All Products
Search
Document Center

Web Application Firewall:Deploy a hybrid cloud WAF cluster

Last Updated:Aug 20, 2026

After purchasing a Hybrid Cloud WAF instance, you can deploy a custom protection cluster, also called a hybrid cloud cluster. You must deploy a cluster before adding your websites to Hybrid Cloud WAF for protection. This topic describes the deployment process.

Prerequisites

  • You have purchased a Hybrid Cloud WAF instance on the Alibaba Cloud Web Application Firewall purchase page. For this instance, Plan must be set to Hybrid Cloud WAF, and Edition must be set to Dedicated Edition.

  • Prepare the necessary resources to deploy the hybrid cloud cluster. These include:

    • Servers with the WAF agent installed

      A hybrid cloud cluster uses your on-premises servers as cluster nodes. Install the WAF agent (vagent) on a server before adding it as a cluster node. For more information, see Step 1: Install the WAF agent.

    • Load balancers

      A hybrid cloud cluster consists of Management, Storage, and Protection components. For high stability, we recommend deploying these components on separate servers. If a component includes multiple nodes, deploy a load balancer in front of the nodes.

    For resource recommendations, see Prepare cluster resources.

Prepare cluster resources

Select a deployment plan based on your protection scenario. Required resources vary by plan.

Protection scenario

Deployment plan

Required resources

Deployment details

Production services that require high security and stability.

Disaster recovery for both protection and management capabilities.

  • Default capacity (up to 10,000 HTTP QPS or 4,000 HTTPS QPS):

    Recommended: 5 servers + 2 load balancers

  • Beyond default capacity:

    Scale out Protection nodes as needed. One Protection node handles 5,000 HTTP QPS or 2,000 HTTPS QPS.

  • Storage component: 1 server

  • Management component: 2 or more servers + 1 load balancer

  • Protection component: 2 or more servers + 1 load balancer

Production services that require high business stability.

Disaster recovery for protection capabilities.

  • Default capacity (up to 10,000 HTTP QPS or 4,000 HTTPS QPS):

    Recommended: 3 servers + 1 load balancer

  • Beyond default capacity:

    Scale out Protection nodes as needed. One Protection node handles 5,000 HTTP QPS or 2,000 HTTPS QPS.

  • Management and Storage components: 1 server

  • Protection component: 2 or more servers + 1 load balancer

Proof-of-concept (POC) testing of basic protection capabilities.

Minimal cluster deployment.

  • Default capacity (up to 10,000 HTTP QPS or 4,000 HTTPS QPS):

    At least 2 servers

  • Beyond default capacity:

    Scale out Protection nodes as needed. One Protection node handles 5,000 HTTP QPS or 2,000 HTTPS QPS.

  • Management and Storage components: 1 server

  • Protection component: 1 or more servers

Procedure

  1. Log on to the Web Application Firewall console.

  2. In the left-side navigation pane, choose Systems > Hybrid Cloud Settings.

  3. Click Add Cluster.

  4. On the Add Cluster page of the Basic Information Configuration wizard, configure the parameters.

    Configure the basic information for the cluster and click Next.

    Parameter

    Description

    Cluster Name

    Enter a name for the hybrid cloud cluster.

    Protection Nodes

    Select the number of Protection nodes for the hybrid cloud cluster.

    Note

    The total number of nodes across all custom Hybrid Cloud WAF clusters cannot exceed the node quota of your Hybrid Cloud WAF instance.

    Each Protection node corresponds to one server and can handle up to 5,000 QPS of HTTP traffic or 2,000 QPS of HTTPS traffic. Select the number of cluster nodes based on the QPS of the websites that the cluster protects.

    Server Port

    Configure the protection ports for the hybrid cloud cluster. These ports must include all ports used by the websites you plan to protect. When adding a website, you can only select from these configured ports.

    Instructions:

    • By default, ports 80, 8080, 443, and 8443 are enabled. No changes are needed unless your services require other ports.

    • To add other ports, enter them manually, pressing Enter after each one.

      Protection ports cannot include the following system-reserved ports: 22, 53, 9100, 4431, 4646, 8301, 6060, 8600, 56688, 15001, 4985, 4986, and 4987.

      Warning

      We recommend configuring only the ports essential for your services to avoid security risks.

