> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Block and Unblock access to CloudFront distribution using AWS WAF

> Hands-on lab · 30m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Project Details

1. This project walks you through how to block traffic using Web ACL and Rules using WAF and CloudFront
2. Duration: **90 minutes**
3. AWS Region: **US East (N. Virginia) us-east-1**

### Introduction

#### WAF (web application firewall)

1. AWS WAF is a web application firewall that helps you to protect your web applications against common web exploits that might affect availability and compromise security.
2. AWS WAF gives you control over how traffic reaches your applications by enabling you to create security rules that block common attack patterns like SQL injection and cross-site scripting.
3. It only allows the request to reach the server based on the rules or patterns you define.
4. Users create their own rules and specify the conditions that AWS WAF searches for in incoming web requests.
5. The cost of WAF is only for what you use.
6. The pricing is based on how many rules you deploy and how many web requests your application receives.
7. For example, you can deploy AWS WAF on Amazon Cloud Front with an Application Load Balancer in front of your web servers or servers running on EC2.

#### Features of WAF

* **Web traffic filtering using custom rules:** You can create your own rules, depending on your requirements, whether to block or allow the incoming and outgoing request. You can also customize the string that appears in your web request.
* **Blocking malicious requests:** You can also configure rules in AWS WAF to identify and block web request threats like SQL injections and cross-site scripting.
* **Tune your rules and monitor traffic:** AWS WAF also allows us to review our rules and customize them to prevent new attacks from reaching the server.

### Architecture diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/001.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=19f659a716012bf08c97e0980402c248" alt="" width="1040" height="570" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/001.png" />

### Project Details

1. Sign in to AWS Management Console
2. Copy the S3 Object URL of the Sample template to create CloudFormation stack
3. Create a CloudFormation stack using a template present in an S3 Bucket
4. Create the WAF Web ACL and Rules
5. SSH into EC2 Instance using Session Manager and run the scripts
6. Delete the IP address and test the working of CloudFront
7. Validation of the Lab
8. Deleting AWS Resources

### Launching Project Environment

1. To launch the project environment, Click on the **Launch lab** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the Project is started, you will be provided with **IAM user name**, **Password**, **Access** **Key**, and **Secret** **Access** **Key**.

<Note>
  You can only start one project at any given time
</Note>

## Lab guide

### Project Steps

#### Task 1: Sign in to AWS Management Console

1. Click on the **Open console** button, and you will get redirected to AWS Console in a new browser tab.
2. On the AWS sign-in page,

   * Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the project.
   * Now copy your **User Name** and **Password** in the Project Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.
3. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

#### Task 2: Copy the S3 Object URL of the Sample template to create CloudFormation stack

1. Make sure you are in **US East (N. Virginia) us-east-1** Region.
2. Navigate to the **Services** menu at the top. Click on **S3** in the **Storage** section.
3. Click on the S3 bucket name starting with **Whizlabs** to open.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/002.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=8fbb9d170ebcc5ae49bc9a3263a3aa91" alt="" width="1410" height="174" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/002.png" />
4. This bucket is created during the start of project, Click on the S3 object "**WAF\_CF\_template.template**" to open.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/003.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=ba401b5be31c854742b28f57b1135b16" alt="" width="2026" height="638" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/003.png" />
5. To copy the **Object URL**, click on the **copy** icon of the **Object URL**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/004.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=8275fdaea628e5c4dba6f594a3180b6c" alt="" width="2042" height="986" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/004.png" />
6. Copy and save it to the notepad, you will need this during the CloudFormation Stack creation.
   **Copied content example: [https://s3.amazonaws.com/whizlabs.1379.27205996/WAF\\\_CF\\\_template.template](https://s3.amazonaws.com/whizlabs.1379.27205996/WAF\\_CF\\_template.template)**

#### Task 3: Create a CloudFormation stack using a template present in an S3 Bucket

1. Navigate to CloudFormation. Click **Services**, click on **CloudFormation** in the **Management & Governance** section.
2. On the CloudFormation dashboard, click on **Create Stack**

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/005.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=19e2fafe0f504be70bc3843b8a0145bb" alt="" width="700" height="728" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/005.png" />
3. For Step-1, Specify template.

