首页 Edge WAF protection (legacy)

Edge WAF protection (legacy)

更新时间: 2026-05-03 03:15:15

DCDN integrates WAF to provide protection on its points of presence (POPs). This feature identifies malicious traffic and forwards only normal, safe traffic to your origin server. It protects your web servers from malicious intrusions, secures your core business data, and mitigates server performance issues caused by malicious attacks.

Important

This legacy version of WAF may fail to block some requests. For enhanced protection, we recommend that you upgrade to Edge Security Accelerator (ESA). The WAF protection offered by Edge Security Accelerator (ESA) provides superior protection compared to the legacy WAF feature of DCDN.

Important
  • Edge WAF is not compatible with WebSocket. You cannot enable both features at the same time.

  • WAF primarily protects your origin server from intrusions, but it cannot prevent fraudulent traffic attacks on your DCDN domain name. Every request to your domain name is inspected by the WAF engine. Therefore, requests are billed regardless of whether they are blocked or monitored.

    If your domain name is at risk of fraudulent traffic, we do not recommend using DCDN. You can also use CloudMonitor to configure alerts for bandwidth or QPS thresholds. If you detect abnormal traffic, promptly disable DCDN.

Prerequisites

  • Enable the edge WAF feature in the DCDN console. To do this, choose WAF Protection > Protection Overview and click Activate Basic Edition.

    Note

    If you are a government, finance, media, or retail customer, or if your monthly spending exceeds USD 2,800, you can fill in your information to activate the Advanced Edition or Enterprise Edition of edge WAF.

  • The Basic Edition supports only the Chinese mainland. Before you enable WAF protection on POPs, ensure the acceleration region for your domain name is set to Chinese Mainland Only. For more information about how to change the acceleration region, see Switch acceleration regions.

Features

DCDN provides WAF protection on its POPs. For more information about WAF features, see What is WAF?.

The following table describes the website protection features supported by different editions of edge WAF. Click the links in the table to view detailed information about each feature.

Feature

Basic Edition

Advanced Edition

Enterprise Edition

Web scan protection

Supported

Supported

Supported

Proactive defense

Not supported

Not supported

Supported

Account security

Not supported

Supported

Supported

HTTP flood protection

Not supported

Supported

Supported

Block a large number of IP addresses in a blacklist

Supported

Supported

Supported

Rate limiting

Not supported

Not supported

Supported

Bot threat intelligence

Not supported

Not supported

Supported

CAPTCHA integration

Not supported

Not supported

Supported

Intelligent crawler detection algorithm

Not supported

Not supported

Supported

Basic web attack protection

Supported

Supported

Supported

Zero-day vulnerability protection

Supported

Supported

Supported

Alert or block mode

Supported

Supported

Supported

Anti-obfuscation decoding

Not supported

Supported

Supported

Custom rule groups

Not supported

Not supported

Supported

HTTP field access control

Not supported

Supported

Supported

Log Service

Not supported

Supported (1 TB)

Supported (3 TB)

Billing

After you enable the WAF feature, edge WAF inspects all requests sent to the domain name. You are charged based on the total number of requests inspected by WAF across your account. For more information, see Billing of edge WAF.

Configure WAF for a single domain

  1. Log on to the DCDN console.

  2. In the left-side navigation pane, click Domain Names.

  3. On the Domain Names page, find the domain name that you want to manage and click Configure in the Actions column.

  4. Click Security Settings and select the WAF Protection tab.

  5. Turn on the WAF - Chinese mainland switch.

  6. Configure protection settings.

    1. Click Modify Configurations.

    2. As needed, add website protection configurations, such as Web security and Bot management.

Configure WAF for multiple domains

  1. Log on to the DCDN console.

  2. In the left-side navigation pane, choose WAF Protection > Configuration Management.

  3. Add the domain names that require protection.

    1. Click Add Domain to WAF.

    2. In the Add Domain to WAF dialog box, select the domain name to add.

      Note

      You can add only one domain name at a time. Repeat this step to add multiple domain names.

    3. Click OK.

  4. Configure protection settings.

    1. Click Configure Protection in the Actions column of the domain name.

    2. As needed, add website protection configurations, such as Web security and Bot management.

Add website protection

Web security

Feature

Parameter

Description

Web intrusion prevention

Status

Enables or disables web intrusion prevention.

Mode

The modes for web intrusion prevention:

  • Block: Blocks detected intrusions.

  • Alert: Reports detected intrusions without blocking them.

