> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Implementing AWS WAF with ALB to block SQL Injection, Geo Location and Query string

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

### Lab Details

1. This tutorial guides you through the process of setting up an Application Load Balancer in AWS Elastic Load Balancer. This advanced load balancing solution efficiently divides incoming application traffic among two Amazon EC2 instances. Furthermore, we will establish a series of regulations to prevent access from specific geographical locations, safeguard against SQL injections, and restrict certain Query String parameters.
2. Duration: **120 minutes**
3. AWS Region: **N. Virginia (us-east-1)**

### Introduction

#### What is AWS WAF?

* AWS WAF is a web application firewall that helps you to protect your web applications against common web exploits that might affect availability and compromise security.
* AWS WAF gives you control over how traffic reaches your applications by enabling you to create security rules that block common attack patterns like SQL injection and cross-site scripting.
* It only allows the request to reach the server based on the rules or patterns you define.
* Users create their own rules and specify the conditions that AWS WAF searches for in incoming web requests.
* The cost of WAF is only for what you use.
* The pricing is based on how many rules you deploy and how many web requests your application receives.
* For example, you can deploy AWS WAF on Amazon CloudFront, Load Balancer or API Gateways.

#### What is Elastic Load Balancing?

* ELB is a service that automatically distributes incoming application traffic and scales resources to meet traffic demands.
* It helps in adjusting capacity according to incoming application and network traffic.
* It can be enabled within a single availability zone or across multiple availability zones to maintain consistent application performance.
* ELB offers features like:
* Detection of unhealthy EC2 instances.
* Spreading EC2 instances across healthy channels only.
* Centralized management of SSL certificates.
* Optional public key authentication.
* Support for both IPv4 and IPv6.
* ELB accepts incoming traffic from clients and routes requests to its registered targets.
* When an unhealthy target or instance is detected, ELB stops routing traffic to it and resumes only when the instance is healthy again.
* ELB monitors the health of its registered targets and ensures that the traffic is routed only to healthy instances.
* ELB's are configured to accept incoming traffic by specifying one or more **listeners**. A listener is a process that checks for connection requests.
* Listeners are configured with a protocol and port number from the client to the ELB and vice-versa i.e., back from ELB to the client.
* ELB supports the following :
* Application Load Balancers.
* Network Load Balancers.
* Gateway Load Balancers.
* Classic Load Balancers.
* Each load balancer is configured differently.
* For Application and Network Load Balancers, you register targets in target groups and route traffic to target groups.
* Gateway Load Balancers use Gateway Load Balancer endpoints to securely exchange traffic across VPC boundaries.
* For Classic Load Balancers, you register instances with the load balancer.
* AWS recommends users to work with Application Load Balancer to use multiple Availability Zones because if one availability zone fails, the load balancer can continue to route traffic to the next available one.
* We can have our load balancer be either internal or internet-facing.
* The nodes of an internet-facing load balancer have Public IP addresses, and the DNS name is publicly resolvable to the Public IP addresses of the nodes.
* Due to the point above, internet-facing load balancers can route requests from clients over the Internet.
* The nodes of an internal load balancer have only Private IP addresses, and the DNS name is publicly resolvable to the Private IP addresses of the nodes.
* Due to the point above, internal load balancers can only route requests from clients with access to the VPC for the load balancer.
* Both internet-facing and internal load balancers route requests to your targets using Private IP addresses.
* Your targets do not need Public IP addresses to receive requests from an internal or an internet-facing load balancer.
* You can create your own rules, depending on your requirements, whether to block or allow the incoming and outgoing request. You can also customise the string that appears in your web request.
* Blocking malicious requests
* You can also configure rules in AWS WAF to identify and block web requests threats like SQL injections and cross-site scripting.
* Tune your rules and monitor traffic
* AWS WAF also allows us to review our rules and customize them to prevent new attacks from reaching the server.