   * Prerequisite - Prepare template : Select **Choose an existing template**
   * Specify Template :

     * Template source    **:** Select **Amazon S3 URL**
     * Amazon S3 URL    : Paste the URL copied from earlier. **[https://s3.amazonaws.com/whizlabs.1379.27205996/WAF\\\_CF\\\_template.template](https://s3.amazonaws.com/whizlabs.1379.27205996/WAF\\_CF\\_template.template)**

     Click on **Next**.

     <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/006.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=d1e0c55bbb52cff18ef9a09c873c25a7" alt="" width="1184" height="714" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/006.png" />
4. For Step-2, Specify stack details

   * Stack Name: Enter ***DemoStack***
   * Keep all the options as default
   * Click on **Next** button.
5. For Step-3, Configure stack options,

   * In the **Permissions** tab, select the **IAM role name**. In the dropdown, please select the **IAM role**.
   * Keep remaining everything as default and click on **Next** button.
6. <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/007.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=669f25381dc06ab01a3e97c1025e432a" alt="" width="2054" height="588" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/007.png" />

   Check the option of acknowledgment. Click Next and click on **Submit** button.
7. Stack creation is having status as **CREATE\_IN\_PROGRESS** and it may take up to **15** **minutes** for the status to change to **CREATE\_COMPLETE**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/008.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=ffc9889f860c3e25a1591a2221bf882f" alt="" width="882" height="608" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/008.png" />
8. After some time, the status has changed to **CREATE\_COMPLETE**.
9. Switch to the Outputs tab and click to open **WebsiteURL** and **CloudFront URL** in a new tab.

#### Task 4: Create the WAF Web ACL and Rules

1. Click On **Services** And Select **WAF & Shield** Under The **Security, Identity And Compliance** Section.
2. In the left panel, scroll to the bottom and click **Switch to the old WAF Console**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/009.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=8ab3d3a4341ece3ac53e39d0945eb2e6" alt="" width="518" height="596" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/009.png" />
3. Open **IP Sets** section from left sidebar and perform the following task:
   •   From drop down make sure it is **Global (CloudFront).**
   **•**   Click on the **Create IP Set** button for creating IPv4 IP set

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/010.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=a11cbf5c4309ef48ed6c5e4ee8c2cd1e" alt="" width="2250" height="626" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/010.png" />

   •   Name: Enter **IP\_match\_v4**
   •   Select IP version: **IPv4**

* IP addresses : **10.0.0.0/32**

•   Keep all the fields as default and click on the **Create IP Set** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/011.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=9d2c141e1e3ad6847ae98b889c7fd1e7" alt="" width="1320" height="1034" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/011.png" />

•   **IP\_match\_v4** IP Set is created successfully.
•   From drop down make sure it is **Global (CloudFront).**
**•**   Click on the **Create IP Set** button again for creating ipv6 IP set
•   Name: Enter **IP\_match\_v6**
**•**   Select IP version as IPv6

Add IP address : **2001:db8:a0b:12f0::1/128**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/012.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=4938be60859656cf356b260ad26ba88f" alt="" width="1354" height="1002" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/012.png" />

**•**   Keep all the fields as default and click on the **Create IP Set** button.
**•   IP\_match\_v6** IP Set is created successfully.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/013.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=e24bbe1f8844f7c0048c52314c22bafa" alt="" width="1662" height="263" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/013.png" />

1. Open **Web ACLs** from left menu
2. Change the Filter to **Global (CloudFront).**
3. Click on the **Create web ACL** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/014.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=131fcd048208c89fc43ee7b233c58f97" alt="" width="940" height="250" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/014.png" />
4. For Step-1, Name web ACL, fill the below details:
   •   Resource Type: Select **Global resources (CloudFront Distributions and AWS Amplify Applications)**
   •   Web ACL Name: Enter **Whiz**
   •   CloudWatch metric name: Enter **Whiz**

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/015.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=3ef519b580da0f5159b68655fe71f29c" alt="" width="1015" height="697" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/015.png" />

   •   Under Associate Click on **Add AWS Resources**  button .
   **•**   A pop up will appear **Add AWS resources** to associate: Select **the CloudFront distribution present** as shown below\*\*.\*\*
   •   Click **Add** button

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/016.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=009787bab6b0a29cec20e00d6cb60eb9" alt="" width="698" height="374" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/016.png" />

   •   Click on the **Next** button to proceed.

