Concept and mechanism
A rate rule depends on aggregation key, window, scope, and action. Many users behind NAT can share an IP counter. The same per-person volume can collectively exceed the limit and interrupt an entire office. Conversely, an address is not necessarily an account identity. AWS WAF estimates rates and does not guarantee an exact per-user quota; such a contractual obligation needs a mechanism suited to the required identity and precision. Increasing retries during blocking can increase observed pressure. Investigate the grouped population before adjusting limits. Confirm both client behavior and the protection objective before proposing an exception.
Guided application
In AWS WAF, custom-key components must be present for a request to be evaluated by that rule. Absence needs its own policy. For forwarded IP, distinguish an absent header from a present invalid value: do not assume invalid-value fallback covers both. The field origin must also be trustworthy. A scope-down limits aggregated and affected requests; Count above the limit observes without imposing blocking. In the fictional partner-network case, correlate failures and aggregation, contain the specific change if necessary, and validate a policy retaining protection without treating a shared IP as individual identity.
One IP counter can represent many users and several operations.
Common pitfalls
IP as account; estimated rate as exact quota; absence as invalidity; Count as traffic reduction.
Related topics: WAF architecture and coverage · Order, actions, and overrides · Parsing and inspection limits
Establish who is aggregated, what is excluded, and which action applies.
Reference: AWS WAF aggregation keys · DR WAF 2026-09; selected AWS WAF and OWASP CRS operational concepts