The access control and throttling whitelist provides access control and throttling policies for websites that are added to Web Application Firewall (WAF) based on the application layer. It also ensures the accessibility of the website. The access control and throttling whitelist supports HTTP flood protection, IP blacklist, scan protection, and custom protection polices. You can configure the access control and throttling whitelist. Requests that match specific conditions in the whitelist can skip specified detection modules.
- Log on to the Web Application Firewall console.
- In the top navigation bar, select the resource group to which the instance belongs and the region, Mainland China or International, in which the instance is deployed.
- In the left-side navigation pane, choose .
- In the upper part of the Website Protection page, select the domain name for which you want to configure the whitelist.
- Click the Access Control/Throttling tab, find the Access Control/Throttling section, and then click Settings.
- Create the access control and throttling whitelist.
After you create rules for the access control and throttling whitelist, they are enabled automatically. You can view newly created rules in the rule list and disable, edit, or delete rules as needed.
- On the Access Control/Throttling - Whitelisting page, click Create Rule.
- In the Add Rule dialogue box, set the following parameters.
Parameter Description Rule name Specify a name for the rule. Matching Condition Specify the conditions that a whitelist request must match. Click Add rule to add more conditions. You can specify a maximum of five conditions. If you have set multiple conditions, the rule is matched only after all of them are met.
For more information about match conditions, see Fields of match conditions.
Modules Bypassing Check Specify the detection modules to be ignored after the match conditions of the rule have been matched. Detection modules include:
- HTTP Flood Protection
- Custom Rules
- IP Blacklist
- Click Save.