### Architecture Diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/001.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=178eed2a4ae08380de59f413402bfa77" alt="" width="4013" height="2316" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/001.png" />

### Task Details

1. Sign in to AWS Management Console.
2. Launch First EC2 Instance.
3. Launch Second EC2 Instance.
4. Create a Target Group.
5. Create an Application Load Balancer.
6. Test Load Balancer DNS.
7. Create AWS WAF Web ACL.
8. Test Load Balancer DNS.
9. Deleting AWS Resources.

### Launching Lab Environment

1. To launch the lab environment, Click on the **Start Lab** button.
2. Please wait until the cloud environment is provisioned. It will take less than a minute to provision.
3. Once the Lab is started, you will be provided with **IAM user name**, **Password**, **Access** **Key**, and **Secret** **Access** **Key**.

> **Note** : You can only start one lab at any given time

## Lab guide

### Lab Steps

#### Task 1: Sign in to AWS Management Console

1. Click on the **Open Console** button, and you will get redirected to AWS Console in a new browser tab.
2. On the AWS sign-in page,

   * Leave the Account ID as default. Never edit/remove the 12 digit Account ID present in the AWS Console. otherwise, you cannot proceed with the lab.
   * Now copy your **User Name** and **Password** in the Lab Console to the **IAM Username and Password** in AWS Console and click on the **Sign in** button.
3. Once Signed In to the AWS Management Console, Make the default AWS Region as **US East (N. Virginia) us-east-1.**

#### Task 2: Launch First EC2 Instance

In this task, we are going to launch the first EC2 instance by providing the required configurations like name, AMI selection, security group , instance type and other settings. Furthermore, we will provide the user data as well.

1. Make sure you are in the **N. Virginia(us-east-1)** Region.
2. Navigate to **EC2** by clicking on the **Services** menu in the top left, then click on **EC2** in the **Compute** section.
3. Navigate to **Instances** from the left side menu and click on **Launch Instances** button.
4. Under the **Name and tags** section :

   * Name : Enter ***MyEC2Server1***

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/002.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=ce337e038861a9e8aeaac65e6312fb7a" alt="" width="972" height="201" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/002.png" />

5. Under the **Application and OS Images (Amazon Machine Image)** section :

   * Select **Quick Start** tab and **Amazon Linux** under it
   * Amazon Machine Image (AMI) : select **Amazon Linux 2023 kernel 6.1 AMI**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/003.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=ef6a67cb0f87d3cdb22840c363db0277" alt="" width="930" height="466" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/003.png" />

6. Under the **Instance Type** section **:**

   * Instance Type : Select **t2.micro**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/004.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=ae20d72fc6dfb46f1b1fc129c638fe69" alt="" width="971" height="260" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/004.png" />

7. Under the **Key Pair (login)** section **:**

   * Click on **Create new key pair** hyperlink
   * Key pair name: **MyWebserverKey**
   * Key pair type: **RSA**
   * Private key file format: **.pem** or **.ppk**
   * Click on **Create key pair** and then select the created key pair from the drop-down.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/005.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=fc3a0800e9f61b8185b4e24fa09be5f9" alt="" width="755" height="764" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/005.png" />

8. Under the **Network Settings** section **:**

   * Click on **Edit** button
   * Auto-assign public IP: select *Enable*
   * Firewall (security groups) : Select **Create a new security group**
   * Security group name : Enter **MyWebserverSG**
   * Description : Enter **My EC2 Security Group**
   * To add **SSH:**

     * Choose Type: **SSH**
     * Source: **Anywhere** (From ALL IP addresses accessible).
   * For **HTTP**, click on **Add security group rule**,

     * Choose Type: **HTTP**
     * Source: **Anywhere**  (From ALL IP addresses accessible).
   * For **HTTPS**, click on **Add security group rule**,

     * Choose Type: **HTTPS**
     * Source: **Anywhere** (From ALL IP addresses accessible).

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/006.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=b63c8c5c65b430bc1bd8ad6b157795e3" alt="" width="917" height="636" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/006.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/007.gif?s=b79d6f44725e1e0757c8be0ca860715a" alt="" width="948" height="606" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/007.gif" />

9. Under the **Advanced details** section **:**

   * Under the **User data:** copy and paste the following script to create an HTML page served by an Apache HTTPD web server.

     ```
     #!/bin/bash
     dnf update -y
     dnf install -y httpd
     systemctl start httpd
     systemctl enable httpd
     echo "<html><h1> Welcome to IP Lab Portal Server 1 </h1></html>" > /var/www/html/index.html
     ```

10. Keep everything else as default and click on the **Launch instance** button.

11. **Launch Status:** Your instance is now launching, Navigate to **Instances** page from the left menu and wait until the status of the EC2 Instance changes to **running**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/008.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=b12c7ed69a2dc887e4c02d993f39ca15" alt="" width="1118" height="197" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/008.png" />

#### Task 3: Launch Second EC2 Instances

In this task, we are going to launch the second EC2 instance by providing the required configurations like name, AMI selection, security group , instance type and other settings. Furthermore, we will provide the user data as well.

1. Now again click on **Launch Instances** button.
2. Under the **Name and tags** section :

* Name : Enter ***MyEC2Server2***

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/009.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=09f7eeb70f612b3c2795d70e71a6ddf4" alt="" width="975" height="202" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/009.png" />

3. Under the **Application and OS Images (Amazon Machine Image)** section :

* Select **Quick Start** tab and **Amazon Linux** under it
* Amazon Machine Image (AMI) : select **Amazon Linux 2023 kernel 6.1 AMI**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/010.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=bbdfdbf0e779d3c9db54ca7ea4a22b90" alt="" width="930" height="466" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/010.png" />

4. Under the **Instance Type** section **:**

   * Instance Type : Select **t2.micro**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/004.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=ae20d72fc6dfb46f1b1fc129c638fe69" alt="" width="971" height="260" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/004.png" />

5. Under the **Key Pair (login)** section **:**

   * Select **MyWebserverKey** from the list.

6. Under the **Network Settings** section **:**

* Click on **Edit** button
* Auto-assign public IP: select **Enable**
* Firewall (security groups) : **Select existing security group**
* Security group name : Enter **MyWebserverSG**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/011.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=f4ad679a317e202f84a22384d20514fe" alt="" width="691" height="336" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/011.png" />

7. Under the **Advanced details** section **:**

   * Under the **User data:** copy and paste the following script to create an HTML page served by Apache httpd web server:

     ```
     #!/bin/bash
     dnf update -y
     dnf install -y httpd
     systemctl start httpd
     systemctl enable httpd
     echo "<html><h1> Welcome to IP Lab Portal Server 2 </h1></html>" > /var/www/html/index.html
     ```

8. Keep everything else as default and then click on the **Launch Instance** button.

9. Your instances are now launching. Navigate to the EC2 instance page and wait until the status changes to the **Running**. It will usually take 1-2 minutes.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/012.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=574ec443894d337837687467792a7b67" alt="" width="1115" height="223" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/012.png" />

#### Task 4: Create a Target Group

In this task, we are going to create a target group for the load balancer and will add the target instances so that the load balancer can distribute the traffic among these instances.

