Updated on 2024-04-12 GMT+08:00

Viewing Basic Information

This topic describes how to view the basic information about a protected website, switch WAF working mode, and delete a domain name of a protected website from WAF.

Prerequisites

You have added the website you want to protect to WAF.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Click in the upper left corner and choose Web Application Firewall under Security & Compliance.
  4. In the navigation pane on the left, choose Website Settings.
  5. View the protected website lists. For details about parameters, see Table 1.

    Table 1 Parameters

    Parameter

    Parameter

    Domain Name

    Protected domain name or IP address.

    Deployment Mode

    How your WAF instance is deployed for your website. Only Dedicated mode is available.

    Last 3 Days

    Protection status of the domain name over the past three days.

    Mode

    WAF mode of the protected domain name. You can click to select one of the following protection modes:

    • Enabled: WAF is enabled.
    • Suspended: WAF is disabled. If a large number of normal requests are blocked, for example, status code 418 is frequently returned, then you can switch the mode to Suspended. In this mode, your website is not protected because WAF only forwards requests. It does not scan for attacks. This mode is risky. You are advised to use the global protection whitelist (formerly false alarm masking) rules to reduce false alarms.

    Policy

    Number of types of WAF protection enabled for the domain name. You can click the number to go to the rule configuration page and configure specific protection rules. For details, see Rule Configuration.

    Access Progress

    The progress of connecting your website to WAF or the website access status.

    • Inaccessible: The website has not been connected to WAF yet or failed to connect to WAF.
    • Accessible: The website has been connected to WAF.
    NOTICE:

    The initial Access Status of a website deployed in Dedicated mode is Inaccessible. When a request reaches your WAF instance, the access status automatically changes to Accessible.

    Operation

    To remove a protected website from WAF, click Delete.

  6. In the Domain Name column, click the domain name of the website to go to the basic information page.
  7. View the basic information about the protected website.

    • Update the certificate: If you select HTTPS for Client Protocol, an SSL certificate is required. To update the certificate, click next to the certificate name in the International Certificate or Chinese Certificate row. Then, in the displayed dialog box, upload a new certificate or select an existing certificate. For more details, see Updating a Certificate.
    • Update the TLS version and TLS cipher suite for accessing the origin server: If you select HTTPS for Client Protocol, you can change TLS version to a more secure one. To do so, click next to the TLS Configuration field. Then, in the displayed dialog box, select the desired TLS version and TLS cipher suite. For more details, see Configuring the Minimum TLS Version and Cipher Suite.
    • Modify the field of Proxy Configured: Click . In the displayed dialog box, select Yes if your web server is using a proxy.
    • Customize the alarm page: Click . In the displayed dialog box, select Custom or Redirection and complete required configurations. By default, Alarm Page is Default.
    • If you want to set a timeout duration for each request, enable Timeout Settings and click to specify WAF-to-Server Connection Timeout (s), Read Timeout (s), and Write Timeout (s). This function cannot be disabled after being enabled. For details, see Configuring Connection Timeout.