Updated on 2026-07-27 GMT+08:00

Configuring an Allowlist

You can configure an allowlist for API data security protection. The access that matches the whitelist policy is allowed, and the risk level of the access is marked as trusted.

Networking Requirements

Figure 1 shows the networking configuration of API data security protection.

Figure 1 Reverse proxy networking
Table 1 Networking description

Device

Description

Client PC

IP address: 172.16.212.65

API Data Security Protection

IP address: 172.16.35.44

Application Server

IP address: 172.16.35.53

Configuring an Allowlist

Before configuring an allowlist, ensure that you have added application assets. For details, see Adding a Proxy Application. Ensure that no rules that conflict with the allowlist are enabled. Figure 2 shows the process of configuring an allowlist.

Figure 2 Configuring an allowlist
  1. Log in to the API data security protection web console as user sysadmin.
  2. In the navigation pane on the left, choose Security Policies > Allowlist.
  3. Click Add in the upper right corner.
  4. In the Add Rule dialog box, configure the allowlist, as shown in Figure 2.
  5. After the configuration is complete, click OK to save the allowlist.

Verifying an Allowlist

  1. Enter the proxy connection IP address and port (172.16.35.44:8182) of the application in the address box of the browser as the client IP address 172.16.212.65.
  2. Log in to the API data security protection web console as user sysadmin.
  3. In the navigation pane on the left, choose Log Management > Retrieval.
  4. If a corresponding access record is displayed and the access risk level is marked as Trusted, the whitelist configuration takes effect.