1. In the EC2 console, navigate to **Target Groups** in the left-side panel under **Load Balancer** in the **Load Balancing** section.
2. Click on **Create target group** button on the top right corner.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/013.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=74287383c14ba5d9aa19c9769026315b" alt="" width="1484" height="435" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/013.png" />

3. Basic configuration:

* Choose a target type : Select **Instances**
* Target group name : Enter ***MyWAFTargetGroup***
* Protocol : Select **HTTP**
* Port : Enter ***80***

4. Health Checks:

* Health check protocol : Select **HTTP**

5. Under Advanced Health Check Settings :

* Choose Healthy threshold : 3
* Choose Unhealthy threshold : 2
* Choose Timeout : 5 seconds
* Choose Interval : 6 seconds

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/014.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=06cb42e7f464849dc52ea01a5f34fae1" alt="" width="869" height="560" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/014.png" />

6. Leave everything as default and click on **Next** button.

7. Register targets:

* Select the two instances we have created i.e **MyEC2Server1** and **MyEC2Server2**.
* Click on **Include as pending below** and scroll down.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/015.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=d551682b74791295091b89c4a6f4074e" alt="" width="1172" height="607" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/015.png" />

8. Review targets:

* Review the targets and click on **Create target group** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/016.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=3341bd1b0be35d6d526cf54d615384ef" alt="" width="1416" height="536" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/016.png" />

9. Your Target group has been successfully created.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/017.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=bef8087f09932e6d52cce4fed7c964d3" alt="" width="1503" height="395" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/017.png" />

#### Task 5: Create an Application Load Balancer

In this task, we are going to create an Application Load balancer by providing the required configurations like name, target group etc.

1. In the EC2 console, navigate to **Load Balancers** in the left-side panel under **Load Balancing**.
2. Click on **Create Load Balancer** at the top-left to create a new load balancer for our web servers.
3. On the next screen, choose **Application Load Balancer** since we are testing the high availability of the web application and click on **Create** button.
4. Basic configuration:

   * Load balancer name: Enter ***MyWAFLoadBalancer***
   * Scheme: Select **Internet-facing**
   * IP address type: Choose **IPv4**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/018.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=e5f7fb184844f5035f70da1ccd0ca5bc" alt="" width="1042" height="594" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/018.png" />

5. Network mapping:

* VPC : Select **Default**
* Mappings : Check **All Availability Zones**

6. Security groups:

* Security groups : Select an **existing security group** i.e **MyWebserverSG** from the drop down menu.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/019.gif?s=da2e653a34a9a9fda22d396247c0944d" alt="" width="1152" height="349" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/019.gif" />

7. Listeners and routing:

* Protocol : Select **HTTP**
* Port : Enter ***80***
* Default action : Select **MyWAFTargetGroup** from the drop down menu

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/020.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=84628d253df1746a860bd94c9da6f23d" alt="" width="1302" height="255" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/020.png" />

8. Leave everything as default and click on **Create load balancer** button.

9. You have successfully created Application Load Balancer.

#### Task 6: Test Load Balancer DNS

In this task, we will test the working of load balancer by copying the DNS to the browser and find out whether it is able to distribute the traffic or not.

1. Now navigate to the **Target Groups** from the left side menu under **Load balancing**.
2. Click on the **MyWAFTargetGroup** Target group name.
3. Now select the **Targets** tab and **wait till both the targets become healthy (Important)**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/021.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=1cc7e8f79c1f5154a595aba0bf4b0a54" alt="" width="1059" height="261" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/021.png" />

4. Now again navigate to **Load Balancers** from the left side menu under **Load balancing**.
5. Select the **MyWAFLoadBalancer** Load Balancer and copy the **DNS name** under **Description** tab.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/022.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=bdd408a687eb597df145de327b85e174" alt="" width="1428" height="734" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/022.png" />

6. Copy the **DNS name** of the  ELB and enter the address in the **browser**.

   * **DNS Example: MyWAFLoadBalancer-2020171322.us-east-1.elb.amazonaws.com**
7. You should see the **index.html** page content of Web Server 1 or Web Server 2

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/023.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=e905ae70744465470dee7f0097a798ba" alt="" width="927" height="219" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/023.png" />

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/024.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=8af0c0cff8783f4ead545674f536f15e" alt="" width="872" height="184" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/024.png" />

8. Now **Refresh** the page a **few times**. You will observe that the index pages change each time you refresh.

> **Note: The ELB will equally divide the incoming traffic to both servers in a Round Robin manner**.

