
AWS Security Agent のペネトレーションテストで許可すべきアクセス元を教えてください
困っていた内容
AWS Security Agent のペネトレーションテストを実施したいです。
テスト対象にある WAF がテストリクエストをブロックするため、許可リストに追加すべき情報を教えてください
どう対応すればいいの?
User-Agent のsecurityagentを許可するか、独自の HTTP ヘッダーを設定してください
Troubleshooting - AWS Security Agent (now part of AWS Continuum)
- If you have a WAF configured, check that you WAF is not blocking penetration test traffic. You can allowlist penetration test traffic by User-Agent header, which will be set to securityagent by default
AWS Security Agent のリクエストは、カスタム HTTP ヘッダー設定で上書きしない限り、User-Agent: securityagentを含みます。
そのため、WAF などでアクセス制限をしている場合は、デフォルトで設定される User-Agent ヘッダーのsecurityagentを許可するか、AWS Security Agent のカスタム HTTP ヘッダー設定で独自の HTTP ヘッダーを設定し、その値を許可してください。
なお、IP アドレスベースで許可が必要な場合、NAT ゲートウェイを設定した VPC を設定し、NAT ゲートウェイに関連付けられた IP アドレスを許可してください。
Tip
When testing against an endpoint that has an IP allowlist, you can add a private VPC configuration with an associated VPC NAT Gateway to your penetration test. You can then use the NAT Gateway IP address to allowlist outbound traffic from the penetration test.
参考資料
By default, AWS Security Agent adds a custom header for User-Agent set to securityagent unless a different custom User-Agent header value is specified.
Penetration test failed due to an IP allowlist
If the endpoint that a penetration test targets has an IP allowlist enabled, you can add a private VPC configuration with an associated VPC NAT Gateway to your penetration test. You can then use the NAT Gateway IP address to allowlist outbound traffic from the penetration test.