    Cluster Access Mode

    Set the network access mode for the hybrid cloud cluster. Valid values:

    • Internet: Indicates that the hybrid cloud cluster connects to the Cloud WAF console through the public network.

    • Internal Network: The hybrid cloud cluster connects to the Cloud WAF private network console over a dedicated connection.

      Important

      This mode is supported only if you have configured Express Connect.

    Remarks

    Add a description for the hybrid cloud cluster.

  5. On the Add Cluster page, click Node Group Configuration, configure the node group, and then click Next.

    You must add node groups before adding nodes.

    When adding a node group:

    • Each node group requires a load balancer for load balancing and disaster recovery.

      Note

      If you do not have a load balancer, contact WAF technical support for assistance.

    • Node group types include Storage (one per cluster), Management, Protection, and Management and Storage (one per cluster). You can add multiple Management and Protection groups for disaster recovery.

      You must add node groups in one of the following orders:

      • Method 1 (at least three node groups): Add one Storage group, then at least one Management group, and finally at least one Protection group.

      • Method 2 (at least two node groups): Add one Management and Storage group, then at least one Protection group.

    Follow these steps to add a node group.

    1. Click Add Node Group.

    2. In the Add Node Group dialog box, configure the parameters and click Save.

      The following table describes the parameters.

      Parameter

      Description

      Node Group Name

      Enter a name for the node group.

      Server IP Address for Load Balancing

      Enter the public IP address of the load balancer for this node group.

      Node Group Type

      Select a type for the node group. Valid values: Protection, Storage, Management, and Management and Storage.

      Region

      If you set Node Group Type to Protection, you must select the region where the node group is located. This parameter is optional for other node group types.

      Remarks

      Add a description for the node group.

    3. Click Save.

  6. Follow the Add Cluster configuration wizard to complete the Initial Node Configuration.

    Add your on-premises servers to the hybrid cloud cluster as cluster nodes. You must first install the WAF agent (vagent) on a server before you can add it as a node. For more information, see Step 1: Install the WAF agent.

    When adding a node:

    • The number of nodes that you add cannot exceed the protection node quota for the cluster.

    • We recommend adding at least two nodes to the Protection node group for active-active disaster recovery.

    Follow these steps to add a node to the cluster.

    1. Click Add Node.

    2. In the Add Node dialog box, configure the node parameters and click Save.

      The following table describes the parameters.

      Parameter

      Description

      Server IP Address

      Enter the public IP address of the on-premises server.

      Node Name

      Enter a name for the node.

      Region

      Select the region where the node is located.

      Server Configuration

      The server configuration information is displayed by default.

      Protection Node Group

      Select the protection node group for the node to join.

    3. Click Save.

  7. After you complete the Add Cluster wizard, the system automatically creates the cluster. This process may take several minutes.

    After the cluster is created, you can view its Basic Information at the top of the page.

    If you have multiple hybrid cloud clusters, click Switch Cluster to view a specific cluster's information.

    The basic information includes fields such as Protection Nodes (with maximum supported QPS), HTTP Port, HTTPS Port, Cluster Access Mode, Log, and Remarks. You can click Edit in the upper-right corner to modify the cluster configuration.

  8. Check the node running status in the Node Status and Application Status columns. If both columns show a green Normal, the node is running correctly. If Application Status shows a red Stopped, investigate and resolve the application error on that node.

    After the cluster is created, you can view the node and application status in the Cluster Nodes section.

    • Node Status indicates whether the server is running. A Normal status means the server is running. A Stopped status means the server is shut down.

      If a server is shut down, the node cannot provide WAF protection. Check the cause and resolve the issue as soon as possible.

    • Application Status indicates whether the WAF agent (vagent) is running. A Normal status means it is running correctly. A Stopped status means the agent has stopped.

      If the WAF agent has stopped, the node may not provide WAF protection. Log on to the on-premises server, check the installation and running status of the agent, and resolve any issues promptly. For more information, see Step 1: Install the WAF agent.

What to do next

After deploying the Hybrid Cloud WAF cluster, go to the Website Access page to add your websites to Hybrid Cloud WAF for protection.

In the Enter Your Website Information step, set Protection Resource to Hybrid Cloud Cluster and specify the Name of Protected Node Group. The remaining settings are the same as for adding a website to a public WAF cluster. For more information, see Add a website to WAF.