Configuring a Traffic Identifier for a Known Attack Source
EdgeSec allows you to configure traffic identifiers by session, server IP address, or user tag to block possibly malicious requests from known attack sources based on Cookie, IP address, or Params.

If you have enabled enterprise projects, ensure that you have all operation permissions for the project where your Edge WAF instance locates. Then, you can select the project from the Enterprise Project drop-down list and configure known attack source traffic identifiers for the domain names.
Prerequisites
A protected website has been added. For details, see Adding a Website to EdgeSec.
Constraints
- If the IP address tag is not configured, EdgeSec identifies the client IP address by default.
- Before enabling Cookie- or Params-based known attack source rules, configure a session or user tag for the corresponding website domain name.
Procedure
- Log in to the management console.
- Click
in the upper left corner of the page and choose .
- In the navigation pane on the left, choose Website Settings page is displayed. . The
- In the Domain Name column, click the domain name of the website to go to the basic information page.
- In the Traffic Identifier area, click
next to IP Tag, Session Tag, or User Tag to configure a traffic identifier by referring to Table 1.
Figure 1 Traffic IdentifierTable 1 Traffic identifier parameters Identifier
Description
Example Value
IP Tag
HTTP request header field of the original client IP address.
This field is used to obtain the real IP address of the client. You can customize the field name and configure multiple fields (separated by commas). After the configuration, EdgeSec preferentially reads the configured field to obtain the real IP address of the client. If multiple fields are configured, EdgeSec reads the IP address from left to right.
CAUTION:- $remote_addr cannot be configured. EdgeSec uses the TCP connection IP address as the client IP address by default.
- If the real IP address of the client is not obtained from the user-defined field, EdgeSec uses the source IP address used to establish a TCP connection with CDN as the client IP address by default.
X-Forwarded-For
Session Tag
This tag is used to block possibly malicious requests based on the cookie attributes of an attack source. Configure this parameter to block requests based on cookie attributes.
jssessionid
User Tag
This tag is used to block possibly malicious requests based on the Params attribute of an attack source. Configure this parameter to block requests based on the Params attributes.
name
- Click Confirm.
Other Operations
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot