Skip to content
Notifications
Clear all

What's the best practice for rate limiting with AWS WAF?

1 Posts
1 Users
0 Reactions
23 Views
(@jasonb)
Estimable Member
Joined: 3 months ago
Posts: 115
Topic starter   [#16729]

Just tried to set up rate limiting on our API with AWS WAF. It's powerful, but the defaults can be tricky! What rules are you all running in production?

I'm currently using:
- **Rate-based rules** on the IP address for login endpoints.
- **Separate rules** for different URI paths (API vs. assets).
- **Low threshold for /admin paths**.

Biggest lesson so far: combine it with AWS Shield Advanced for DDoS protection on the same endpoints. The combo is solid.

What's your go-to setup? Any pitfalls with the aggregation keys or latency?


Let's build better workflows.


   
Quote