Using WAF, ELB, and NAT Gateway to Protect On-Premises Services
Application Scenarios
By default, with cloud load balancer access mode, WAF can protect only workloads deployed on Huawei Cloud. If your origin servers are deployed on-premises, but you want to use WAF in this mode, you can use Network Address Translation (NAT) gateways to route traffic from Huawei Cloud to the public IP addresses of your origin server. Then, you can connect your website to WAF in cloud load balancer access mode to let WAF check your website traffic.
Architecture
Resource and Cost Planning
| Resource | Description | Monthly Fee |
|---|---|---|
| Elastic Load Balance (ELB) |
| For details about billing rules, see Billing Description. |
| NAT Gateway |
| For details about billing rules, see Billing. |
| Web Application Firewall (WAF) | Cloud mode - standard edition:
| For details about pricing rules, see Billing Description. |
Step 1: Create a Dedicated Load Balancer
- Go to the Buy Elastic Load Balancer page.
- Click Buy Elastic Load Balancer.
- Select the basic configuration for the load balancer as prompted.
- Type: Select Dedicated load balancer.
- Specifications: Select Application load balancing (HTTP/HTTPS) .
- Other parameters: Set them based on your service requirements.
- Configure the network as prompted.
- IP as a Backend: Toggle it on (
). - Frontend Subnet: Select the subnet for your load balancer to use the IP addresses in this subnet to receive requests.
- Backend Subnet: Select the subnet for your load balancer to use IP addresses in this subnet to establish connections with backend servers. You need to select a backend subnet that is different from the frontend subnet.
If the frontend subnet is the same as the backend one, NAT Gateway will get confused.
- Other parameters: Set them based on your service requirements.
- IP as a Backend: Toggle it on (
For details about how to create a dedicated load balancer, see Creating a Dedicated Load Balancer.
- Select the basic configuration for the load balancer as prompted.
- Click Next.
- Confirm the configuration details and complete the creation as prompted.
After the configuration is complete, you can check the created load balancer in the load balancer list. The instance has Status set to Running, Type to Dedicated, and Specifications to Application.
Step 2: Configure a Listener for the Load Balancer You Created
- Click the name of the target load balancer in the Name/ID column.
- Click the Listeners tab, click Add Listener, and configure the listener name, frontend protocol, and port.
- Click Next: Configure Request Routing Policy.
- Click Next: Add Backend Server. Then, click the IP as Backend Servers tab.
- Click Add IP as Backend Server. In the displayed dialog box, configure IP Address and Backend Port.
- IP Address: Enter the IP address of your origin server.
- Backend Port: Enter the port number.
- Click OK.
- Click Next: Confirm, confirm the information, and click Submit.
After the configuration is complete, you can check the configured frontend protocol and port in the Listener column of the target load balancer.
Step 3: Configure a NAT Gateway
- Buy a public NAT gateway.
- Go to the Buy Public NAT Gateway page.
- Subnet: Select the one you configured as the backend subnet in 2.b.
- Other parameters: Set them to meet your service requirements.
- Click Next and confirm the public NAT gateway specifications on the displayed page.
- Confirm the details and click Submit.
You can view the NAT gateway you purchased in the NAT gateway list. It takes 1 to 6 minutes to create a public NAT gateway.
- Go to the Buy Public NAT Gateway page.
- Add an SNAT rule.
- On the displayed page, click the name of the public NAT gateway on which you need to add an SNAT rule.
- On the SNAT Rules tab, click Add SNAT Rule.
Subnet: Select the one you configured as the backend subnet in 2.b.
- Click OK.
After the configuration is complete, you can view the added rule on the SNAT Rules tab.
Step 4: Add Website Domain Names to WAF in Cloud Load Balancer Access Mode
- Buy the standard edition cloud WAF.
- Log in to the WAF console.
- In the upper right corner of the page, click Buy WAF. On the purchase page displayed, select Cloud Mode for WAF Mode.
- Region: Select the region nearest to your services WAF will protect.
- Edition: Select Standard.
- Expansion Package and Required Duration: Set them based on site requirements.
- Confirm the product details and click Buy Now in the lower right corner of the page.
- Check the order details and read the WAF Disclaimer. Then, select the box and click Pay Now.
- On the payment page, select a payment method and pay for your order.
After the order is paid, click Access Console to go to the Dashboard page. Hover over the Product Details area to view the purchased instance edition and its specifications.
- Add the domain name to WAF in cloud load balancer access mode.
- In the navigation pane on the left, choose Access Management.
- On the Access Management page, click the Cloud Load Balancer tab and complete the access configuration.
