Before you can use Web Application Firewall (WAF) to protect your web services, you must add your website to WAF.
Integration methods
WAF supports two integration methods: CNAME record and transparent proxy mode. By default, WAF supports HTTP/1.0, HTTP/1.1, and HTTP/2.0. You can select an integration method based on your business needs.
If your website supports the HTTP/2.0 protocol, you can turn on the HTTP2 switch to enable protection for your HTTP/2.0 services.
Differences | CNAME record | Transparent proxy mode |
Concept | Redirects web traffic to WAF by adding your website information and modifying the domain's DNS record. | Redirects web traffic to WAF by adding your website information, without requiring changes to your domain's DNS record. |
Supported origin servers | All origin servers, regardless of whether they are deployed on Alibaba Cloud. | Origin servers deployed on ECS instances or Internet-facing SLB instances. |
Scope of integration | You can add only one domain at a time. | You can add all domains that belong to an instance at once. |
Back-to-origin configuration required | Yes | No |
DNS record modification required | Yes. You must modify the DNS record. | No. You do not need to modify the DNS record. |
Origin server protection required | Yes. The origin server is at risk of direct attacks, so you must configure origin server protection. | No. You do not need to configure origin server protection. |
Limitations | None. |
For more information about the limitations, see Transparent proxy mode. |
CNAME record integration
Go to the Add Domain Name page.
Add a domain name. Provide website information, such as the domain name and back-to-origin settings, to WAF.
Parameter
Description
Domain Name
Enter the domain name of the website that you want to protect.
Protection Resource
Select the type of protection resource based on your requirements.
Protocol Type
Select the protocol types that your website supports. You can select Enable HTTPS Routing, Enable HTTP Back-to-Origin, and Enable Origin SNI.
Origin server address
Specify the address of the origin server where WAF forwards requests. The following address types are supported:
IP address: The public IP address of an SLB instance, an ECS instance, or a server in an external data center.
Domain name (such as a CNAME): A back-to-origin domain that is different from the protected domain. Only IPv4 addresses are supported for back-to-origin traffic.
Origin server port
Based on the selected Protocol Type, configure the port that the origin server uses to provide services.
ImportantIf the origin server uses a port other than HTTP port 80 or HTTPS port 443, you can specify a custom server port from the range of ports that WAF supports. For more information, see Ports supported by WAF.
Load Balancing Algorithm
If you specify multiple origin server addresses, select a load balancing algorithm for the servers.
Is a Layer 7 proxy such as Anti-DDoS Proxy or CDN deployed in front of WAF
Indicate if another Layer 7 proxy service, such as Anti-DDoS Proxy or CDN, is deployed in front of WAF.
Enable Traffic Mark
Specify whether to enable the traffic mark feature.
Back-to-origin Timeout Configuration
If your origin server has a long processing time that may cause timeouts, you can configure the connection and read/write timeout periods for WAF.
Retry Back-to-origin Requests
When a back-to-origin request fails, WAF retries the request up to three times for each origin server by default. If you disable this feature, WAF does not retry failed requests.
Back-to-origin Keep-alive Requests
Configure persistent connections between WAF and your origin server.
For more information, see Add a domain name.
Locally verify your domain name settings in WAF. This step helps prevent service disruptions by ensuring that your forwarding settings are correct before you modify the domain's DNS record. For more information, see Local verification.
Modify the domain's DNS record to direct website traffic to WAF.
The following steps show how to modify a DNS record by using Alibaba Cloud DNS as an example.
Obtain the CNAME or IP address from WAF. For more information, see Obtain the CNAME of WAF.
Go to the Domains page of the Alibaba Cloud DNS console. Find the domain name you want to manage, click Settings in the Actions column, and change the value of the CNAME record to the CNAME provided by WAF.
For more information, see Modify the DNS record of a domain name.
Verify that WAF protection is effective.
In a web browser, enter the domain name you added. If the website loads correctly, the domain was added successfully.