9. Test **SQL Injection** :

* Along with the ELB DNS add the following URL parameter: ***/product?item=securitynumber'+OR+1=1--***
* Syntax : **http\://\<ELB DNS>/product?item=securitynumber'+OR+1=1--**
* Example : **MyWAFLoadBalancer-2020171322.us-east-1.elb.amazonaws.com**\*\*\*/product?item=securitynumber'+OR+1=1--\*\*\*
* You will be able to see the below output.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/025.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=ce16de0ffb177e698d7426b849ca74b9" alt="" width="1218" height="299" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/025.png" />

* Here the **SQL Injection went inside the server** and since we only have an index page, the server doesn't know how to solve the URL that is why you got **Not Found** page.

10. Test Query String Parameter :

* Along with the ELB DNS add the following URL parameter: ***/?admin=123456***
* Syntax : **http\://\<ELB DNS>/?admin=123456**
* Example : **MyWAFLoadBalancer-2020171322.us-east-1.elb.amazonaws.com**\*\*\*/?admin=123456\*\*\*
* You will be able to see the below output.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/026.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=ffbd8bc526e43476b3b8e20bf7bc739a" alt="" width="954" height="193" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/026.png" />

* Here also the **Query string went inside the server** and the server always passes the query string inside and it is resolved by the code that you write. Here the query string is passed and there is no code to resolve the this but it wont throw any error it just becames an unused value. so you got a response back.

#### Task 7: Create AWS WAF Web ACL

In this task , we are going to create an AWS WAF Web ACL where we will add some customized rules for location restriction, query strings and

1. Navigate to **WAF** by clicking on the **Services** menu in the top, then click on **WAF & Shield** in the **Security, Identity & Compliance** section.

   Click on **Switch to the Old WAF Console** option at the Bottom.

   <img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/027.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=263a8f4ea943fb96bd1d57cc1936085a" alt="" width="491" height="824" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/027.png" />
2. Click on **Create web ACL** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/028.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=a59cf1d56f82d8d1dc5e509ebd9e71c8" alt="" width="1221" height="496" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/028.png" />

3. Describe web ACL and associate it to AWS resources :

* Resource type : Select **Regional resources**
* Region : Select **US East (N.Virginia)** from the dropdown.
* Name : Enter ***MyWAFWebAcl***
* Description : Enter ***WAF for SQL Injection, Geo location and Query String parameters.***
* CloudWatch metric name : Automatically selects the WAF name, so no changes required.
* **Associated AWS resources :**
* Click on the **Add AWS resources** button.
* Resource type : Select **Application Load Balancer**
* Select **MyWAFLoadBalancer** Load Balancer from the list.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/029.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=73932b252070c40177c213fce832d99d" alt="" width="1022" height="619" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/029.png" />

* Now click on the **Add** button.
* Click on the **Next** button.

4. Add rules and rule groups :

   * Under **Rules**, click on **Add rules** and then select **Add my own rules and rule groups.**

     * Rule type : Select **Rule builder**
     * Name : Enter ***GeoLocationRestriction***
     * Type : Select **Regular rule**
     * If a request : Select **doesn't match the statement (NOT)**
     * Inspect : Select **Originates from a country in**
     * Country codes : Select **\<Your Country>** In this example we select **India-IN**

       > **Note** : You can also select multiple countries also.
     * IP address to use to determine the country of origin : Select **Source IP address**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/030.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=c57a3c1bbdc361d7128fdae15554d5b1" alt="" width="1060" height="581" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/030.png" />

* Under **Then** : **Action** Select **Block**.
* Click on **Add rule**.
* Here we are only allowing requests to come from India and all the requests that come from other countries will be blocked.
* Under **Rules**, click on **Add rules** and then select **Add my own rules and rule groups**.

