Using WAF to Protect OBS Buckets Where CDN Content Is Stored
Application Scenarios
If you have enabled Content Delivery Network (CDN) for website domain name acceleration and the content is stored in an Object Storage Service (OBS) bucket, you can deploy the combination of CDN, OBS, and WAF to prevent possible website attacks against the OBS buckets. This topic describes how to deploy CDN, OBS, and WAF for services at the same time.
If you add domain names to CDN for content acceleration and use DNS to route requests destined for the domain names to an OBS bucket, the bucket domain name becomes the origin server address. You can refer to this practice to configure WAF protection. For details about CDN, see Adding Domain Names to CDN for Content Acceleration.
Solution Architecture and Advantages
CDN can effectively accelerate websites, WAF can block malicious website traffic, and OBS buckets can store large volumes of files. Data is stored in OBS buckets, CDN accelerates data access, and WAF filters out malicious requests. This setup reduces costs while enhancing OBS data security.

Resource and Cost Planning
| Resource | Description | Monthly Fee |
|---|---|---|
| OBS buckets |
| For details about billing rules, see Billing Description. |
| CDN |
| For details about billing rules, see Billing Description. |
| WAF | Cloud mode - standard edition:
| For details about pricing rules, see Billing Description. |
Constraints
- This method only applies to domain names connected to cloud WAF through CNAME records.
- In this scenario, WAF can protect only dynamic website content and small static resource files. Therefore, if OBS stores large files (greater than 100 MB), using cloud WAF for protection is not recommended.
Step 1: Buy the Standard Edition Cloud WAF
- Log in to the WAF console.
- In the upper right corner of the page, click Buy WAF. On the purchase page displayed, select Cloud Mode for WAF Mode.
- Region: Select the region nearest to your services WAF will protect.
- Edition: Select Standard.
- Expansion Package and Required Duration: Set them based on site requirements.
- Confirm the product details and click Buy Now in the lower right corner of the page.
- Check the order details and read the WAF Disclaimer. Then, select the box and click Pay Now.
- On the payment page, select a payment method and pay for your order.
After the order is paid, click Access Console to go to the Dashboard page. Hover over the Product Details area to view the purchased instance edition and its specifications.
Step 2: Bind a CDN Acceleration Domain Name to OBS
- Log in to the OBS console.
- Click
in the upper left corner and select a region or project. - In the navigation pane on the left, choose Buckets. On the displayed page, click the name of the target bucket.
- In the navigation pane, choose Domain Name Mgmt.
- Click Configure Acceleration Domain Name. In the Origin Server row, copy the bucket domain name.
Acceleration: Enter the domain name to be accelerated with CDN.
For details about other parameters, see Configuring an Acceleration Domain Name.
After the domain name is bound, you can enter the domain name and any file name in the OBS bucket in the address box of the browser (for example, <Protected domain name >/test.png, where test.png is the name of the image uploaded to the OBS bucket). If the website can be accessed, the domain name is added successfully.
Step 3: Connect the Domain Name to WAF and Set Origin Server Address to the OBS Domain Name
To use WAF to protect OBS buckets, you need to connect the bucket domain name accelerated by CDN to WAF. The origin server address is the OBS bucket domain name.
- Log in to the WAF console.
- In the navigation pane on the left, choose Access Management.
- On the Access Management page, click the Cloud CNAME tab and click Add Website.
If only one access mode is enabled, click Add Website.
- On the displayed page, configure key parameters by referring to Table 2. For details about how to configure other parameters, see Connecting Your Website to WAF with Cloud Mode - CNAME Access.
Table 2 Parameter description Parameter
Description
Domain Name
Enter the domain name bound to OBS in Step 2: Bind a CDN Acceleration Domain Name to OBS.
Protected Port
Enter the port through which the website service traffic goes.
Server Configuration
- Client Protocol: protocol used by a client to access a server. The options are HTTP and HTTPS.
- Server Protocol: protocol used by WAF to forward client requests. The options are HTTP and HTTPS.
- Server Address: Enter the public IP address or origin server domain name of the website. This address is used to receive normal service requests forwarded by WAF. Set this parameter to OBS bucket domain name.
You can also copy the OBS bucket domain name in the Domain Name column on the OBS Summary page.
- Server Port: service port over which the WAF instance forwards client requests to the origin server.
- Click Next and complete the basic information about the website to be protected. Perform the following operations as prompted on the Add Website page: Figure 1 Domain name added to WAF
After the preceding steps are complete, you can check the Access Status of the added domain name in the domain name list. The Access Status of the domain name is Inaccessible at first. You need to modify the DNS record.
- Click Step 3: Change the back-to-source address of the proxy and copy the WAF CNAME record. Figure 2 Copying a WAF CNAME record
Step 4: Changing the Origin Server Address in CDN to the WAF CNAME Record
- Go to the Public Zones page.
- In the navigation pane on the left, choose Domains.
- In the domain list, click the target domain name or click Configure in the Operation column.
- Click the Basic Settings tab. In the Origin Server Settings area, click Edit.
In the Address text box, enter the WAF CNAME record copied in Step 6.
Operation Result Verification
After the configuration is complete, you can enter the added domain name and any file name in the OBS bucket in the address box of the browser (for example, <Protected domain name >/test.png, where test.png is the name of the image uploaded to OBS). If the website can be accessed, the domain name has been added successfully.
You can also enter the added domain name and web attack code in the address box of the browser (for example, curl -kv <Protected domain name >?name='1%20or %201=1'). If the 418 blocking page is displayed, the attack is blocked, WAF protection was successful.
Follow-up Operations
After the preceding configuration is complete, WAF enables the basic web protection rule for the domain name by default. By identifying and detecting the characteristics of requests for accessing the domain name, WAF forwards normal access requests to OBS private buckets for security protection. You can enable more protection rules if needed. For details, see Protection Policy Configuration.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot