For websites added to Web Application Firewall (WAF), web intrusion prevention responds quickly to common web attacks and zero-day vulnerabilities to secure your websites. Web intrusion prevention supports the RegEx Protection engine and the big data deep learning engine. You can configure the web intrusion prevention whitelist. Requests that match specific conditions in the whitelist can skip specified detection modules.

Notice This topic uses the new version of the WAF console released in January 2020. If the WAF instance was created before this date, you cannot to use the web intrusion prevention whitelist.

Prerequisites

  • A Web Application Firewall instance is available. For more information, see Activate a WAF instance.
  • The website is associated with the Web Application Firewall instance. For more information, see Add domain names.

Background information

The web intrusion prevention whitelist is generally used to allow access requests that are mistakenly blocked. We recommend that you set the match conditions as precisely as possible to ensure that only the specific access requests are allowed.

For more information about supported detection modules of web intrusion prevention, see:

Procedure

  1. Log on to the Web Application Firewall console.
  2. In the top navigation bar, select the resource group to which the instance belongs and the region, Mainland China or International, in which the instance is deployed.
  3. In the left-side navigation pane, choose Protection Settings > Website Protection.
  4. In the upper part of the Website Protection page, select the domain name for which you want to configure the whitelist.Switch Domain Name
  5. Click the Web Security tab, find the Web Intrusion Prevention section, and then click Settings.
  6. Create the web intrusion prevention whitelist.
    1. On the Web Intrusion Prevention - Whitelisting page, click Create Rule.
    2. In the Add Rule dialogue box, set the following parameters.Add a rule, web intrusion prevention, whitelist
      Parameter Description
      Rule name Specify a name for the rule.
      Matching Condition Specify the match conditions of the whitelist rule. Click Add rule to add more conditions. You can specify a maximum of five conditions. If you have set multiple conditions, the rule is matched only after all of them are met.

      For more information about match conditions, see Fields of match conditions.

      Modules Bypassing Check Specify the detection modules to be ignored after the match conditions of the rule are matched. Supported modules include:
      • Web Attack Protection
      • Deep Learning
    3. Click Save.
    After you create rules for the web intrusion prevention whitelist, they are enabled automatically. You can view newly created rules in the rule list and disable, edit, or delete rules as needed.The web intrusion prevention whitelist