| 202601 | - Known issues have been fixed.
|
| 202512 | - More non-standard HTTP ports are supported.
- Known issues have been fixed.
|
| 202509 | - JS challenges are configured for asynchronous APIs, supporting cross-domain scenarios.
- The memory usage of dedicated WAF engines has been optimized.
- Known issues have been fixed.
|
| 202507 | - New condition combinations are available in the condition field.
- More non-standard ports are supported.
- Known issues have been fixed.
|
| 202504.V1 | - Custom fields can be recorded in logs.
- Inspection conditions can be combined with OR.
- Known issues have been fixed.
|
| 202504 | - The IP threat intelligence database is supported.
- Advanced JS challenge is supported.
- Bot protection supports CAPTCHA.
- JA3 and JA4 fingerprints are supported.
- Content-Length supports numerical comparison.
- Known issues have been fixed.
|
| 202502 | - Custom headers can be used as trace IDs.
- Counting requests to all WAF instances is supported in CC attack protection rules. You need to submit a service ticket to enable this function.
- Advanced JS challenge is supported.
- Known issues have been fixed.
|
| 202412 | - IPv6 addresses are supported for geolocation access control rules.
- WAF supports in-house bot mitigation.
- Custom response headers can be forwarded.
- Known issues have been fixed.
|
| 202410 | - Customizable response headers on the custom block pages
- Obtaining and processing the TOA field
|
| 202408 | Known issues have been fixed. |
| 202407 | - In-depth decoding supported in precise protection rules
- Known issues have been fixed.
|
| 202405 | - The health-check API is supported.
- Cookies can be checked for invalid characters.
- The Protective Action in CC attack protection rules can be set to JS Challenge.
- Known feature crawler can be set in the condition list of precise protection rules.
- When and how to execute a precise rule can be set in the Apply parameter.
- Requests for only error response codes 4xx and 5xx can be logged. Function parameter: upstream.extend.only_log_abnormal_status.
- In dedicated mode, the default values of X-Real-IP and X-Hwwaf-Real-IP are returned from $client_ip instead of $remote_addr.
|
| 202312 | - A global protection whitelist rule can be set to ignore invalid requests.
- JavaScript-based anti-crawler rules support more protective actions, including Block, Log only, and Verification code.
|
| 202308 | - The $remote_addr field is added to the IP identifier, which can be directly set to the IP address of the TCP connection.
- IP addresses used in TCP connections can be identified by CC, precise protection, blacklist, and whitelist rules.
- A block duration can be set if Protective Action is set to Verification code in a CC attack protection rule.
|
| 202305 | - HTTP2 is enabled globally by default. There is no need to enable it manually.
- By default, a request can pass through WAF four times before it goes to the origin server. Error code 523 will be returned if the request exceeds this limit.
- Strict multipart format verification is supported.
- Dedicated ELB network load balancers are supported. (In earlier versions, only shared load balancers and dedicated application load balancers are supported.)
|
| 202211 | - Built-in tags can be added to attack logs (hit_data) when built-in rules are hit.
- Destination rate limiting and response code conditions can be configured in CC attack protection rules.
|
| 202209 | - TLS v1.3 is supported.
- Protection for on-premises web servers is supported.
- Cloud Eye can be used to monitor WAF.
- More types of statistics are added to heartbeat logs for attacks.
- HTTPS ports 60700 to 60999 (300 ports) are added to the protection port list.
|
| 202207 | - The wildcard domain name matching logic is supported.
- The global protection whitelist is supported.
|
| 202205 | Configuring the earliest TLS version based on instances is supported. |
| 202204 | - Rules can be updated and delivered from the management plane.
- False alarm masking rules can work for all domain names and specified domain names.
- All conditions can be configured for false alarm masking.
|
| 202202 | The request logging methods are optimized. |
| 202201 | Some regular expression matching rules are optimized. |
| 202111 | - The log only mode is supported for information leakage rules.
- Attack logs of invalid requests are added.
- Precise protection rules can work to each IP address (only for IPv4 format) in the XFF request header.
- Timeout duration can be set for specified domain names.
- Some functions are optimized.
|
| 202110 | The performance of some functions is improved. |
| 202109 | - Precise protection rules can work to the request body field.
- Precise protection rules support regular expression matching and all subfields.
- Some logs can be interconnected with LTS.
|
| 202106 | - The HTTPS port supports HTTP/2.
- The region ID field is added to access logs.
- The region ID field and engine IP address are added to attack logs.
|