All Products
Search
Document Center

Web Application Firewall:Use the intelligent load balancing feature

Last Updated:Jan 10, 2024

Web Application Firewall (WAF) provides intelligent load balancing for services that are added to WAF in CNAME record mode. WAF uses the intelligent multi-node access technology to ensure that access requests to your services are automatically scheduled among multiple nodes or lines to achieve disaster recovery. This ensures high service availability and minimizes access latency.

What is intelligent load balancing?

After you enable intelligent load balancing for a WAF instance, the WAF instance is allocated at least three protection nodes in different regions to implement automatic disaster recovery across nodes and regions. WAF uses the intelligent DNS resolution feature and the least response time algorithm to minimize the path and latency when requests are forwarded to origin servers.

Intelligent load balancing applies only to a service that is added to WAF in CNAME record mode. By default, intelligent load balancing is disabled for a WAF instance. The following table describes the capabilities of a WAF instance after intelligent load balancing is enabled for the instance.

Capability

Before intelligent load balancing is enabled

After intelligent load balancing is enabled

Disaster recovery

  • Protection capabilities based on multiple single-active nodes

  • Standard failover for disaster recovery

  • Protection capabilities based on multi-node load balancing for services that are added to WAF

  • Automatic failover based on intelligent DNS resolution in case of network failures

Access acceleration

N/A

The shortest link based on the closest protection node and origin server

image

Benefits

The following table describes the benefits of intelligent load balancing.

Scenario

Business characteristic

Benefit

Architecture

Active geo-redundancy services

Multiple nodes are deployed on the cloud or in data centers across regions. The nodes simultaneously provide services and work as backups for each other to achieve disaster recovery.

Co-location multi-active services require high reliability and low access latency.

  • Automatic disaster recovery among multiple lines to achieve automatic recovery from network failures

  • Distributed health check to balance loads among multiple lines

  • Upgraded least response time algorithm to minimize latency

image

Co-location multi-active services

Multiple nodes are deployed on the cloud or in data centers in the same region. The nodes simultaneously provide services and work as backups for each other to achieve disaster recovery. Co-location multi-active services require high reliability and low access latency.

  • Automatic disaster recovery among multiple lines to achieve automatic recovery from network failures

  • Distributed health check to balance loads among multiple lines

image

Co-location single-active service

A single node is deployed on the cloud or in a data center in the same region to provide online services.

Note

Co-location single-active services do not have automatic disaster recovery capabilities. You can enable intelligent load balancing to achieve high service availability, automatic disaster recovery, and reduced access latency for the services.

  • Automatic disaster recovery among multiple lines to achieve automatic recovery from network failures

  • Distributed health check to balance loads among multiple lines

image

Billing rules

You are charged for the intelligent load balancing feature. The fees are included in the bills of the WAF instance for which you enable the feature.

After you enable intelligent load balancing for one or more domain names that are added to a WAF instance in CNAME record mode, intelligent load balancing is enabled for the WAF instance. You are charged regardless of the number of domain names. For more information about the billing rules, see Billing overview.

Enable intelligent load balancing

You can enable intelligent load balancing only for domain names that are added to WAF in CNAME record mode.

To enable intelligent load balancing, perform the following steps:

  1. On the Website Configuration page of the WAF 3.0 console, click Add on the CNAME Record tab. The Add Domain Name wizard appears.

  2. In the Configure Listener step, click More Settings and set the Protection Resource parameter to Shared Cluster-based Intelligent Load Balancing. 共享集群智能负载均衡

  3. In the Change Forwarding Rule step, set the Load Balancing Algorithm parameter to Least time. 负载均衡算法

For more information, see Add a domain name to WAF.

After you complete the preceding configurations, WAF automatically uses the intelligent DNS resolution feature and least response time algorithm to minimize the path and latency of traffic from protection nodes to origin servers.