If only one access mode is enabled, complete the access configuration on the Access Management page.
- Connecting a single one
- Click the number next to Inaccessible, locate the target load balancer, and click Connect in the Operation column.
You can also select a load balancer configured with a listener and click Connect.
If the Connect button is grayed out, no listener is configured for the load balancer. Add a listener to the load balancer and then configure the access.
- On the displayed Connect Domain Name to Load Balancer pane, configure the access and click OK. Table 2 describes the parameters.
- Click the number next to Inaccessible, locate the target load balancer, and click Connect in the Operation column.
- One-click batch access
- Select at least one load balancer configured with a listener and click Connect.
You can add multiple protected domain names to an accessible load balancer.
- On the displayed Connect pane, configure the access and click OK. Table 2 describes the parameters.
- Select at least one load balancer configured with a listener and click Connect.
Table 2 Access configuration parameters Parameter
Description
Example Value
Protection Policy
Select the protection policy you want to use for the website.
One-click batch access allows you to use the same protection policy or different policies for multiple load balancers quickly.
- Use the same policy: Select this option if you want to use the same protection policy for all load balancers that are connected to WAF in one-click mode.
- Use different policies: Select a protection policy for each load balancer.
In either way, you can select system-generated policies or custom policies you created.- System-generated policy (default) includes:
- Basic Web Protection: General Check is enabled by default. It can defend against attacks such as SQL injections, XSS, remote overflow attacks, file inclusions, Bash vulnerability exploits, remote command execution, directory traversal, sensitive file access, and command/code injections.
General Check includes:
- Rule Set: Default rule set (medium) is selected.
- Protective Action: Log only is selected. It means WAF only logs detected attacks but does not block them.
- Anti-Crawler: Scanner detection is enabled by default, and Protective Action is set to Log only. WAF only logs detected attacks but does not block them. This type of detection can defend against web scans, such as vulnerability and virus scanning, and crawler behaviors from tools like OpenVAS and Nmap.
- Basic Web Protection: General Check is enabled by default. It can defend against attacks such as SQL injections, XSS, remote overflow attacks, file inclusions, Bash vulnerability exploits, remote command execution, directory traversal, sensitive file access, and command/code injections.
- A protection policy created manually: a custom policy you create based on your security requirements. Only the standard, professional, and enterprise editions support manually created protection policies. For more information, see Configuring Protection Policies.
Use the same policy > System-generated policy
Connection Configuration
Configure access information.
- Protected Domain Name: Set this parameter to the domain name or IP address (public or private IP address) you want to protect. Make sure that the domain name has been resolved to the EIP of the created load balancer.
- Domain Name: Single domain names or wildcard domain names are supported.
Single domain name: Enter a single domain name, for example, www.example.com.
Wildcard domain name:- If the server IP address of each subdomain name is the same, enter a wildcard domain name. For example, if the subdomain names a.example.com, b.example.com, and c.example.com have the same server IP address, you can add the wildcard domain name *.example.com to WAF to protect all three.
- If the server IP addresses of subdomain names are different, add subdomain names as single domain names one by one.
- Wildcard domain name * can be added.
- In ELB load balancer access mode, one load balancer supports only one wildcard domain name.
- IP: You can select a public or private IP address. If a private IP address is used, ensure that the corresponding network path is accessible so that WAF can correctly monitor and filter traffic.
- Domain Name: Single domain names or wildcard domain names are supported.
- ELB Listener: Select the listener configured for the ELB load balancer. You can select an ELB listener of another account.
- All listeners: Select all listeners under the ELB load balancer.
- Specific listener: Select a specific listener under the ELB load balancer.
- Policy: If you select User different policies for Protection Policy, you need to select a protection policy for each load balancer.
Protected Domain Name: *
ELB Listener: All listeners
After the access is complete, click the number next to Accessible to view the load balancers that have been connected to WAF.
- Connecting a single one
Operation Result Verification
If General Check is enabled and Mode is set to Block for your domain name www.example.com, take the following steps to verify the protection effect:
- Clear the browser cache and enter the domain name in the address bar to check whether the website is accessible.
- If the website is inaccessible, connect the website domain name to WAF by referring to Step 1: Create a Dedicated Load Balancer to Step 4: Add Website Domain Names to WAF in Cloud Load Balancer Access Mode.
- If the website is accessible, go to Step 2.
- Clear the browser cache and enter http://www.example.com?id=1%27%20or%201=1 in the address box of the browser to simulate an SQL injection attack.
WAF blocks the access request. Figure 2 shows an example block page.
- Return to the WAF console. In the navigation pane, choose Events. On the displayed page, view the event log.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
