All Products
Search
Document Center

Web Application Firewall:Configure a website whitelist

Last Updated:May 27, 2026

After you add your website to Web Application Firewall (WAF), you can configure a website whitelist to allow trusted requests to bypass all WAF security modules and access your origin server directly. Use this for traffic from trusted vulnerability scanners or authenticated third-party APIs.

Prerequisites

  • You have activated a Web Application Firewall instance.

  • Your website has been added to WAF. For more information, see Tutorials.

Background

WAF Website Protection consists of multiple security modules. By default, all inbound requests are inspected by every enabled security module. Create a website whitelist to let requests from fully trusted sources bypass all security modules and access the origin server directly.

You can also configure module-specific whitelists to bypass individual modules. WAF supports these module-specific whitelists:

Note

Module-specific whitelists are more secure than a general website whitelist. Configure them as needed.

Procedure

  1. Log on to the Web Application Firewall console.

  2. In the top menu bar, select the resource group and region for your Web Application Firewall instance (Chinese Mainland or Outside Chinese Mainland).

  3. In the left navigation pane, choose Protection Config > Website Protection.

  4. On the Website Protection page, switch to the domain name to configure.切换域名

  5. Click Website Whitelist in the upper-right corner.

  6. Create a website whitelist rule.

    1. On the Website Whitelist page, click Create.

    2. In the Create Rule dialog box, configure these parameters.Website whitelist

      Parameter

      Description

      Rule Name

      Enter a name for the rule.

      Match Condition

      Define conditions a request must meet. Click Add Condition to add up to five conditions. If you add multiple conditions, the request must match all of them.

      Supported fields are listed in Descriptions of match condition fields.

    3. Click Save.

    The rule takes effect immediately and appears in the rule list. You can disable, edit, or delete it from there.

Reference

Descriptions of match condition fields