The region blacklist module identifies the source regions of access requests and allows you to block or allow requests from specific regions, helping you mitigate regionally concentrated malicious traffic.
Prerequisites
The Edge WAF service is activated. For more information, see Activate Edge WAF.
You have added a domain name to Edge WAF. For more information, see Add a protected domain name.
Create a region blacklist-based protection policy
-
Log on to the DCDN console.
-
In the left-side navigation pane, choose .
-
On the Protection Policies page, click Create Policy.
-
On the Create Policy page, configure the policy parameters.
Section
Parameter
Description
Policy Information
Policy Type
Select Blocking Settings.
Policy Name
The policy name. It can be up to 64 characters in length and can contain letters, digits, and underscores (_).
Make Default
Whether to set this policy as the default policy for the current policy type.
Note-
Only one default policy is allowed per policy type. Once set, the default policy cannot be changed.
-
If a default policy already exists for this policy type, this switch is unavailable.
Rule Information
Regions in Chinese Mainland
Select a region in the Chinese mainland to block.
Regions Outside Chinese Mainland
Select a region outside the Chinese mainland to block.
Action
The action that WAF performs when a request matches a rule. Valid values:
-
Block: blocks matching requests and returns a block page to the client.
-
Monitor: does not block matching requests.
Use Monitor mode to evaluate rule effectiveness and verify that legitimate requests are not blocked before switching the action to Block.
Protected Domain Names
Protected Domain Names
The domain names to associate with this protection policy.
NoteA domain name can be associated with only one protection policy of the same type.
If the domain name is already associated with another policy of the same type, it is reassociated with the current policy.
-
Click Create Policy.
The new protection policy is enabled by default.