AAD and WAF Interworking
Scenarios
This topic describes how to configure DNS resolution to implement interworking between AAD and WAF.
After AD with WAF interworking is enabled, traffic is routed through AAD before being directed to WAF, enabling a coordinated defense mechanism.
When protecting multiple domain names under AAD with the same instance and port, and using WAF CNAME as the origin server, it is important to note that if the origin server IP addresses for these CNAMEs differ and all WAF CNAMEs are bypassed, then all domain names linked to that particular high-defense IP address and port will become inaccessible.
Prerequisites
- You have purchased an AAD instance.
- You have purchased cloud WAF and properly configured the protected domain names.
Constraints
- Joint protection with AAD and WAF is only for domain names.
When configuring the joint protection with AAD and WAF, you need to configure these two domain names separately.
- For a high-defense IP address and port, you can configure only one type of origin server. Once an origin server domain name is set, configuring an additional origin server IP address is not possible.
Procedure
- Obtain the WAF CNAME value.
- Log in to the management console.
- Click in the upper left corner of the management console and select a region or project.
- Click in the upper left corner and choose Web Application Firewall under Security & Compliance.
- In the navigation pane, choose Website Settings.
- On the Domains page, click the target domain name whose CNAME value you want to obtain.
- In the Basic Information area, click for Use Layer-7 Proxy.
Figure 2 Basic information
- In the dialog box that is displayed, select No and click OK.
- On the Basic Information page, copy the CNAME.
Figure 3 Copying the CNAME value
- Add the obtained WAF CNAME value to an AAD instance.
After interworking with WAF is configured, no certificate needs to be uploaded for website services.
- Click in the upper left corner of the page and choose .
- Choose Domain Name Access configuration page is displayed. . The
- Select Chinese mainland or Other.
- Click Add Domain.
- Enter the domain name information and click Next.
Figure 4 Configuring website domain
Table 1 Parameter description Parameter
Description
Protected Domain Name
Enter the domain name of the service to protect. Wildcard domain names are supported, for example, *.domain.com.
Origin Server Type
- Set this parameter to Domain name.
- Enter the forwarding protocol and origin server port of the origin server domain name.
- Enter the copied WAF CNAME.
Server Configuration
Enter the forwarding protocol and port used by the origin server.
- On the Select Instance and Line page, select the required instances and high-defense IP addresses and click Submit and Continue.
Figure 5 Selecting an instance and a line
- Click Next.
- On the Modify DNS Resolution page, copy the CNAME of the AAD and click Finish.
Figure 6 Copying AAD CNAME
- Modify DNS configuration.
- Click in the upper left corner of the page and choose . The Domain Name Service management console is displayed.
- Click Public Zones.
- Locate the row that contains the target domain name, and choose Manage Record Set.
- Click Add Record Set to add a CNAME record set.
Figure 7 Adding a record set
Table 2 Key parameters Parameter
Description
Name
Set this parameter to the domain name configured in AAD.
Record Type
Select CNAME – Map one domain to another.
Line
Select Default.
TTL (s)
TTL is short for time-to-live, which specifies the cache period of resource records on a local DNS server. If your service address is frequently changed, set TTL to a smaller value.
DNS record
Enter the copied AAD CNAME.
DNS resolution takes a period of time. In most cases, domain names can be resolved within 5 minutes.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot