Help Center/ Web Application Firewall/ Best Practices/ Website Access Configuration/ Using WAF, ELB, and NAT Gateway to Protect On-Premises Services
Updated on 2026-08-26 GMT+08:00

Using WAF, ELB, and NAT Gateway to Protect On-Premises Services

Application Scenarios

By default, with cloud load balancer access mode, WAF can protect only workloads deployed on Huawei Cloud. If your origin servers are deployed on-premises, but you want to use WAF in this mode, you can use Network Address Translation (NAT) gateways to route traffic from Huawei Cloud to the public IP addresses of your origin server. Then, you can connect your website to WAF in cloud load balancer access mode to let WAF check your website traffic.

Architecture

Figure 1 Architecture

Resource and Cost Planning

Table 1 Resources and costs

Resource

Description

Monthly Fee

Elastic Load Balance (ELB)

  • Billing mode: Yearly/Monthly
  • Instance type: Dedicated
  • Specifications: Application load balancing (HTTP/HTTPS); Medium II
  • Billed By: Bandwidth
  • Bandwidth: 10 Mbit/s

For details about billing rules, see Billing Description.

NAT Gateway

  • Billing mode: Yearly/Monthly
  • Specifications: Medium

For details about billing rules, see Billing.

Web Application Firewall (WAF)

Cloud mode - standard edition:
  • Billing mode: Yearly/Monthly
  • Number of domain names that can be protected: 10
  • QPS quota: 2,000 QPS
  • Maximum bandwidth:
    • Origin servers deployed on Huawei Cloud: 100 Mbit/s
    • Origin servers deployed outside Huawei Cloud: 30 Mbit/s

For details about pricing rules, see Billing Description.

Step 1: Create a Dedicated Load Balancer

  1. Go to the Buy Elastic Load Balancer page.
  2. Click Buy Elastic Load Balancer.

    1. Select the basic configuration for the load balancer as prompted.
      • Type: Select Dedicated load balancer.
      • Specifications: Select Application load balancing (HTTP/HTTPS) .
      • Other parameters: Set them based on your service requirements.
    2. Configure the network as prompted.
      • IP as a Backend: Toggle it on ().
      • Frontend Subnet: Select the subnet for your load balancer to use the IP addresses in this subnet to receive requests.
      • Backend Subnet: Select the subnet for your load balancer to use IP addresses in this subnet to establish connections with backend servers. You need to select a backend subnet that is different from the frontend subnet.

        If the frontend subnet is the same as the backend one, NAT Gateway will get confused.

      • Other parameters: Set them based on your service requirements.

    For details about how to create a dedicated load balancer, see Creating a Dedicated Load Balancer.

  3. Click Next.
  4. Confirm the configuration details and complete the creation as prompted.

    After the configuration is complete, you can check the created load balancer in the load balancer list. The instance has Status set to Running, Type to Dedicated, and Specifications to Application.

Step 2: Configure a Listener for the Load Balancer You Created

  1. Click the name of the target load balancer in the Name/ID column.
  2. Click the Listeners tab, click Add Listener, and configure the listener name, frontend protocol, and port.
  3. Click Next: Configure Request Routing Policy.
  4. Click Next: Add Backend Server. Then, click the IP as Backend Servers tab.
  5. Click Add IP as Backend Server. In the displayed dialog box, configure IP Address and Backend Port.

    • IP Address: Enter the IP address of your origin server.
    • Backend Port: Enter the port number.

  6. Click OK.
  7. Click Next: Confirm, confirm the information, and click Submit.

    After the configuration is complete, you can check the configured frontend protocol and port in the Listener column of the target load balancer.

Step 3: Configure a NAT Gateway

  1. Buy a public NAT gateway.

    1. Go to the Buy Public NAT Gateway page.
      • Subnet: Select the one you configured as the backend subnet in 2.b.
      • Other parameters: Set them to meet your service requirements.
    2. Click Next and confirm the public NAT gateway specifications on the displayed page.
    3. Confirm the details and click Submit.

      You can view the NAT gateway you purchased in the NAT gateway list. It takes 1 to 6 minutes to create a public NAT gateway.

  2. Add an SNAT rule.

    1. On the displayed page, click the name of the public NAT gateway on which you need to add an SNAT rule.
    2. On the SNAT Rules tab, click Add SNAT Rule.

      Subnet: Select the one you configured as the backend subnet in 2.b.

    3. Click OK.

      After the configuration is complete, you can view the added rule on the SNAT Rules tab.