  * Rule type : Select **Rule builder**
  * Name : Enter ***QueryStringRestriction***
  * Type : Select **Regular rule**
  * If a request : Select **matches the statement**
  * Inspect : Select **Query string**
  * Match type : Select **Contains string**
  * String to match : Enter ***admin***
  * Text transformation : Leave as default.
  * Under **Then** : **Action** Select **Block**.
  * Click on **Add rules**.
* Anytime in the request URL contains a query string as **admin** WAF will block that request.
* Under **Rules**, click on **Add rules** and then select **Add managed rule groups**.

  * It will take a few minutes to load the page. It lists all the rules which are managed by AWS.
  * Click on **AWS managed rule groups**.
  * Scroll down to **SQL database** and enable the corresponding **Add to web ACL** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/031.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=8e78ea0b3fa318d07de9e61fc22a6af0" alt="" width="850" height="115" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/031.png" />

* Scroll down to the end and click on **Add rules** button.
* Now you have 3 rules added.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/032.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=3fc6cf994e929b3ded79fe10d6b37d24" alt="" width="784" height="174" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/032.png" />

* Under **Default web ACL action for requests that don't match any rules**, **Default action** Select **Allow**.
* Click on the **Next** button.

5. Set rule priority :

   * No changes required, leave as default.
   * You can move the rules based on your priority.
   * Click on the **Next** button.
6. Configure metrics :

   * Leave it as default.
   * Click on the **Next** button.
7. Review and create web ACL :

   * Review the configuration done, scroll to the end and click on **Create web ACL** button.
8. It will take a few seconds to create the Web ACL, so wait till its completed.

   ***Note: Make sure the Load Balancer is attached to the Web ACL by navigating to the Associated AWS resources tab. If it is not attached, click Add AWS resources and manually add the Load Balancer.***

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/033.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=c8e742dfb8162f6f54b2d17cf402cdb5" alt="" width="1595" height="769" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/033.png" />

#### Task 8: Test Load Balancer DNS

1. Now again navigate to **Load Balancers** from the left side menu under **Load balancing**.
2. Select the **MyWAFLoadBalancer** Load Balancer and copy the **DNS name** under **Description** tab.
3. Copy the **DNS name** of the  ELB and enter the address in the **browser**.

   * **DNS Example: MyWAFLoadBalancer-2020171322.us-east-1.elb.amazonaws.com**
4. You should see the **index.html** page content of Web Server 1 or Web Server 2.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/034.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=bda0a8a6241eff850b4735e3052aeacd" alt="" width="927" height="219" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/034.png" />

5. Now **Refresh** the page **a few times**.You will observe that the index pages change each time you refresh.

   > **Note: The ELB will equally divide the incoming traffic to both servers in a Round Robin manner**.

6. Test **SQL Injection** :

   * Along with the ELB DNS add the following URL parameter: ***/product?item=securitynumber'+OR+1=1--***
   * Syntax : **http\://\<ELB DNS>/product?item=securitynumber'+OR+1=1--**
   * Example : **MyWAFLoadBalancer-2020171322.us-east-1.elb.amazonaws.com**\*\*\*/product?item=securitynumber'+OR+1=1--\*\*\*
   * You will be able to see the below output.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/035.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=043bc63ff5f665de813242de4a4dae38" alt="" width="1262" height="209" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/035.png" />

* Here the **SQL Injection is blocked by WAF before it goes inside the server**.

7. Test Query String Parameter :

   * Along with the ELB DNS add the following URL parameter: ***/?admin=123456***
   * Syntax : **http\://\<ELB DNS>/?admin=123456**
   * Example : **MyWAFLoadBalancer-2020171322.us-east-1.elb.amazonaws.com**\*\*\*/?admin=123456\*\*\*
   * You will be able to see the below output.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/036.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=72390c01bb43a3826b9c31e62c2354b9" alt="" width="1179" height="204" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/036.png" />

* Here also the **Query string which contains admin is blocked by WAF before it could go inside the server**.

