Help Center> Web Application Firewall> FAQs> Service Interruption Check> Why Cannot the Vulnerability Scanning Tool Scan Real Services on My Website Protected with WAF?
Updated on 2024-02-26 GMT+08:00

Why Cannot the Vulnerability Scanning Tool Scan Real Services on My Website Protected with WAF?

After a domain name is connected to cloud WAF with CNAME records, the real services of the website cannot be scanned by vulnerability scanning tools. Only the IP address of WAF can be scanned.

Solutions

Solution 1: On the WAF console, switch the WAF working mode to Bypassed. For details, see Switching WAF Working Mode.

Bypassed: If you enable this, requests are directly sent to backend origin servers without passing through WAF. Before enabling this mode, enable the service port of origin servers to let requests go to origin servers.

Solution 2: Add the website IP address to the vulnerability scanning tool for scanning. Take CodeArts Inspector as an example. You can add website IP addresses to the service.

Service Interruption Check FAQs

more