AWS Security Agent のペネトレーションテストで許可すべきアクセス元を教えてください

AWS Security Agent のペネトレーションテストで許可すべきアクセス元を教えてください

AWS Security Agent のペネトレーションテストで WAF にブロックされる場合の対策方法について、User-Agent ヘッダーの許可設定と IP ホワイトリストの構成方法を紹介します。
2026.10.02

困っていた内容

AWS Security Agent のペネトレーションテストを実施したいです。
テスト対象にある WAF がテストリクエストをブロックするため、許可リストに追加すべき情報を教えてください

どう対応すればいいの?

User-Agent のsecurityagentを許可するか、独自の HTTP ヘッダーを設定してください

Troubleshooting - AWS Security Agent (now part of AWS Continuum)

  • If you have a WAF configured, check that you WAF is not blocking penetration test traffic. You can allowlist penetration test traffic by User-Agent header, which will be set to securityagent by default

AWS Security Agent のリクエストは、カスタム HTTP ヘッダー設定で上書きしない限り、User-Agent: securityagentを含みます。

そのため、WAF などでアクセス制限をしている場合は、デフォルトで設定される User-Agent ヘッダーのsecurityagentを許可するか、AWS Security Agent のカスタム HTTP ヘッダー設定で独自の HTTP ヘッダーを設定し、その値を許可してください。

なお、IP アドレスベースで許可が必要な場合、NAT ゲートウェイを設定した VPC を設定し、NAT ゲートウェイに関連付けられた IP アドレスを許可してください。

https://docs.aws.amazon.com/securityagent/latest/userguide/connect-agent-vpc.html

Tip
When testing against an endpoint that has an IP allowlist, you can add a private VPC configuration with an associated VPC NAT Gateway to your penetration test. You can then use the NAT Gateway IP address to allowlist outbound traffic from the penetration test.

参考資料

By default, AWS Security Agent adds a custom header for User-Agent set to securityagent unless a different custom User-Agent header value is specified.

Penetration test failed due to an IP allowlist

If the endpoint that a penetration test targets has an IP allowlist enabled, you can add a private VPC configuration with an associated VPC NAT Gateway to your penetration test. You can then use the NAT Gateway IP address to allowlist outbound traffic from the penetration test.


AWSテクニカルサポートノートについて

過去にクラスメソッドのAWS総合支援サービスで頂いたお問合せの中から、通常のAWS利用時でも有益になりうる情報をテクニカルサポートチームがTIPSとしてご紹介しています。技術サポートは、無料でご提供しております。詳細は下記ボタンからご覧ください。

クラスメソッドのAWSサポートの詳細を見る

この記事をシェアする

AWSのお困り事はクラスメソッドへ

関連記事