import type { MetadataBearer as __MetadataBearer } from "@smithy/types"; import type { CreateRateBasedRuleRequest, CreateRateBasedRuleResponse } from "../models/models_0"; /** * @public */ export type { __MetadataBearer }; /** * @public * * The input for {@link CreateRateBasedRuleCommand}. */ export interface CreateRateBasedRuleCommandInput extends CreateRateBasedRuleRequest { } /** * @public * * The output of {@link CreateRateBasedRuleCommand}. */ export interface CreateRateBasedRuleCommandOutput extends CreateRateBasedRuleResponse, __MetadataBearer { } declare const CreateRateBasedRuleCommand_base: { new (input: CreateRateBasedRuleCommandInput): import("@smithy/core/client").CommandImpl; new (input: CreateRateBasedRuleCommandInput): import("@smithy/core/client").CommandImpl; getEndpointParameterInstructions(): import("@smithy/types").EndpointParameterInstructions; }; /** * *

This is AWS WAF Classic documentation. For * more information, see AWS * WAF Classic in the developer guide.

*

* For the latest version of AWS * WAF, use the AWS WAFV2 API and see the AWS WAF Developer Guide. With the latest version, AWS WAF has a single set of endpoints for regional and global use.

*
*

Creates a RateBasedRule. The RateBasedRule contains a * RateLimit, which specifies the maximum number of requests that AWS WAF allows * from a specified IP address in a five-minute period. * The RateBasedRule also * contains the IPSet objects, ByteMatchSet objects, and other * predicates that identify the requests that you want to count or block if these requests * exceed the RateLimit.

*

If you add more than one predicate to a RateBasedRule, a request not * only must exceed the RateLimit, but it also must match all the * conditions to be counted or blocked. For example, suppose you add the following to a * RateBasedRule:

* *

Further, you specify a RateLimit of 1,000.

*

You then add the RateBasedRule to a WebACL and specify that * you want to block requests that meet the conditions in the rule. For a request to be * blocked, it must come from the IP address 192.0.2.44 and the * User-Agent header in the request must contain the value * BadBot. Further, requests that match these two conditions must be received at * a rate of more than 1,000 requests every five minutes. If both conditions are met and the * rate is exceeded, AWS WAF blocks the requests. If the rate drops below 1,000 for a * five-minute period, AWS WAF no longer blocks the requests.

* *

As a second example, suppose you want to limit requests to a particular page on your site. To do this, you could add the following to a * RateBasedRule:

* * * *

Further, you specify a RateLimit of 1,000.

*

By adding this RateBasedRule to a WebACL, you could limit requests to your login page without affecting the rest of your site.

* * *

To create and configure a RateBasedRule, perform the following * steps:

*
    *
  1. *

    Create and update the predicates that you want to include in the rule. For more * information, see CreateByteMatchSet, CreateIPSet, * and CreateSqlInjectionMatchSet.

    *
  2. *
  3. *

    Use GetChangeToken to get the change token that you provide * in the ChangeToken parameter of a CreateRule * request.

    *
  4. *
  5. *

    Submit a CreateRateBasedRule request.

    *
  6. *
  7. *

    Use GetChangeToken to get the change token that you provide in the * ChangeToken parameter of an UpdateRule * request.

    *
  8. *
  9. *

    Submit an UpdateRateBasedRule request to specify the predicates * that you want to include in the rule.

    *
  10. *
  11. *

    Create and update a WebACL that contains the * RateBasedRule. For more information, see CreateWebACL.

    *
  12. *
*

For more information about how to use the AWS WAF API to allow or block HTTP requests, * see the AWS WAF Developer * Guide.

* @example * Use a bare-bones client and the command you need to make an API call. * ```javascript * import { WAFRegionalClient, CreateRateBasedRuleCommand } from "@aws-sdk/client-waf-regional"; // ES Modules import * // const { WAFRegionalClient, CreateRateBasedRuleCommand } = require("@aws-sdk/client-waf-regional"); // CommonJS import * // import type { WAFRegionalClientConfig } from "@aws-sdk/client-waf-regional"; * const config = {}; // type is WAFRegionalClientConfig * const client = new WAFRegionalClient(config); * const input = { // CreateRateBasedRuleRequest * Name: "STRING_VALUE", // required * MetricName: "STRING_VALUE", // required * RateKey: "IP", // required * RateLimit: Number("long"), // required * ChangeToken: "STRING_VALUE", // required * Tags: [ // TagList * { // Tag * Key: "STRING_VALUE", // required * Value: "STRING_VALUE", // required * }, * ], * }; * const command = new CreateRateBasedRuleCommand(input); * const response = await client.send(command); * // { // CreateRateBasedRuleResponse * // Rule: { // RateBasedRule * // RuleId: "STRING_VALUE", // required * // Name: "STRING_VALUE", * // MetricName: "STRING_VALUE", * // MatchPredicates: [ // Predicates // required * // { // Predicate * // Negated: true || false, // required * // Type: "IPMatch" || "ByteMatch" || "SqlInjectionMatch" || "GeoMatch" || "SizeConstraint" || "XssMatch" || "RegexMatch", // required * // DataId: "STRING_VALUE", // required * // }, * // ], * // RateKey: "IP", // required * // RateLimit: Number("long"), // required * // }, * // ChangeToken: "STRING_VALUE", * // }; * * ``` * * @param CreateRateBasedRuleCommandInput - {@link CreateRateBasedRuleCommandInput} * @returns {@link CreateRateBasedRuleCommandOutput} * @see {@link CreateRateBasedRuleCommandInput} for command's `input` shape. * @see {@link CreateRateBasedRuleCommandOutput} for command's `response` shape. * @see {@link WAFRegionalClientResolvedConfig | config} for WAFRegionalClient's `config` shape. * * @throws {@link WAFBadRequestException} (client fault) *

* * @throws {@link WAFDisallowedNameException} (client fault) *

The name specified is invalid.

* * @throws {@link WAFInternalErrorException} (server fault) *

The operation failed because of a system problem, even though the request was valid. Retry your request.

* * @throws {@link WAFInvalidParameterException} (client fault) *

The operation failed because AWS WAF didn't recognize a parameter in the request. For example:

* * * @throws {@link WAFLimitsExceededException} (client fault) *

The operation exceeds a resource limit, for example, the maximum number of WebACL objects that you can create * for an AWS account. For more information, see * Limits in the AWS WAF Developer Guide.

* * @throws {@link WAFStaleDataException} (client fault) *

The operation failed because you tried to create, update, or delete an object by using a change token that has already been used.

* * @throws {@link WAFTagOperationException} (client fault) *

* * @throws {@link WAFTagOperationInternalErrorException} (server fault) *

* * @throws {@link WAFRegionalServiceException} *

Base exception class for all service exceptions from WAFRegional service.

* * * @public */ export declare class CreateRateBasedRuleCommand extends CreateRateBasedRuleCommand_base { /** @internal type navigation helper, not in runtime. */ protected static __types: { api: { input: CreateRateBasedRuleRequest; output: CreateRateBasedRuleResponse; }; sdk: { input: CreateRateBasedRuleCommandInput; output: CreateRateBasedRuleCommandOutput; }; }; }