NoteAccess your website via its domain name, not the CNAME provided by WAF. The CNAME is used for DNS resolution only and cannot be accessed directly.
In a web browser, enter the domain name you added and a web attack code, for example,
<protected domain name>/alert(xss), wherealert(xss)is a test code for a cross-site scripting attack. If a 405 block page appears, WAF has successfully intercepted the attack.
After you complete these steps, your website is successfully added to WAF. For more comprehensive protection, take the following steps:
Upload an HTTPS certificate
If your website uses the HTTPS protocol, you must upload a valid HTTPS certificate after you add the domain name. This ensures that WAF can process HTTPS traffic. For more information, see Add a domain name.
Add WAF back-to-origin IP CIDR blocks to the allowlist
After you add a website to WAF, WAF uses specific back-to-origin IP CIDR blocks to forward legitimate traffic to your origin server. This can increase the frequency and concentration of access from these IP addresses. To prevent your origin server's security software from blocking these IP addresses as attack sources, you must add the WAF back-to-origin IP CIDR blocks to your security software's allowlist. For more information, see Add the back-to-origin IP CIDR blocks of WAF to an allowlist.
Configure origin server protection
For security reasons, configure an access control policy on your origin server to allow inbound traffic only from WAF back-to-origin IP CIDR blocks. This prevents attackers from bypassing WAF and attacking your origin server directly. For more information, see Configure origin server protection.
Configure a custom TLS configuration
If a WAF-protected website uses HTTPS, you can customize the TLS protocol versions and cipher suites for the domain name. For more information, see Configure custom TLS policies.
Transparent proxy mode integration
Go to the Add Domain Name page in the Web Application Firewall console and set Access Mode to Transparent Proxy.
Add a domain name.
Parameter
Description
Domain Name
Enter the website domain name.
Instance and port
Select an instance type and add the ports of the corresponding instance. WAF supports enabling the transparent proxy mode for the origin server ports of the following instance types: SLB-based Domains, Layer 7 SLB-based Domains, Layer 4 SLB-based Domains, and ECS-based Domains.
Is a Layer 7 proxy such as Anti-DDoS Proxy or CDN deployed in front of WAF
Indicate if another Layer 7 proxy service, such as Anti-DDoS Proxy or CDN, is deployed in front of WAF.
Enable Traffic Mark
Specify whether to enable the traffic mark feature.
For more information, see Transparent proxy mode.
Verify that WAF protection is effective.
In a web browser, enter the domain name you added. If the website loads correctly, the domain was added successfully.
NoteAccess your website via its domain name, not the CNAME provided by WAF. The CNAME is used for DNS resolution only and cannot be accessed directly.
In a web browser, enter the domain name you added and a web attack code, for example,
<protected domain name>/alert(xss), wherealert(xss)is a test code for a cross-site scripting attack. If a 405 block page appears, WAF has successfully intercepted the attack.
Integrate WAF with other cloud services
In addition to adding a website directly to WAF, you can integrate WAF with other Alibaba Cloud services, such as Anti-DDoS Proxy and CDN, to build a comprehensive security architecture.
Improve website protection by deploying Anti-DDoS Proxy and WAF together: To protect your website against both web application attacks and DDoS attacks, you can deploy Anti-DDoS Proxy and WAF in front of your origin server.
Use WAF and CDN to protect accelerated domains: To defend your website against web application attacks while using CDN for content acceleration, you can deploy CDN and WAF in front of your origin server.
Next steps
After you add your website to WAF, its traffic is routed through WAF for protection. WAF offers multiple detection modules to defend your website against various security threats. By default, the Protection Rules Engine under Web Security and the HTTP Flood Protection module under Access Control/Throttling are enabled. They protect against common web application attacks—such as SQL injection, XSS, and webshell uploads—and HTTP flood attacks. You must manually enable other protection modules and configure specific protection rules. For more information, see Overview of website protection configurations.