   1. For Step-2, Add Rules and rule groups, complete the below requirements given:
      •   Click on the **Add rule** button then select **Add my own rules and rule groups**.

      <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/017.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=ab896360f7df8a1d14fbf88cece7a9bd" alt="" width="940" height="626" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/017.png" />

      •   Select **Rule builder.**

      <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/018.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=a662d3c3a128dcf9588e62b22af792df" alt="" width="940" height="333" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/018.png" />

      •   Name: Enter **Rule**
      •   Rule type: **Regular rule** (default)

      <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/019.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=5663b43338844bcfdd069ceac34b666c" alt="" width="940" height="468" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/019.png" />

      •   To Add Statement and action, Choose the following:
      •   if a request : **matches the statement**
      •   inspect : **Originate from an IP address in**
      •   IP Set : **IP\_match\_v4.**
      **•   Action : Block**

      <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/020.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=cc0db5d2f42a3a9cdea39cb07fe7821e" alt="" width="663" height="315" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/020.png" />

      •   Click on the **Add Rule** button.
      •   Click on the **Add rule** button again then select **Add my own rules and rule groups**.

      •   Select **Rule builder.**

      <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/018.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=a662d3c3a128dcf9588e62b22af792df" alt="" width="940" height="333" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/018.png" />

      •   Name: Enter **Rule2**
      •   Rule type: **Regular rule** (default)
      •   To Add Statement and action, Choose the following:
      •   if a request : **matches the statement**
      •   inspect : **Originate from an IP address in**
      •   IP Set : **IP\_match\_v6.**
      **•**   Action **: Block**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/021.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=1e16e37248d42204923eaa58d8e922ca" alt="" width="672" height="688" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/021.png" />

•   Click on the **Add Rule** button.
•   Default Web ACL action for requests that don't match any rules: Select **Block.**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/022.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=2daf611876a34cff4a4d459606b867ec" alt="" width="1608" height="1328" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/022.png" />

•   Click on the **Next** button.

1. For Step-3, keep **Set rule priority** as default and click **Next**.
2. For Step-4, keep **Configure metrics** as default and click **Next**.
3. For Step-5, review and click on **Create Web ACL** button.
4. Web ACL **Whiz** is created successfully.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/023.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=4458b0074a728ee1e92649ee3ca09ccf" alt="" width="911" height="363" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/023.png" />

#### Task 5: SSH into EC2 Instance using Session manager and run the scripts

1. Navigate to **EC2** by clicking on the **Services** menu at the top, then click on **EC2** in the **Compute** section.
2. Click on the to **Instances** on the left panel\*\*.\*\*
3. Select the instance by clicking on the **Instance id**.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/024.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=ce786cd4083638fed77968f8ef0d4183" alt="" width="1780" height="284" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/024.png" />
4. Click on the **Connect** button.
5. Switch to the **Session Manager** tab and click on the **Connect** button.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/025.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=c50d851f6a9eb6d8b62a7b4b54bb67f1" alt="" width="1650" height="870" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/025.png" />
6. The session manager will start the session that can be used for SSH.
7. Change the directory to root:

```plaintext theme={null}
cd ~
```

8. Check the present work directory:

```plaintext theme={null}
pwd
```

9. Make sure both the files are present, run the below command to list the files present in this directory:

```plaintext theme={null}
ls
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/026.jpg?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=b8695d8dd7f9cb0685be79ee5fb13c11" alt="" width="402" height="52" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/026.jpg" />

10. Run the below command for blocking the EC2 Instance website:

```plaintext theme={null}
python3 cloudfront_sgs.py
```

11. Refresh both **CloudFront** and **Website** tab.

12. CloudFront's distribution domain will work fine but the Website one will not open because the script has blocked and restricted access for EC2 and only allowed from CloudFront's distribution domain.

13. Block the access of **CloudFront** also. Paste the below command to the session manager's terminal:

