Which Protection Rules Are Included in the System-Generated Policy?
When you add a website to WAF, you can select an existing policy you have created or the system-generated policy. For details, see Table 1.
You can also tailor your protection rules after the domain name is connected to WAF.
| Edition | Policy | Description |
|---|---|---|
| Standard edition | Basic web protection (Log only mode and common checks) | The basic web protection defends against attacks such as SQL injections, XSS, remote overflow vulnerabilities, file inclusions, Bash vulnerabilities, remote command execution, directory traversal, sensitive file access, and command/code injections. |
| Cloud mode (Standard, professional, and enterprise editions) and dedicated mode | Basic web protection (Log only mode and common checks) | The basic web protection defends against attacks such as SQL injections, XSS, remote overflow vulnerabilities, file inclusions, Bash vulnerabilities, remote command execution, directory traversal, sensitive file access, and command/code injections. |
| Anti-crawler (Log only mode and Scanner feature) | WAF only logs web scanning tasks, such as vulnerability scanning, virus scanning, and crawling behavior of OpenVAS and Nmap. |
Log only: WAF only logs detected attack events instead of blocking them.
What is your overall rating for this page?
Thank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot