Optional Readonlydestination(OPTIONAL) An array of Network Firewall stateless port range configurations.
Optional Readonlydestinations(OPTIONAL) An array of destination CIDR ranges to inspect for.
Optional Readonlyprotocols(OPTIONAL) An array of IP protocol numbers to inspect for.
Optional Readonlysource(OPTIONAL) An array of Network Firewall stateless port range configurations.
Optional Readonlysources(OPTIONAL) An array of source CIDR ranges to inspect for.
Optional Readonlytcp(OPTIONAL) An array of Network Firewall stateless TCP flag configurations.
NetworkConfig / CentralNetworkServicesConfig / NfwConfig / NfwRuleGroupConfig / NfwRuleGroupRuleConfig / NfwRuleSourceConfig / NfwStatelessRulesAndCustomActionsConfig / NfwRuleSourceStatelessRuleConfig / NfwRuleSourceStatelessRuleDefinitionConfig / NfwRuleSourceStatelessMatchAttributesConfig
Network Firewall stateless rule match attributes configuration.
Description
Use this configuration to define stateless rule match attributes for Network Firewall. To be a match, a packet must satisfy all of the match settings in the rule.
See
https://docs.aws.amazon.com/AWSCloudFormation/latest/UserGuide/aws-properties-networkfirewall-rulegroup-matchattributes.html
Example