Help Center/ Web Application Firewall/ Help Panel/ Tier-2 Help Panel - Website Settings/ Process of Connecting a Website to WAF (Cloud Mode - CNAME Access)
Updated on 2025-08-04 GMT+08:00

Process of Connecting a Website to WAF (Cloud Mode - CNAME Access)

Before connecting a domain name to WAF, check whether the domain name uses a proxy, such as CDN and advanced anti-DDoS services.

Process

No proxy used

No proxies used between the client and WAF

  • If your website is not connected to WAF, DNS resolves your domain name to the origin server IP address. So, web visitors can directly access the origin server.
  • If your website is connected to WAF, DNS resolves your domain name to the CNAME record of WAF. In this way, the traffic passes through WAF. WAF then filters out illegitimate traffic and routes only legitimate traffic to the origin server.
Figure 1 No proxy used

Proxy used

Proxies used between the client and WAF

Figure 2 A proxy used
  • If your website is not connected to WAF, DNS resolves the domain name to the proxy IP address. Then, the proxy routes the traffic to the origin server.
  • If your website is connected to WAF, DNS resolves the domain name to WAF IP address. In this way, the proxy forwards the traffic to WAF. WAF then filters out illegitimate traffic and only routes legitimate traffic to the origin server.

Flowchart of connecting a website to cloud WAF

Figure 3 Process of connecting a website to WAF - Cloud Mode (CNAME Access)

Video Tutorial