Step 4: Add Website Domain Names to WAF in Cloud Load Balancer Access Mode

  1. Buy the standard edition cloud WAF.

    1. Log in to the WAF console.
    2. In the upper right corner of the page, click Buy WAF. On the purchase page displayed, select Cloud Mode for WAF Mode.
      • Region: Select the region nearest to your services WAF will protect.
      • Edition: Select Standard.
      • Expansion Package and Required Duration: Set them based on site requirements.
    3. Confirm the product details and click Buy Now in the lower right corner of the page.
    4. Check the order details and read the WAF Disclaimer. Then, select the box and click Pay Now.
    5. On the payment page, select a payment method and pay for your order.

      After the order is paid, click Access Console to go to the Dashboard page. Hover over the Product Details area to view the purchased instance edition and its specifications.

  2. Add the domain name to WAF in cloud load balancer access mode.

    1. In the navigation pane on the left, choose Access Management.
    2. On the Access Management page, click the Cloud Load Balancer tab and complete the access configuration.

      If only one access mode is enabled, complete the access configuration on the Access Management page.

      • Connecting a single one
        1. Click the number next to Inaccessible, locate the target load balancer, and click Connect in the Operation column.

          You can also select a load balancer configured with a listener and click Connect.

          If the Connect button is grayed out, no listener is configured for the load balancer. Add a listener to the load balancer and then configure the access.

        2. On the displayed Connect Domain Name to Load Balancer pane, configure the access and click OK. Table 2 describes the parameters.
      • One-click batch access
        1. Select at least one load balancer configured with a listener and click Connect.

          You can add multiple protected domain names to an accessible load balancer.

        2. On the displayed Connect pane, configure the access and click OK. Table 2 describes the parameters.
      Table 2 Access configuration parameters

      Parameter

      Description

      Example Value

      Protection Policy

      Select the protection policy you want to use for the website.

      One-click batch access allows you to use the same protection policy or different policies for multiple load balancers quickly.

      • Use the same policy: Select this option if you want to use the same protection policy for all load balancers that are connected to WAF in one-click mode.
      • Use different policies: Select a protection policy for each load balancer.
      In either way, you can select system-generated policies or custom policies you created.
      • System-generated policy (default) includes:
        • Basic Web Protection: General Check is enabled by default. It can defend against attacks such as SQL injections, XSS, remote overflow attacks, file inclusions, Bash vulnerability exploits, remote command execution, directory traversal, sensitive file access, and command/code injections.

          General Check includes:

          • Rule Set: Default rule set (medium) is selected.
          • Protective Action: Log only is selected. It means WAF only logs detected attacks but does not block them.
        • Anti-Crawler: Scanner detection is enabled by default, and Protective Action is set to Log only. WAF only logs detected attacks but does not block them. This type of detection can defend against web scans, such as vulnerability and virus scanning, and crawler behaviors from tools like OpenVAS and Nmap.
      • A protection policy created manually: a custom policy you create based on your security requirements. Only the standard, professional, and enterprise editions support manually created protection policies. For more information, see Configuring Protection Policies.

      Use the same policy > System-generated policy

      Connection Configuration

      Configure access information.

      • Protected Domain Name: Set this parameter to the domain name or IP address (public or private IP address) you want to protect. Make sure that the domain name has been resolved to the EIP of the created load balancer.
        • Domain Name: Single domain names or wildcard domain names are supported.

          Single domain name: Enter a single domain name, for example, www.example.com.

          Wildcard domain name:
          • If the server IP address of each subdomain name is the same, enter a wildcard domain name. For example, if the subdomain names a.example.com, b.example.com, and c.example.com have the same server IP address, you can add the wildcard domain name *.example.com to WAF to protect all three.
          • If the server IP addresses of subdomain names are different, add subdomain names as single domain names one by one.
          • Wildcard domain name * can be added.
          • In ELB load balancer access mode, one load balancer supports only one wildcard domain name.
        • IP: You can select a public or private IP address. If a private IP address is used, ensure that the corresponding network path is accessible so that WAF can correctly monitor and filter traffic.
      • ELB Listener: Select the listener configured for the ELB load balancer. You can select an ELB listener of another account.
        • All listeners: Select all listeners under the ELB load balancer.
        • Specific listener: Select a specific listener under the ELB load balancer.
      • Policy: If you select User different policies for Protection Policy, you need to select a protection policy for each load balancer.

      Protected Domain Name: *

      ELB Listener: All listeners

      After the access is complete, click the number next to Accessible to view the load balancers that have been connected to WAF.

Operation Result Verification

If General Check is enabled and Mode is set to Block for your domain name www.example.com, take the following steps to verify the protection effect:

  1. Clear the browser cache and enter the domain name in the address bar to check whether the website is accessible.

  2. Clear the browser cache and enter http://www.example.com?id=1%27%20or%201=1 in the address box of the browser to simulate an SQL injection attack.

    WAF blocks the access request. Figure 2 shows an example block page.

    Figure 2 Block page

  3. Return to the WAF console. In the navigation pane, choose Events. On the displayed page, view the event log.