Edge WAF protection (legacy)
DCDN integrates WAF to provide protection on its points of presence (POPs). This feature identifies malicious traffic and forwards only normal, safe traffic to your origin server. It protects your web servers from malicious intrusions, secures your core business data, and mitigates server performance issues caused by malicious attacks.
This legacy version of WAF may fail to block some requests. For enhanced protection, we recommend that you upgrade to Edge Security Accelerator (ESA). The WAF protection offered by Edge Security Accelerator (ESA) provides superior protection compared to the legacy WAF feature of DCDN.
The following sections describe how to use the legacy edge WAF:
-
Edge WAF is not compatible with WebSocket. You cannot enable both features at the same time.
-
WAF primarily protects your origin server from intrusions, but it cannot prevent fraudulent traffic attacks on your DCDN domain name. Every request to your domain name is inspected by the WAF engine. Therefore, requests are billed regardless of whether they are blocked or monitored.
If your domain name is at risk of fraudulent traffic, we do not recommend using DCDN. You can also use CloudMonitor to configure alerts for bandwidth or QPS thresholds. If you detect abnormal traffic, promptly disable DCDN.
Prerequisites
-
Enable the edge WAF feature in the DCDN console. To do this, choose and click Activate Basic Edition.
NoteIf you are a government, finance, media, or retail customer, or if your monthly spending exceeds USD 2,800, you can fill in your information to activate the Advanced Edition or Enterprise Edition of edge WAF.
-
The Basic Edition supports only the Chinese mainland. Before you enable WAF protection on POPs, ensure the acceleration region for your domain name is set to Chinese Mainland Only. For more information about how to change the acceleration region, see Switch acceleration regions.
Features
DCDN provides WAF protection on its POPs. For more information about WAF features, see What is WAF?.
The following table describes the website protection features supported by different editions of edge WAF. Click the links in the table to view detailed information about each feature.
|
Feature |
Basic Edition |
Advanced Edition |
Enterprise Edition |
|
Web scan protection |
|||
|
Proactive defense |
Not supported |
Not supported |
|
|
Account security |
Not supported |
||
|
HTTP flood protection |
Not supported |
||
|
Block a large number of IP addresses in a blacklist |
|||
|
Rate limiting |
Not supported |
Not supported |
|
|
Bot threat intelligence |
Not supported |
Not supported |
|
|
CAPTCHA integration |
Not supported |
Not supported |
|
|
Intelligent crawler detection algorithm |
Not supported |
Not supported |
|
|
Basic web attack protection |
|||
|
Zero-day vulnerability protection |
|||
|
Alert or block mode |
|||
|
Anti-obfuscation decoding |
Not supported |
||
|
Custom rule groups |
Not supported |
Not supported |
|
|
HTTP field access control |
Not supported |
||
|
Log Service |
Not supported |
Supported (1 TB) |
Supported (3 TB) |
Billing
After you enable the WAF feature, edge WAF inspects all requests sent to the domain name. You are charged based on the total number of requests inspected by WAF across your account. For more information, see Billing of edge WAF.
Configure WAF for a single domain
-
Log on to the DCDN console.
-
In the left-side navigation pane, click Domain Names.
-
On the Domain Names page, find the domain name that you want to manage and click Configure in the Actions column.
-
Click Security Settings and select the WAF Protection tab.
-
Turn on the WAF - Chinese mainland switch.
-
Configure protection settings.
-
Click Modify Configurations.
-
As needed, add website protection configurations, such as Web security and Bot management.
-
Configure WAF for multiple domains
-
Log on to the DCDN console.
-
In the left-side navigation pane, choose .
-
Add the domain names that require protection.
-
Click Add Domain to WAF.
-
In the Add Domain to WAF dialog box, select the domain name to add.
NoteYou can add only one domain name at a time. Repeat this step to add multiple domain names.
-
Click OK.
-
-
Configure protection settings.
-
Click Configure Protection in the Actions column of the domain name.
-
As needed, add website protection configurations, such as Web security and Bot management.
-
Add website protection
Web security
|
Feature |
Parameter |
Description |
|
Status |
Enables or disables web intrusion prevention. |
|
|
Mode |
The modes for web intrusion prevention:
|
|
|
Protection Rule Group |
The web intrusion prevention rules:
|
|
|
Decoding Settings |
Specify the content formats that you want the regular expression engine to decode and analyze.
Note
To ensure protection, the regular expression engine decodes and analyzes the content of all formats in requests by default. If the regular expression engine frequently blocks legitimate requests that contain content in a specific format by mistake, you can clear the format to reduce the false positive rate. |
|
|
Status |
Enables or disables the proactive defense feature. |
|
|
Mode |
|
Bot management
|
Feature |
Parameter |
Description |
|
Status |
Enables or disables the Allowed crawlers feature. Note
Allowed crawlers provides a whitelist of search engine crawlers, such as Google, Bing, Baidu, Sogou, 360, and Yandex. These crawlers are allowed to access all your domain names. Based on your business requirements, you can click Configure Now to manage this feature. |
|
|
Typical Bot Behavior Identification |
Status |
Enables or disables typical bot behavior identification. Note
This feature provides common algorithms to identify typical bot behaviors. You can configure basic business parameters and risk thresholds for machine learning to generate intelligent protection results against advanced bots. Based on your business requirements, you can click Configure Now to add algorithm rules. |
|
Status |
Enables or disables bot threat intelligence. Note
Powered by the robust computing capabilities of Alibaba Cloud, Bot threat intelligence provides threat intelligence from multiple dimensions, such as dial-up IP pools, IP addresses of data centers, IP addresses of malicious scanning tools, and malicious bot libraries generated by real-time cloud models. This feature can be used to block access to all domain names or specified paths. Based on your business requirements, you can click Configure Now to edit the intelligence. |
|
|
Status |
Enables or disables app protection. Note
This feature provides security protection such as trusted communication and protection against bot scripts for native apps. You need to integrate the Alibaba Cloud SDK. |
Access control/throttling
|
Feature |
Parameter |
Description |
|
Status |
Enables or disables protection. Note
This feature protects against HTTP flood attacks by analyzing traffic characteristics and offers protection policies in different modes. |
|
|
Mode |
|
|
|
High-frequency Web Attack Blocking |
Enables or disables protection. When enabled, this feature automatically blocks client IPs that launch multiple web attacks in a short period.
|
|
|
Directory Traversal Prevention |
Enables or disables protection. When enabled, this feature automatically blocks client IPs that initiate multiple directory traversal attacks within a short period.
|
|
|
Scanner Blocking |
Enables or disables protection. When enabled, this feature automatically blocks access requests from IP addresses of common scanning tools. |
|
|
Collaborative Protection |
Enables or disables protection. When enabled, this feature automatically blocks access requests from IP addresses in the Alibaba Cloud global malicious scanning IP library. |
|
|
Status |
Enables or disables the IP blacklist feature. The IP blacklist feature allows you to block access from specific IP addresses and CIDR blocks, and limit access from IP addresses in specified regions. Note
Based on your business requirements, you can click Configure Now to add an IP address blacklist and a region blacklist. |
|
|
Status |
Enables or disables custom protection policies. This feature allows you to define precise rules to control access based on specific request conditions. Note
Based on your business requirements, you can click Configure Now to add a custom protection policy. |
View WAF logs and reports
After you enable WAF, you can view reports to monitor attacks and review protection effectiveness. For more information, see View WAF logs and reports.
to open the configuration window.