---
title: AWS Web Application Firewall (WAF)
description: AWS WAF resource replication with Arpio
---

[Skip to content](https://docs.arpio.io/aws-web-application-firewall#main-content)

English

Show submenu for translations

[Customer ticket portal](https://docs.arpio.io/tickets-view?hsLang=en)

- Home
- Products
- Pricing
- Blog
- Company

Open main navigation

Close main navigation

- Home
- Products
- Pricing
- Blog
- Company
- English
  
  Show submenu for translations
- [Customer ticket portal](https://docs.arpio.io/tickets-view)

 Welcome to Arpio Technical Docs

- There are no suggestions because the search field is empty.

1. [Arpio Documentation](https://docs.arpio.io/?hsLang=en)
2. [AWS Reference Guides](https://docs.arpio.io/aws-reference-guides?hsLang=en)
3. [AWS Resource Reference](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-resource-reference)

# AWS Web Application Firewall (WAF)

## AWS WAF resource replication with Arpio

### WAFv2

Arpio replicates the following WAFv2 resource types into your recovery environment.

#### Web ACL

Arpio replicates AWS WAFv2 web access control lists (web ACLs) to your recovery account. AWS WAF can be used to protect the following resource types:

- Amazon API Gateway REST API
- Elastic Load Balancing (ELB) Application Load Balancer (ALB)
- Amazon Cognito User Pool

Please contact us if you would like to replicate AWS WAF with AWS AppSync, GraphQL API, Amazon CloudFront, or WAFv1.

| **Attribute** | **Translation** |
| --- | --- |
| Rules | ARNs in rules that refer to rule groups, IP sets, and regex pattern sets are translated for the recovery environment. |
| CaptchaConfig ChallengeConfig CustomResponseBodies DefaultAction Description Name Scope VisibilityConfig | These attributes are replicated to your recovery environment without translation. |

#### Rule Group

Rule groups will automatically be included in a recovery point, if a web ACL using that rule group is in the recovery point.

| **Attribute** | **Translation** |
| --- | --- |
| Rules | ARNs in rules that refer to IP sets, and regex pattern sets are translated for the recovery environment. |
| Capacity CustomResponseBodies Description Name Scope VisibilityConfig | These attributes are replicated to your recovery environment without translation. |

#### IP Set

IP sets will automatically be included in a recovery point, if a rule group, or web ACL using that IP set is in the recovery point.

Arpio replicates IP sets as-is, no attributes are translated in the recovery environment.

#### Regex Pattern Set

Regex pattern sets will automatically be included in a recovery point, if a rule group, or web ACL using that IP set is in the recovery point.

Arpio replicates regex pattern sets as-is, no attributes are translated in the recovery environment.

### Managed Rule Groups

#### AWS Managed Rule Groups

If your web ACL uses an AWS managed rule group, your configuration will be replicated to the recovery environment. There is an extra cost for managed rule groups, but you will only be charged when your application is in the failover or test failover states.

#### Marketplace Managed Rule Groups

If your web ACL uses managed rule groups from the AWS Marketplace, and your recovery environment uses a separate AWS account from your primary environment, then you will need to purchase a subscription in the recovery account. Once you have purchased that subscription, Arpio will automatically replicate your configuration to the recovery environment.

- [Getting Started](https://docs.arpio.io/getting-started?hsLang=en#main-content)

    - [New Account Setup](https://docs.arpio.io/getting-started?hsLang=en#new-account-setup)
    - [New Application Setup](https://docs.arpio.io/getting-started?hsLang=en#new-application-setup)
- [Arpio Fundamentals](https://docs.arpio.io/arpio-fundamentals?hsLang=en#main-content)

    - [Platform Fundamentals](https://docs.arpio.io/arpio-fundamentals?hsLang=en#platform-fundamentals)
    - [Platform Features](https://docs.arpio.io/arpio-fundamentals?hsLang=en#platform-features)
- [Arpio Reference Guides](https://docs.arpio.io/arpio-reference-guides?hsLang=en#main-content)

    - [Arpio API](https://docs.arpio.io/arpio-reference-guides?hsLang=en#arpio-api)
    - [Lifecycle Events](https://docs.arpio.io/arpio-reference-guides?hsLang=en#lifecycle-events)
    - [Role-Based Access Controls (RBAC)](https://docs.arpio.io/arpio-reference-guides?hsLang=en#role-based-access-controls-rbac)
    - [Single Sign-On (SSO) Integration](https://docs.arpio.io/arpio-reference-guides?hsLang=en#single-sign-on-sso-integration)
    - [Test Planning](https://docs.arpio.io/arpio-reference-guides?hsLang=en#test-planning)
    - [Test & Recovery How-To](https://docs.arpio.io/arpio-reference-guides?hsLang=en#test-recovery-how-to)
- [AWS Reference Guides](https://docs.arpio.io/aws-reference-guides?hsLang=en#main-content)

    - [AWS Resource Reference](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-resource-reference)
    - [AWS Configuration Tags](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-configuration-tags)
    - [AWS Access](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-access)
    - [AWS Testing](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-testing)
    - [AWS Solutions](https://docs.arpio.io/aws-reference-guides?hsLang=en#aws-solutions)
- [Azure Reference Guides](https://docs.arpio.io/azure-reference-guides?hsLang=en#main-content)

    - [Azure Resource Reference](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-resource-reference)
    - [Azure Configuration Tags](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-configuration-tags)
    - [Azure Scenarios](https://docs.arpio.io/azure-reference-guides?hsLang=en#azure-scenarios)
- [FAQ](https://docs.arpio.io/faq?hsLang=en#main-content)

    - [AWS FAQ](https://docs.arpio.io/faq?hsLang=en#aws-faq)
    - [Contact Support](https://docs.arpio.io/faq?hsLang=en#contact-support)
    - [License & Billing](https://docs.arpio.io/faq?hsLang=en#license-billing)
    - [Tests and Recoveries](https://docs.arpio.io/faq?hsLang=en#tests-and-recoveries)

- Home
- Products
- Pricing
- Blog
- Company

[![bubble-wand-tight.64](https://docs.arpio.io/hs-fs/hubfs/bubble-wand-tight.64.png?width=64&height=64&name=bubble-wand-tight.64.png "bubble-wand-tight.64")](https://arpio.io)

Copyright © 2026, Arpio