When AWS updates a rule group

AWS updates the managed rule groups on your firewall over time. The Advisor reads that change. It will not tell you to block from counts that were gathered on an older list of rules.

What we store

Each managed group on your firewall is saved with a version. We read the versions AWS is serving, and the rule names in those versions. If a group were left without a version, AWS would serve its default, and AWS can move that default. A group that is already blocking would then block rules you have not reviewed.

A saved version stays put when AWS moves the default. Your blocking rules do not change because AWS published something new.

A group still in count

If the new version adds a rule, removes a rule, or the rule list cannot be read, the group stays in count and the 24-hour watch starts over. Counts from the older version are not used. The Advisor says Hold until a full day of counts is from the rules running now.

If the new version has the same rule names, the group moves to that version and stays in count. The 24-hour watch starts over. AWS can change a rule without renaming it, so counts from the older version are not used. The Advisor says Hold until a full day of counts is from the version running now. Nothing blocks until you click.

A missing rule list is not treated as the same rules. That group stays on hold.

A group that is already blocking

If the new version only adds rules, the firewall moves to that version and the new rules count. Rules that were already blocking stay blocking. That move does not promote anything, and it does not allow anything. Each new rule needs its own count. A total for the whole group is not that rule. The Advisor will not say Promote for it until that count exists.

If the new version removes or renames rules, or the names are the same, or the lists cannot be compared, the firewall stays on the version it already has. Tuning shows what AWS published. You click Update when you want the newer version. New rules from that click start in count. Nothing is promoted by the click.

A version AWS will no longer accept cannot stay on the firewall, or a later save would fail. We move off that version. New rules count. If they cannot be counted one by one, the whole group goes back to count. Nothing is promoted.

What you see

Tuning names the change in plain language: which group, which version, and whether rules were added, removed, or the names stayed the same. The same sentence is on the protection report, in the weekly digest, and in the ready-to-promote mail when that rule is still in its watch window. A count group whose names stayed the same still says the watch started over.

You still click Promote. Nothing on this page blocks a request or writes an allowlist.

Related guides

More in this section