Migrating a web ACL: switchover - Amazon WAF, Amazon Firewall Manager, and Amazon Shield Advanced
Services or capabilities described in Amazon Web Services documentation might vary by Region. To see the differences applicable to the China Regions, see Getting Started with Amazon Web Services in China (PDF).

Migrating a web ACL: switchover

After you've verified your new web ACL settings, you can start to use it in place of your Amazon WAF Classic web ACL.

To begin using your new Amazon WAF web ACL
  1. Associate the Amazon WAF web ACL with the resources that you want to protect, following the guidance at Associating or disassociating a web ACL with an Amazon resource. This automatically disassociates the resources from the old web ACL.

    The switch can take from a few seconds to a number of minutes to propagate. During this time, some requests might be processed by the old web ACL and others by the new web ACL. Your resources will be protected throughout the switch, but you might notice inconsistencies in request handling until it's complete.

  2. Configure logging for the new web ACL, following the guidance at Logging Amazon WAF web ACL traffic.

  3. (Optional) If your Amazon WAF Classic web ACL is no longer associated with any resources, consider removing it entirely from Amazon WAF Classic. For information, see Deleting a Web ACL.