← WAF: application protection and operations
02 / 6 · 40 MIN

Order, actions, and overrides

Interpret rule evaluation without confusing observation with permission or blocking.

Concept and mechanism

In AWS WAF, rules are evaluated in ascending numeric priority. A terminating action ends that evaluation: Allow before a group can prevent later rules from inspecting the request. Count records a match and lets evaluation continue; it means neither that the request is authorized nor that it was blocked. A Count rule can therefore match while a later Block rule determines the final decision. When reviewing a policy, follow the order using a concrete request and identify the first terminating point. The number of configured rules does not prove that every rule is reached for each path.

Guided application

Also distinguish changing individual actions from overriding only a group result to Count. The latter does not change internal evaluation; a terminating rule can prevent observing other rules in the group. For tuning, establish the scope of each override. CAPTCHA and Challenge have token-dependent behavior and require attention to the client. Do not assume a browserless batch can complete an interactive flow. In an incorrectly blocked export case, a broad Allow restores service but removes later inspection. Review the specific match, residual risk, and necessary regression before accepting the exception as a durable solution.

IN PRACTICE

Priority 10 Allow terminates before priority 20 Block when both would match.

Common pitfalls

Count as Allow; higher priority number as first; group override as every action; batch as browser.

Related topics: WAF architecture and coverage · Parsing and inspection limits · Tuning and false positives

Take this idea with you

Follow evaluation flow and identify the action that actually decides.

Create account

Reference: AWS WAF rule priority · DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts