Connecting a Website to WAF (Cloud Mode - CNAME Access)
After purchasing cloud WAF, you need to add the domain name you want to protect to WAF so that the website traffic can go to WAF. WAF detects and filters out attack traffic and forwards normal traffic to the origin server IP address. In this way, WAF keeps the origin server IP address secure, stable, and available.
Before adding a domain name to WAF, check whether the domain name uses a proxy, such as CDN and advanced anti-DDoS services.
No proxy used
No proxies used between the client and WAF
- If your website is not connected to WAF, DNS resolves your domain name to the origin server IP address. So, web visitors can directly access the origin server.
- If your website is connected to WAF, DNS resolves your domain name to the CNAME record of WAF. In this way, the traffic passes through WAF. WAF then filters out illegitimate traffic and routes only legitimate traffic to the origin server.
Proxy used
Proxies used between the client and WAF
- If your website is not connected to WAF, DNS resolves the domain name to the proxy IP address. Then, the proxy routes the traffic back to the origin server.
- After your website is connected to WAF, DNS resolves your domain name to the access address of WAF. In this way, the proxy forwards the traffic to WAF. WAF then filters out illegitimate traffic and routes only legitimate traffic to the origin server.
Flowchart of adding a domain name to cloud WAF
Only the domain names that have been registered with ICP licenses can be added to WAF.
- In the navigation pane on the left, choose Website Settings.
- Click Add Website.
- Select Cloud - CNAME and click Configure Now.
If your domain name is hosted on Huawei Cloud DNS, you can click Quick Add Domain Names Hosted on Cloud to quickly add the domain name to WAF.
You can enter a multi-level single domain name (for example, top-level domain name example.com or second-level domain name www.example.com) or a wildcard domain name (*.example.com).
If the server IP address of each subdomain name is the same, enter a wildcard domain name. For example, if the subdomain names a.example.com, b.example.com, and c.example.com have the same server IP address, you can add the wildcard domain name *.example.com to WAF to protect all three.
- Connecting a Website to WAF. Perform the following steps to add a domain name to WAF:
- Add a domain name to WAF.
- Whitelist back-to-source IP addresses of WAF.
After you connect your website to WAF, uninstall other security software from the origin server or allow only the requests from WAF to access your origin server. This ensures normal access while protecting origin servers from attacks.
- Test the connectivity between WAF and your origin server. Make sure WAF can forward received requests to the origin server.
To ensure that WAF can properly forward requests, perform local verification before modifying the DNS configuration.
- Modify DNS resolution record for the website domain name.
Scenario
Parameter Generated
Operation Related to Domain Name Resolution
No proxies used
CNAME
DNS resolves the domain name to the WAF CNAME record.
Proxy used
CNAME, subdomain name, and TXT record
- Change the back-to-source IP address of the proxy such as CDN or anti-DDoS to the WAF CNAME record.
- (Optional) Add a WAF subdomain name and TXT record at your DNS provider.
- Verify that the domain name has been connected to WAF.
If the Access Status of the domain name is Accessible, the domain name has been connected to WAF, and WAF starts protecting it. After a domain name is connected to WAF, WAF automatically enables protection.
WAF automatically checks the access status of protected websites every hour. If WAF confirms that a protected website has received 20 access requests within 5 minutes, it considers that the website has been successfully connected to WAF.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot