoutableIpSet* since it now covers more than RFC1918.
…SYNSD-2758) GeoMatchStatement only ever geolocates the first XFF value, so ANY let a trailing forged/private value cancel a block on a genuine first-hop match from a blocked country. Prod WAF logs show no legitimate multi-hop chain carrying a real geolocatable IP past position 1, so FIRST closes that gap with no observed cost.
…allback-behavior-602 SYNSD-2758: Only excuse forwarded IPs confirmed RFC1918-private from the geo-restriction rule
R602 port plfm 9897
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Not sure why it's showing diffs, all these should already be in dev...