Updated on 2025-07-04 GMT+08:00

Policy Configuration

Description

By default, System-generated policy is selected for Policy. You can also select a custom policy.

If you are using WAF standard edition, only System-generated policy can be selected.

Table 1 System-generated policies

Edition

Protection Policy

Standard

Basic web protection (Log only mode and General Check)

The basic web protection defends against attacks such as SQL injections, XSS, remote overflow vulnerabilities, file inclusions, Bash vulnerabilities, remote command execution, directory traversal, sensitive file access, and command/code injections.

Professional and enterprise editions

Basic web protection (Log only mode and General Check)

The basic web protection defends against attacks such as SQL injections, XSS, remote overflow vulnerabilities, file inclusions, Bash vulnerabilities, remote command execution, directory traversal, sensitive file access, and command/code injections.

Anti-crawler (Log only mode and Scanner feature)

WAF only logs web scanning tasks, such as vulnerability scanning, virus scanning, and crawling behavior of OpenVAS and Nmap.

FAQs