Help Center/ Config/ User Guide/ Resource Compliance/ Built-In Policies/ Web Application Firewall/ WAF Instances Must Be Enabled to Protect Domain Names
Updated on 2025-08-25 GMT+08:00

WAF Instances Must Be Enabled to Protect Domain Names

Rule Details

Table 1 Rule details

Parameter

Description

Rule Name

waf-instance-enable-protect

Identifier

WAF Instances Must Be Enabled to Protect Domain Names

Description

If no WAF instance is enabled for domain name protection, the check result is non-compliant.

Tag

waf

Trigger Type

Periodic

Filter Type

Account

Rule Parameters

None

Application Scenarios

For users with web-based businesses, it is required to enable the Web Application Firewall (WAF) service. If WAF is enabled, all public traffic to the website will first go through the WAF. Malicious traffic will be detected and filtered by the WAF, while normal traffic will be returned to the source IP, ensuring the safety, stability, and availability of the source IP.

Solution

Enable WAF instances for your websites by following the instructions in Website Connection Overview.

Rule Logic

  • If no WAF instance is enabled for domain name protection, the check result is non-compliant.
  • If a WAF instance is enabled for domain name protection, the check result is compliant.