Configuring an Allowlist
You can configure an allowlist for API data security protection. The access that matches the whitelist policy is allowed, and the risk level of the access is marked as trusted.
Scenarios
In an enterprise's internal system, some API callers are considered trusted sources. For example, the internal O&M monitoring platform periodically calls the health check APIs, the CI/CD pipeline automatically calls the deployment APIs, and authorized partners call the data sharing APIs through private lines. These requests feature high frequency and fixed sources. If complete security rule verification and masking are performed each time, the API response delay increases and system resources are consumed. By configuring an allowlist policy, you can add trusted IP address segments, internal service accounts, or APIs of authorized partners to the allowlist. Requests that match the allowlist are directly allowed and marked as trusted, skipping the risk prevention and masking process. This ensures security control precision and improves the processing efficiency of high-frequency trusted traffic.
Prerequisites
You have added an application asset.
Configuring an Allowlist
- Log in to the API data security protection web console as user sysadmin.
- In the navigation pane on the left, choose Security Policies > Allowlist.
- Click Add in the upper right corner.
- In the Add Rule dialog box, configure the allowlist, as shown in Figure 1.
- After the configuration is complete, click OK to save the allowlist.
Verifying an Allowlist
- Enter the proxy connection IP address and port (172.16.35.44:8182) of the application in the address box of the browser as the client IP address 172.16.212.65.
- Log in to the API data security protection web console as user sysadmin.
- In the navigation pane on the left, choose Log Management > Retrieval.
- If a corresponding access record is displayed and the access risk level is marked as Trusted, the whitelist configuration takes effect.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
