Stopping WAF from Inserting Cookie Fields
This topic describes how to stop WAF from inserting the HWWAFSESTIME and HWWAFSESID fields into cookies. However, you should exercise caution when enabling this function. If WAF does not insert the HWWAFSESTIME and HWWAFSESID fields into cookies, CC attack protection rules (verification code), known attack source rules, and dynamic anti-crawler rules will be unable to work.
Principles
- HWWAFSESTIME
This field is used to mark the validity period of a WAF session and control the session-level frequency limit in CC attack protection. It prevents attackers from reusing old sessions to bypass the limit.
- HWWAFSESID
This field specifies the unique session ID for user access. It is used to associate consecutive requests from the same user to enable known attack source and dynamic anti-crawler rules.
If this function is enabled, WAF does not insert HWWAFSESTIME or HWWAFSESID into response cookies. The core of the CC CAPTCHA verification, known attack source blocking, and dynamic anti-crawler functions is to identify and track the same access entity. The two cookies are the key for WAF to track session. Without HWWAFSESTIME, WAF will be unable to check whether a session is valid. Without HWWAFSESID, WAF will be unable to distinguish between different visitors. So, if you disable this function, related WAF protection functions are disabled accordingly due to the lack of data support. Exercise caution when enabling this function.
Typical Application Scenarios
| Whether to Enable This Function | Application Scenario | Potential Impact | Decision Point |
|---|---|---|---|
| Yes |
| This is an important security function. If it is disabled, protection capabilities will be downgraded. | If this function is enabled, other protection measures are required, such as enhanced rule configuration. |
| No |
| The response cookie contains the two WAF-specific fields. This does not affect services. | Keep the default setting (disabled) to ensure protection integrity. |
Prerequisites
You have connected your website to WAF. For details, see Access Management.
Procedure
- Log in to the WAF console.
- Click
in the upper left corner and select a region or project. - (Optional) If you have enabled the enterprise project function, in the upper part of the navigation pane on the left, select your enterprise project from the Filter by enterprise project drop-down list. Then, WAF will display the related security data in the enterprise project on the page.
- In the navigation pane on the left, choose .
- On the Protected Objects page, click the target domain name.
- In the Do Not Insert the Cookie Field column, click
to enable the function.
If this function is enabled, the CC attack protection (verification code), known attack source rules, and dynamic anti-crawler rules will be unable to work. Exercise caution when enabling this function.
After the preceding configurations are complete, access the protected website, press F12 to open the developer tool, click the current domain name under Cookie on the Application tab, and check whether the HWWAFSESTIME and HWWAFSESID fields are included.
Related Operations
- If all unnecessary cookies need to be disabled due to compliance requirements, you can add "Cache-Control: no-cache" to the response header in WAF after enabling this function to prevent the browser from caching old cookies.
- If this function is enabled, you are advised to configure CC attack protection rules for IP addresses to limit the access frequency of IP addresses and make up for the protection gap after the CC verification is disabled.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot