After you add a domain name to Web Application Firewall (WAF) but before you update the domain's DNS resolution to route traffic to WAF, we recommend performing a local verification. You can do this by modifying the DNS resolution on your local computer to confirm that the WAF configuration is effective. This topic describes how to perform local verification on the Windows operating system.
Background information
By modifying the hosts file on your local computer, you can configure domain-to-address mappings that act as local DNS resolution records. For local verification, you must point the protected domain name to a WAF IP address. This setup allows you to access the protected domain name from your computer to verify the WAF configuration. This process helps prevent website access interruptions caused by configuration errors.
Prerequisites
You have manually added a website domain name using the CNAME record mode. For more information, see Manually add a website.
Procedure
This procedure uses a Windows computer as an example.
-
Open File Explorer on your local computer.
-
In the address bar, enter C:\Windows\System32\drivers\etc\hosts and open the hosts file with a text editor.
-
Add the following record to the end of the hosts file:
<WAF IP address> <protected domain name>In this record,
<protected domain name>is the domain you added to WAF, and<WAF IP address>is the corresponding WAF IP address. Separate the<WAF IP address>and the<protected domain name>with a space.-
Log on to the Web Application Firewall 3.0 console. From the top menu bar, select the resource group and region (Chinese Mainland or Outside Chinese Mainland) for the WAF instance.
-
In the left navigation pane, click Onboarding.
-
On the CNAME Record tab, locate the domain name you added and click the
icon to copy the WAF CNAME for the domain name. -
In Windows, open Command Prompt.
-
Run the following command:
ping <WAF CNAME that you copied>Pinging xxx.yundunwaf3.com [47.xxx.xxx.213] with 32 bytes of data: Reply from 47.xxx.xxx.213: bytes=32 time=31ms TTL=40 Reply from 47.xxx.xxx.213: bytes=32 time=29ms TTL=40 Reply from 47.xxx.xxx.213: bytes=32 time=28ms TTL=40 Reply from 47.xxx.xxx.213: bytes=32 time=28ms TTL=40 Ping statistics for 47.xxx.xxx.213: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milliseconds: Minimum = 28ms, Maximum = 31ms, Average = 29ms -
From the output of the
pingcommand, note the WAF IP address for the domain.Example: If the protected domain name you added to WAF is
test.aliyundoc.comand its corresponding WAF IP address is47.23.XX.XX, add the following line to the end of your hosts file:47.23.XX.XX test.aliyundoc.com
-
-
Save the modified hosts file and run the
ping <protected domain name>command to verify that the change has taken effect.The
pingcommand should resolve to the WAF IP address. This indicates that the modification to your hosts file is effective.If the command resolves to the origin IP address, flush the DNS cache by running the
ipconfig /flushdnscommand. Then, run the ping command again until the change takes effect. -
Open a web browser on your computer and enter the protected domain name in the address bar to access your site.
-
If your website loads correctly, the WAF configuration is valid. You can now restore the hosts file and change your domain's DNS resolution to route traffic through WAF for protection. For more information, see Change the DNS record of a domain name.
-
If your website does not load correctly, there may be a WAF configuration issue. Review your domain settings in WAF, fix any issues, and then repeat this verification process. For more information, see Add a domain name to WAF.
-
-
Optional: Simulate a simple web attack to verify that WAF provides protection.
For example, in your browser's address bar, enter
<protected domain name>/alert(xss).WAF should return a block page. If the block is successful, your browser displays a 405 error page with a message that access was blocked due to a potential security threat. The page also displays a request ID. This confirms that Web Application Firewall blocked the XSS attack.
-
After you complete the local verification, open the hosts file again and delete the record you added in Step 3.
ImportantIf you do not delete the record, requests from your local computer to access the protected domain name may fail.
Quickly verify CNAME with DNS commands
As an alternative to modifying the hosts file, you can use DNS query commands to directly verify the CNAME resolution status of your domain name. This method allows you to quickly troubleshoot the onboarding status of a domain name without modifying local files.
-
Use the
nslookupcommand:nslookup -type=cname <protected domain name>If the output includes a WAF CNAME, such as
xxx.c.yundunwaf2.comorxxx.yundunwaf3.com, the domain name is onboarded to WAF. -
Use the
digcommand:dig cname <protected domain name>If the CNAME record in the
ANSWER SECTIONof the output points to the WAF CNAME, the domain name is onboarded to WAF.
These commands verify only the CNAME resolution status at the DNS level. To verify the protection capabilities of WAF, such as blocking a web attack, you must still modify the hosts file to bind the WAF IP address and then access the protected domain name to test the protection. For more information, see Procedure.