Help Center/ Web Application Firewall/ FAQs/ About WAF/ Why Does the Vulnerability Scanning Tool Report Disabled Ports for My WAF-Protected Website?
Updated on 2026-08-18 GMT+08:00

Why Does the Vulnerability Scanning Tool Report Disabled Ports for My WAF-Protected Website?

Symptom

When a third-party vulnerability scanning tool scans the website whose domain name has been connected to WAF, the scan result shows that some standard ports (such as port 443) and non-standard ports (such as ports 80, 8000, and 8443) are vulnerable.

Possible Cause

Because the ports on WAF engines used for cloud CNAME access are shared among all users, third-party vulnerability scanning tools can detect all ports used by WAF to provide services. The results of port checks for your domain names should be based on the ports that you configured on WAF. Port vulnerabilities reported for WAF service ports in your scan reports do not affect your origin server security. WAF ensures the security of its engine IP address mapped the CNAME record.

Handling Suggestions

No action is required.