Deleting a Web ACL
Warning
Amazon WAF Classic support will end on September 30, 2025.
Note
This is Amazon WAF Classic documentation. You should only use this version if you created Amazon WAF resources, like rules and web ACLs, in Amazon WAF prior to November 2019, and you have not migrated them over to the latest version yet. To migrate your web ACLs, see Migrating your Amazon WAF Classic resources to Amazon WAF.
For the latest version of Amazon WAF, see Amazon WAF.
To delete a web ACL, you must remove the rules that are included in the web ACL and disassociate all CloudFront distributions and Application Load Balancers from the web ACL. Perform the following procedure.
To delete a web ACL
Sign in to the Amazon Web Services Management Console and open the Amazon WAF console at https://console.amazonaws.cn/wafv2/
. If you see Switch to Amazon WAF Classic in the navigation pane, select it.
In the navigation pane, choose Web ACLs.
Choose the name of the web ACL that you want to delete. This opens a page with the web ACL's details in the right pane.
Note
If you don't see the web ACL, make sure the Region selection is correct. Web ACLs that protect Amazon CloudFront distributions are in Global (CloudFront).
On the Rules tab in the right pane, choose Edit web ACL.
To remove all rules from the web ACL, choose the x at the right of the row for each rule. This doesn't delete the rules from Amazon WAF Classic, it just removes the rules from this web ACL.
Choose Update.
Disassociate the web ACL from all CloudFront distributions and Application Load Balancers. On the Rules tab, under Amazon resources using this web ACL, choose the x for each API Gateway API, CloudFront distribution or Application Load Balancer.
On the Web ACLs page, confirm that the web ACL that you want to delete is selected, and then choose Delete.