An access control/throttling whitelist allows legitimate business requests that would otherwise be blocked by access control or throttling rules.
Prerequisites
-
You have activated a Web Application Firewall instance.
-
Your website has been added to WAF. For more information, see Tutorials.
Background
The access control/throttling feature lets you define custom, application-layer access control and traffic management policies to ensure your website's availability. It includes the following detection modules:
If these modules block legitimate requests to your website, you can configure an access control/throttling whitelist. This ensures that requests meeting the whitelist conditions bypass inspection by the specified modules.
As a best practice, define match conditions as precisely as possible to ensure that you allow only legitimate requests.
Procedure
-
Log on to the Web Application Firewall console.
-
In the top menu bar, select the resource group and region for your Web Application Firewall instance (Chinese Mainland or Outside Chinese Mainland).
-
In the left navigation pane, choose .
-
On the Website Protection page, switch to the domain name to configure.

Click the Access Control/Throttling tab, go to the Access Control/Throttling section, and click Configure Now on the right.
Create a whitelist rule.
On the Access Control/Throttling - Whitelist page, click Create.
In the Create Rule dialog box, configure the rule.

Parameter
Description
Rule Name
Enter a name for the rule.
Match Condition
Specify the conditions that a request must meet to be whitelisted. Click Add Condition to set up to five conditions. If multiple conditions exist, a request must meet all of them to be considered a match.
For more information about the fields in a match condition, see Fields in a match condition.
Bypassed Modules
Select the protection modules to bypass when a request matches the conditions. Available options are:
Default HTTP Flood Protection
Custom Rule
IP Address Blacklist
Scan Protection
Click Save.
The new whitelist rule is enabled by default. It appears in the rule list, where you can disable, edit, or delete it.