PuppyIP Resource Center
Development & Networking Tools 5 min Published 2026-10-07

AWS WAF Classic end of support: how to check the October 7 date and regional migration

AWS's official retirement table lists October 7, 2026 as WAF Classic's end-of-support date. First check whether Classic is still in use and read the account's regional AWS Health notices. Conflicting document dates do not establish that every protection stops simultaneously.

AWS WAF Classic AWS WAF End of support Migration AWS Health

Service eligibility and regional restrictions

PuppyIP serves only compliant overseas businesses and their authorized personnel. Proxy services are not available in mainland China. The service may only be used for lawful business activities outside mainland China. Use of this service within mainland China is prohibited.

Hosting a proxy IP or server overseas does not change these restrictions. The service must not be provided to end users in mainland China through relaying, forwarding, sharing or resale. Before use, read the Terms of Service.

Key Takeaways

  • The retirement table lists an October 7, 2025 announcement and October 7, 2026 end of support. Today is not the plan's initial announcement.
  • The migration page still says September 30, 2025, while Classic guidance directs users to regional AWS Health milestones. Public text does not explain the discrepancy.
  • Confirm that rules and web ACLs belong to unmigrated WAF Classic; resource creation year alone is insufficient.
  • Migration generates a new configuration template but does not carry resource associations; logging is off by default. Complete configuration and verify protection after creating the new ACL.

Why does the table say October 7 while another page says 2025?

As checked October 7, 2026, AWS General Reference's sunset table lists WAF Classic's retirement announcement as October 7, 2025 and end of support as October 7, 2026. The table defines these dates as stopping service operations and support.

The official migration page retains September 30, 2025 as end of support. Its top notice and the Classic chapter also say retirement is underway and direct users to AWS Health for regional milestones and dates. These dates conflict, and the public text does not explain why.

The table warrants immediate attention but does not prove every region and resource stops protection at one instant. Account-specific notices, affected regions, and resource state should guide action. Do not treat the old date as a new announcement or infer postponement from a conflict.

Are you using Classic or the current WAF?

Retirement concerns AWS WAF Classic, not the entire WAF product. The current AWS WAF launched in November 2019. Classic documentation is for users with rules, web ACLs, and related resources in the older version that have not migrated.

A web ACL is a collection of request-inspection rules attached to a protected service. Classic can protect CloudFront, Application Load Balancer, and API Gateway entry points. Match rule groups to the actual site or API when inventorying.

Creation year is only a lead. A website created before 2019 may now use current WAF, while a recently redesigned site may still rely on old configuration. Verify the active WAF version and associated web ACL directly.

Match AWS Health dates to the actual resources

An authorized owner should read AWS Health notices for the relevant account, recording service, region, milestone dates, and affected resources, then match them to Classic configuration. No real AWS account was accessed here, so private notices cannot be confirmed on your behalf.

Inventory each Classic ACL's rules, default action, protected resource, and logging. Verify each account and region separately. One regional notice cannot represent all environments, and a successful webpage response does not prove protection rules still work as intended.

If the table, migration page, and account notice cannot be reconciled, ask AWS support with the specific region and resources. Prepare migration in parallel. Without account evidence, the actual shutdown instant remains unknown; do not select a universal date yourself.

What can the migration tool do?

The official procedure reads the Classic ACL and related resources, generates a compatible AWS WAF CloudFormation template, and stores it in S3. Reading and generation do not modify or delete Classic configuration. Deploying, checking, and switching the new configuration remain necessary.

The tool primarily migrates the ACL and resources it uses. Unreferenced rule groups and IP sets need separate handling. It supports migration within the same account, not a cross-account copy strategy.

Resource association is easy to miss: CloudFront and other protected resources are not automatically attached to the new ACL. AWS deliberately avoids affecting production traffic during generation. Arrange the actual switch after checks.

Creating rules is not proof that they protect the site

Migrated logging is off by default. Before switching, configure required logs, check rules and default actions, and verify the new ACL's resource association. Successful template deployment establishes creation, not completed migration.

Hypothetical example: a new CloudFront ACL has the expected rule count, but the distribution still points to the old ACL. The new rules do not yet protect that entry point. This illustrates association checking, not an account fault tested here.

After the documented manual additions and resource switch, observe allowed requests, blocks, and logs against business requirements. Retain configuration and recovery arrangements. Because Classic is retiring, an indefinite ability to switch back cannot be assumed.

What should you do first today?

If every entry point already uses current AWS WAF, retain version and association evidence; no repeat migration is needed solely because Classic appears in the table. If Classic remains, prioritize the regional Health notice, protected resources, and missing configuration for the cloud owner.

Answer which old configuration is active, when the account notice requires action, and how to prove the new ACL took over. Date clarification and preparation can proceed together. A successful page request, template generation, or SDK upgrade cannot replace those answers.

Sources

Frequently Asked Questions

Will AWS Marketplace managed rules migrate too?

AWS says seller-managed Marketplace rules are not carried over. Check corresponding current-WAF rules and subscription conditions and configure them under the migration plan. A matching template rule count does not prove all managed protection survived.

Does the same process handle Firewall Manager rules?

The tool does not handle Firewall Manager-managed rule groups. AWS recommends rebuilding policies for current AWS WAF through Firewall Manager. Identify the management method first to avoid migrating an ACL while omitting central policy.

Can AWS WAF Security Automations be converted directly?

AWS explicitly warns not to use this migration for Security Automations because it does not convert the Lambda functions the automation may use. Check a current-WAF automation solution and plan automation behavior separately from ordinary rules.