> ##### Do you know?
>
> WAF can offer protection against Distributed Denial of Service (DDoS) attacks by analyzing traffic patterns, detecting abnormal behavior, and mitigating the impact of such attacks.

#### Task 9: Delete AWS Resources

**10.1 Deleting an EC2 Instance**

* Make sure you are in the **US East (N. Virginia) us east-1** Region.
* Navigate to **EC2** by clicking on the **Services** menu in the top, then click on **EC2** under **Compute** section.
* Now select the EC2 instance that you have created, click on the **Instance State** and click on the **Terminate** option.
* Click on **Yes,Terminate** button and your EC2 will start terminating.

**10.2 Deleting Elastic LoadBalancer and Target Group**

* In the EC2 console, navigate to **Load Balancer** in the left-side paneol.
* **MyWAFLoadBalancer** will be listed here.
* To **delete** the load balancer, need to perform the following actions:

  * **Select** the load balancer,
  * Click on the **Actions** button,
  * Select the **Delete** option.

    <img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/038.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=06c9f1f9b0bb63cec0079580b2034644" alt="" width="1444" height="480" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/038.png" />
* Confirm by typing **confirm** and then click on **Delete** button when a pop-up is shown.

  <img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/039.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=be03908886a0bb0cfda8860fee4a4478" alt="" width="757" height="503" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/039.png" />
* **MyWAFLoadBalancer** be deleted immediately.
* In the EC2 console, navigate to **Target Groups** in the left-side panel.
* **MyWAFTargetGroup** will be listed here.
* To delete the **target group**, need to perform the following actions:

  * **Select** the target group,
  * Click on the **Actions** button,
  * Select the **Delete** option.

    <img src="https://mintcdn.com/ip-cloud-architect-pathway/OGWG_Fy9il7e0mi5/images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/040.png?fit=max&auto=format&n=OGWG_Fy9il7e0mi5&q=85&s=fcafc876f933854cdf09bcb52d4b4890" alt="" width="1452" height="315" data-path="images/labs/implementing-aws-waf-with-alb-to-block-sql-injection-geo-location-and-query-stri/040.png" />
* Now click on the **Yes, delete** button to confirm deletion.
* **MyWAFTargetGroup** will be deleted immediately.

**10.3 Deleting Web ACL**

* Navigate to **WAF** by clicking on the **Services** menu in the top, then click on **WAF & Shield** in the **Security, Identity & Compliance** section.
* On the left side menu, select **Web ACLs** and then click on the Web ACL name that you created, **MyWAFWebAcl**.
* Select **Associated AWS resources** tab, select the application load balancer and click on **Diassociate**  button.
* In the textbox enter ***remove*** and click on **Diassociate** button.
* On the left side menu, select **Web ACLs** and then select the radio button of the Web ACL that you created, **MyWAFWebAcl**.
* Click on the **Delete** button, In the textbox enter ***delete*** and click on **Delete** button.
* Now the WAF will be successfully deleted.

### Completion and Conclusion

1. You have successfully launched First EC2 Instance.
2. You have successfully launched Second EC2 Instance.
3. You have successfully created an Application Load Balancer and Target Group.
4. You have successfully tested Load Balancer DNS.
5. You have successfully created AWS WAF Web ACL.
6. You have successfully tested Load Balancer DNS.

### End Lab

1. Sign out of the AWS Account.
2. You have successfully completed the lab.
3. Once you have completed the steps, click on **End Lab** from your IP Lab Portal and wait till the process gets completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Launch EC2 AMI type Amazon Linux** — Check whether the EC2 instance is launched using an Amazon AMI.
* **Create a Application Load Balancer** — Check if given type of Load Balancer is created or not.
* **Create ELB Target Group** — Check if given type of Load Balancer is created or not.
* **Check Load Balancer DNS Status** — Check whether the Elastic Load Balancer DNS URL is accessible from the internet or not.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.