Updated on 2026-09-01 GMT+08:00

Configuring Protection Policies

A protection policy is a collection of multiple protection rules. You can configure and manage protection rules in a policy. After a website is connected to WAF, a default protection policy is generated for the website domain name. You can configure protection rules for the policy as needed. You can configure protection rules in the default policy, or create a policy and configure protection rules for specific attack scenarios.

Constraints

  • A protection policy can be applied to multiple protected domain names, but a protected domain name can have only one protection policy.

Adding a Protection Policy

  1. Log in to the WAF console.
  2. Click in the upper left corner and select a region or project.
  3. (Optional) If you have enabled the enterprise project function, in the upper part of the navigation pane on the left, select your enterprise project from the Filter by enterprise project drop-down list. Then, WAF will display the related security data in the enterprise project on the page.
  4. In the navigation pane on the left, choose Policies > WAF Core Protection.
  5. Click Add Policy on the My Policies tab.
  6. In the Add Policy dialog box, enter a policy name and click OK.

    Figure 1 Add Policy

  7. Confirm the policy information and click OK.

    After completing the preceding configuration, you can manage the added policy in the policy list. You can:
    • View a policy: You can view protection items enabled for the policy, protected domain names added to the policy, and the enterprise project to which the policy belongs.
    • Rename a policy: Click next to the policy name to change the policy name.
    • Deleting a policy: Locate the row that contains the target policy, click More > Delete in the Operation column.

      If a policy is applied to a domain name, remove the domain name from the policy. Otherwise, the policy cannot be deleted.

    • Batch delete policies: Select at least one policy that is no longer applied to any domain name and click Delete above the list.
    • Copy a policy: In the Operation column of the target policy, choose More > Copy, and enter a new policy name and the enterprise project to which the policy belongs. Policies can only be copied within the same enterprise project.
      • WAF will name the copied policy original-policy-name_copy by default. You can rename the new policy.
      • If your policy has a known attack source rule configured, configure it again after you copy the policy as known attack source rules configured in dependent rules will become invalid in the new policy.

Adding a Domain Name to a Policy

After adding a policy, you need to add a domain name to the policy for the policy to work on the corresponding website.

  1. Log in to the WAF console.
  2. Click in the upper left corner and select a region or project.
  3. (Optional) If you have enabled the enterprise project function, in the upper part of the navigation pane on the left, select your enterprise project from the Filter by enterprise project drop-down list. Then, WAF will display the related security data in the enterprise project on the page.
  4. In the navigation pane on the left, choose Policies > WAF Core Protection.
  5. In the row containing the target policy, click Add Domain Name in the Operation column.
  6. In the Add Domain Name dialog box, select the domain name to be protected from the Domain Name drop-down list and click .

    You can select multiple domain names for a protection policy, but a domain name can be added to only one protection policy.

    Figure 2 Adding a domain name to a policy


    After completing the preceding configurations, you can locate the policy and view domain names added to the policy in the Domain Name column.

    Figure 3 Viewing added domain names

    A domain name can be added to only one policy. After the preceding operations are complete, the selected domain name will be protected with the current policy.