status

The lifecycle state of the firewall rule. Possible values:

  • CREATING — DNS Firewall is provisioning the rule. Rules created with the PartnerThreatProtection rule type begin in this state while DNS Firewall verifies the calling account's AWS Marketplace entitlement.

  • COMPLETE — The rule is provisioned and enforcing matches.

  • CREATION_FAILED — Provisioning failed. StatusMessage contains a human-readable reason. A rule in this state is immutable: UpdateFirewallRule rejects the request, and the rule must be removed with DeleteFirewallRule.

For rules that do not require asynchronous provisioning, this field may be absent.