AWS::NetworkFirewall::FirewallPolicy StatefulRuleGroupOverride - Amazon CloudFormation
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

AWS::NetworkFirewall::FirewallPolicy StatefulRuleGroupOverride

The setting that allows the policy owner to change the behavior of the rule group within a policy.


To declare this entity in your Amazon CloudFormation template, use the following syntax:


{ "Action" : String }


Action: String



The action that changes the rule group from DROP to ALERT. This only applies to managed rule groups.

Required: No

Type: String

Allowed values: DROP_TO_ALERT

Update requires: No interruption