Help Center/ Web Application Firewall/ FAQs/ About WAF/ Can WAF Protect Websites Accessed Through HSTS Authentication?
Updated on 2026-08-18 GMT+08:00
Can WAF Protect Websites Accessed Through HSTS Authentication?
Yes. WAF can protect HTTP and HTTPS applications.
- If a website uses the HTTP Strict Transport Security (HSTS) policy, the client (such as a browser) is forced to use HTTPS to communicate with the website. This reduces the risk of session hijacking. Websites configured with HSTS policy use the HTTPS protocol. So, WAF can protect these websites.
WAF can protect domain names (including wildcard domain names, top-level domain names, and second-level domain names) and IP addresses (including public and private IP addresses). The protected objects vary depending on the access mode.
- Cloud CNAME: protects your web applications that are accessible over domain names and are deployed on any clouds or in on-premises data centers.
- Cloud load balancer: protects your web applications that are deployed on Huawei Cloud and accessible over domain names or IP addresses (public or private IP addresses).
- Dedicated Mode: protects your web applications that are deployed on Huawei Cloud and accessible over domain names or IP addresses (public or private IP addresses).
Parent topic: About WAF
What is your overall rating for this page?
0
1
2
3
4
5
6
7
8
9
10
Very dissatisfiedVery satisfied
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
The system is busy. Please try again later.
For any further questions, feel free to contact us through the chatbot.
Chatbot