Help Center/ Web Application Firewall/ User Guide/ Access Management/ Advanced Settings/ Stopping WAF from Inserting Cookie Fields
Updated on 2026-09-01 GMT+08:00

Stopping WAF from Inserting Cookie Fields

This topic describes how to stop WAF from inserting the HWWAFSESTIME and HWWAFSESID fields into cookies. However, you should exercise caution when enabling this function. If WAF does not insert the HWWAFSESTIME and HWWAFSESID fields into cookies, CC attack protection rules (verification code), known attack source rules, and dynamic anti-crawler rules will be unable to work.

Principles

By default, WAF inserts the HWWAFSESTIME and HWWAFSESID fields into response cookies to support core security functions. These fields are used only for WAF internal security logic and do not store any user privacy data (such as accounts and passwords). This complies with GDPR and DJCP (MLPS) 2.0 requirements. There is no need to worry about privacy risks.
  • HWWAFSESTIME

    This field is used to mark the validity period of a WAF session and control the session-level frequency limit in CC attack protection. It prevents attackers from reusing old sessions to bypass the limit.

  • HWWAFSESID

    This field specifies the unique session ID for user access. It is used to associate consecutive requests from the same user to enable known attack source and dynamic anti-crawler rules.

If this function is enabled, WAF does not insert HWWAFSESTIME or HWWAFSESID into response cookies. The core of the CC CAPTCHA verification, known attack source blocking, and dynamic anti-crawler functions is to identify and track the same access entity. The two cookies are the key for WAF to track session. Without HWWAFSESTIME, WAF will be unable to check whether a session is valid. Without HWWAFSESID, WAF will be unable to distinguish between different visitors. So, if you disable this function, related WAF protection functions are disabled accordingly due to the lack of data support. Exercise caution when enabling this function.

Typical Application Scenarios

Table 1 Application scenario descriptions

Whether to Enable This Function

Application Scenario

Potential Impact

Decision Point

Yes

  • Unnecessary cookies are prohibited according to business compliance requirements.
  • Static websites (without user interaction)
  • In-house session mechanism to avoid cookie conflicts

This is an important security function. If it is disabled, protection capabilities will be downgraded.

If this function is enabled, other protection measures are required, such as enhanced rule configuration.

No

  • Dynamic websites (with user login and interaction)
  • Defense against CC attacks and crawlers
  • No cookie usage restrictions

The response cookie contains the two WAF-specific fields. This does not affect services.

Keep the default setting (disabled) to ensure protection integrity.

Prerequisites

You have connected your website to WAF. For details, see Access Management.

Procedure

  1. Log in to the WAF console.
  2. Click in the upper left corner and select a region or project.
  3. (Optional) If you have enabled the enterprise project function, in the upper part of the navigation pane on the left, select your enterprise project from the Filter by enterprise project drop-down list. Then, WAF will display the related security data in the enterprise project on the page.
  4. In the navigation pane on the left, choose Assets > Protected Objects.
  5. On the Protected Objects page, click the target domain name.
  6. In the Do Not Insert the Cookie Field column, click to enable the function.

    If this function is enabled, the CC attack protection (verification code), known attack source rules, and dynamic anti-crawler rules will be unable to work. Exercise caution when enabling this function.

    After the preceding configurations are complete, access the protected website, press F12 to open the developer tool, click the current domain name under Cookie on the Application tab, and check whether the HWWAFSESTIME and HWWAFSESID fields are included.

Related Operations

  • If all unnecessary cookies need to be disabled due to compliance requirements, you can add "Cache-Control: no-cache" to the response header in WAF after enabling this function to prevent the browser from caching old cookies.
  • If this function is enabled, you are advised to configure CC attack protection rules for IP addresses to limit the access frequency of IP addresses and make up for the protection gap after the CC verification is disabled.