Protection Rule Group

The web intrusion prevention rules:

  • Loose Rule: We recommend that you select the Loose Rule if the Medium Rule causes a high number of incorrect blocks. The loose mode has the lowest rate of false positives but is also more likely to miss attacks.

  • Medium rule group: This is the default rule group.

  • Strict Rule: If you need stricter protection against path traversal, SQL injection, and command execution, we recommend that you select Strict Rule.

Decoding Settings

Specify the content formats that you want the regular expression engine to decode and analyze.

  1. Click jiema to open the configuration window.

  2. Select or clear the formats that you want to decode.

    • You cannot clear the following formats: URL Decoding, JavaScript Unicode Decoding, Hex Decoding, Comment Processing, and Space Compression.

    • You can clear the following formats: Multipart Data Parsing, JSON Data Parsing, XML Data Parsing, Serialized PHP Data Decoding, HTML Entity Decoding, UTF-7 decoding, Base64 Decoding, and Form Data Parsing.

  3. Click OK.

Note

To ensure protection, the regular expression engine decodes and analyzes the content of all formats in requests by default. If the regular expression engine frequently blocks legitimate requests that contain content in a specific format by mistake, you can clear the format to reduce the false positive rate.

Proactive defense

Status

Enables or disables the proactive defense feature.

Mode

  • Alert: Generates alerts for attack requests but does not block them.

  • Block: Blocks attack requests.

Bot management

Feature

Parameter

Description

Allowed crawlers

Status

Enables or disables the Allowed crawlers feature.

Note

Allowed crawlers provides a whitelist of search engine crawlers, such as Google, Bing, Baidu, Sogou, 360, and Yandex. These crawlers are allowed to access all your domain names. Based on your business requirements, you can click Configure Now to manage this feature.

Typical Bot Behavior Identification

Status

Enables or disables typical bot behavior identification.

Note

This feature provides common algorithms to identify typical bot behaviors. You can configure basic business parameters and risk thresholds for machine learning to generate intelligent protection results against advanced bots. Based on your business requirements, you can click Configure Now to add algorithm rules.

Bot threat intelligence

Status

Enables or disables bot threat intelligence.

Note

Powered by the robust computing capabilities of Alibaba Cloud, Bot threat intelligence provides threat intelligence from multiple dimensions, such as dial-up IP pools, IP addresses of data centers, IP addresses of malicious scanning tools, and malicious bot libraries generated by real-time cloud models. This feature can be used to block access to all domain names or specified paths. Based on your business requirements, you can click Configure Now to edit the intelligence.

App protection

Status

Enables or disables app protection.

Note

This feature provides security protection such as trusted communication and protection against bot scripts for native apps. You need to integrate the Alibaba Cloud SDK.

Access control/throttling

Feature

Parameter

Description

HTTP flood protection

Status

Enables or disables protection.

Note

This feature protects against HTTP flood attacks by analyzing traffic characteristics and offers protection policies in different modes.

Mode

  • Block (default): Recommended for normal traffic to minimize false positives.

  • Emergency: Use this mode when your website traffic is abnormal.

Scan protection

High-frequency Web Attack Blocking

Enables or disables protection.

When enabled, this feature automatically blocks client IPs that launch multiple web attacks in a short period.

  • Click Configure Now to configure a custom protection policy.

  • Click Unblock IP Address to manually unblock an IP address.

Directory Traversal Prevention

Enables or disables protection.

When enabled, this feature automatically blocks client IPs that initiate multiple directory traversal attacks within a short period.

  • Click Configure Now to configure a custom protection policy.

  • Click Unblock IP Address to manually unblock an IP address.

Scanner Blocking

Enables or disables protection. When enabled, this feature automatically blocks access requests from IP addresses of common scanning tools.

Collaborative Protection

Enables or disables protection. When enabled, this feature automatically blocks access requests from IP addresses in the Alibaba Cloud global malicious scanning IP library.

IP blacklists

Status

Enables or disables the IP blacklist feature.

The IP blacklist feature allows you to block access from specific IP addresses and CIDR blocks, and limit access from IP addresses in specified regions.

Note

Based on your business requirements, you can click Configure Now to add an IP address blacklist and a region blacklist.

Custom protection policy

Status

Enables or disables custom protection policies.

This feature allows you to define precise rules to control access based on specific request conditions.

Note

Based on your business requirements, you can click Configure Now to add a custom protection policy.

View WAF logs and reports

After you enable WAF, you can view reports to monitor attacks and review protection effectiveness. For more information, see View WAF logs and reports.