```plaintext theme={null}
sudo python3 waf_ip_update.py
```

14. Refresh the **CloudFront** distribution page.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/027.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=3f79f8b6d3e349efcf8dd1f6c630644f" alt="" width="2708" height="622" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/027.png" />

* **Note: It may take up to 10 minutes for the changes to be reflected in CloudFront. Please refresh after every 30 seconds if the above error is not appearing.**

#### Task 6: Delete the IP address and test the working of CloudFront

1. Click On **Services** And Select **WAF & Shield** Under The **Security, Identity And Compliance** Section.
2. Go to Web ACLs click on the **Rule** button, first you need to delete both rules then you can delete IP sets because it is attached to the Web ACLs.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/028.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=8b07be6add54cf635f335c2f3f19ccdd" alt="" width="2702" height="866" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/028.png" />

3. Navigate To **IP Sets** From Left Sidebar, select both IP one by one.
4. Change The Filter To **Global(Cloudfront)**
5. Click On The **IP\_match\_v4,** now click on the **Delete** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/029.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=031acbf43f90bc296d9256dcbce9b2d9" alt="" width="1204" height="644" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/029.png" />

6. Same way select **IP\_match\_v6** And Delete By Clicking On The **Delete** Button.
7. IP's Are Deleted When You See The Confirmation.
8. Now **Refresh** The CloudFront Distribution Domain Page.

#### <img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/030.png?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=9bebeb94c49c1783ff29e2388083c22d" alt="" width="2014" height="864" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/030.png" />

**Note: It may take up to 1 minute for the page to be ready.**

<Tip>
  **Do you know?**

  AWS WAF can be used to block or unblock access to a CloudFront distribution based on the client's IP address. This can be useful for preventing unauthorized access to your content, or for blocking traffic from specific geographic regions.
</Tip>

#### Task 7 : Validation of the Lab

1. Once the lab steps are completed, please click on the **Check my work** button on the left side panel.
2. This will validate the resources in the AWS account and displays whether you have completed this lab successfully or not.
3. Sample output :

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/031.gif?s=ab065c29d94ce143c063f61cefc90adf" alt="" width="998" height="608" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/031.gif" />

#### Task 8: Delete AWS Resources

##### Delete the CloudFormation Stack application

1. Navigate to **CloudFormation** by Clicking on **Services**, click on **CloudFormation** in the **Management & Governance** section.
2. Click on the **Stacks** present on the left sidebar.
3. Select the **CloudFormation stack** present and Click on the **Delete** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/qRudZfyc-Pm9Aad9/images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/032.jpg?fit=max&auto=format&n=qRudZfyc-Pm9Aad9&q=85&s=b62eb2254e7215280e7d2fe3dc8099ba" alt="" width="1491" height="241" data-path="images/labs/block-and-unblock-access-to-cloudfront-distribution-using-aws-waf/032.jpg" />

4. Confirm the deletion by clicking on the **Delete stack** button.
5. CloudFormation stack is deleted successfully.

### Completion and conclusion

1. You have successfully created and launched Amazon EC2 Instance using the CloudFormation stack.
2. You have successfully created CloudFront distribution using the CloudFormation stack.
3. You have successfully created Web ACL using AWS WAF Classic.
4. You have successfully done SSH using Session Manager.
5. You have successfully blocked traffic of the EC2 instance's website and CloudFront distribution domain by running the scripts.
6. You have successfully updated the Web ACL for allowing CloudFront distribution domain.

### End lab

1. Sign out of AWS Account.
2. You have successfully completed the project.
3. Once you have completed the steps, click on **End lab** in the IP Lab Portal.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Create a CloudFormation Stack** — Check whether a CloudFormation stack is created or not.
* **Launch an Amazon EC2 Instance from CloudFormation** — Check whether an EC2 instance is created from CloudFormation or not.
* **Invoke CloudFront Distribution Domain** — Check whether the CloudFront Distribution domain is accessible from the internet or not.
* **Create CloudFront Distribution** — Check whether a CloudFront Distribution is created and status as Deployed or not.

## Related help

* [FAQs and Troubleshooting](/aws-cp/support/faqs-and-troubleshooting)
