All Products
Search
Document Center

Web Application Firewall:Protect a website service by using Anti-DDoS Proxy and WAF

Last Updated:Sep 18, 2026

If your website is vulnerable to volumetric DDoS attacks and web application attacks, such as SQL injection, cross-site scripting (XSS), and command injection, use Anti-DDoS Proxy with Web Application Firewall (WAF). This topic describes how to configure the two services for layered protection.

How it works

Traffic flows through two protection layers before reaching your origin server:

Layer

Service

Threats mitigated

Ingress

Anti-DDoS Proxy

Volumetric DDoS attacks (network-layer and transport-layer floods)

Intermediate

WAF

Web application attacks, such as SQL injection, XSS, command injection, and HTTP flood attacks

Backend

Origin server, such as an ECS instance, an SLB instance, or a data center server

Receives traffic after inspection by Anti-DDoS Proxy and WAF

The following figure shows the traffic flow.

image

Usage notes

Requests pass through multiple proxies before reaching the origin server, which cannot directly obtain client IP addresses. Learn how to obtain the originating IP addresses of requests.

Prerequisites

Before you begin, complete the following prerequisites:

This topic uses WAF 3.0 as an example, but the steps also apply to WAF 2.0.

Step 1: Add your website to WAF

WAF supports CNAME record mode and cloud native mode. Review the access mode overview and select the mode that best fits your environment.

  1. Log on to the WAF 3.0 console. In the top navigation bar, select a resource group and either Chinese Mainland or Outside Chinese Mainland as the region.

  2. In the left-side navigation pane, click Onboarding.

  3. Select the CNAME Record or Cloud Native tab and complete the steps for that mode.

CNAME record mode

  1. On the CNAME Record tab, click Add.

  2. In the Configure Listener step, set the parameters and click Next. The following table provides a brief overview of the parameters. For more information, see Add a domain to WAF via CNAME.

    Parameter

    Description

    Domain Name

    Enter the domain name of your website.

    Protocol Type

    Select the protocol and ports that your website uses. Press Enter after each port number. If you select HTTPS, upload the certificate associated with the domain name. You can then enable HTTP/2 and forced HTTPS redirection, and configure the TLS version and cipher suite.

    Is a Layer 7 proxy such as Anti-DDoS Proxy or CDN deployed in front of WAF

    Select Yes. For Obtain Actual IP Address of Client, select one of the following options: <br>- Use the First IP Address in X-Forwarded-For Field as Actual IP Address of Client (default): WAF uses the first IP address in the X-Forwarded-For header as the client's originating IP address.<br>- [Recommended] Use the First IP Address in Specified Header Field as Actual IP Address of Client to Prevent X-Forwarded-For Forgery: If your proxy records originating IP addresses in a custom header, such as X-Client-IP or X-Real-IP, select this option and enter the header name in the Header Field field. A custom header prevents attackers from forging X-Forwarded-For values to bypass WAF protection.

    More Settings

    Configure IPv6 protection and exclusive IP addresses, and select a protection resource type based on your requirements.

    Resource Group

    Select the resource group for the domain name. If you leave this blank, the domain name is added to the Default Resource Group.

  3. In the Configure Forwarding Rule step, configure the parameters and click Submit.

    Parameter

    Description

    Load Balancing Algorithm

    If your origin server has multiple addresses, select a load balancing algorithm.

    Server Address

    Enter the public IP address or domain name of the origin server that receives back-to-origin requests from WAF.

    Advanced HTTPS Settings

    Specify whether to use HTTP for back-to-origin requests and enable back-to-origin SNI.

    Other Advanced Settings

    Configure Enable Traffic Mark, Retry Back-to-origin Requests, Back-to-origin Keep-alive Requests, and the connection timeout period.

  4. In the Add Completed step, copy the CNAME provided by WAF. You will use this CNAME as the origin server address in Anti-DDoS Proxy.

Cloud native mode

For more information, see Cloud native mode.

  • Use SDK module mode for Application Load Balancer (ALB), Microservices Engine (MSE), Function Compute.

  • Use reverse proxy cluster mode for Classic Load Balancer (CLB) or ECS.

Step 2: Add your website to Anti-DDoS Proxy

  1. Log on to the Anti-DDoS Proxy console.

  2. In the top navigation bar, select the region of your instance:

    • Anti-DDoS Proxy (Chinese Mainland): select Chinese Mainland.

    • Anti-DDoS Proxy (Outside Chinese Mainland): select Outside Chinese Mainland.

  3. In the left-side navigation pane, choose Onboarding > Website Config.

  4. On the Website Config page, click Add Website. Enter the required information and click Next.

    Parameter

    Description

    Function Plan

    Select the function plan of the Anti-DDoS Proxy instance.

    Instance

    Select the Anti-DDoS Proxy instance. You can associate up to eight instances with a domain name. All instances must use the same Function Plan.

    Websites

    Enter the domain name of your website.

    Protocol Type

    Select the protocol used by your website. If you select HTTPS, upload the certificate for the domain name. After selecting HTTPS, you can also enable forced HTTPS redirection and HTTP/2, and use HTTP for back-to-origin requests. Learn how to add one or more websites, including how to upload certificates, customize security policies, and enable Online Certificate Status Protocol (OCSP) stapling.

    Server Address

    - If you added the domain name to WAF in CNAME Record: select Origin Domain Name and enter the WAF CNAME obtained in Step 1.<br>- If you added the domain name to WAF in Cloud Native: select Origin IP Address and enter the public IP address of the origin server.

    Server Port

    Set based on the Protocol Type value. HTTP and WebSocket use port 80 by default; HTTPS, HTTP/2, and WebSockets use port 443 by default. Click Custom to enter additional ports, separated by commas (,).

    CNAME Reuse

    Available only for Anti-DDoS Proxy (Outside Chinese Mainland). Select whether to enable CNAME reuse. For more information, see Use the CNAME reuse feature.

  5. Configure the forwarding settings and click Next.

    Parameter

    Description

    Back-to-origin scheduling algorithm

    Controls how Anti-DDoS Proxy distributes requests across multiple origin server addresses. Three options are available:<br>- Round-robin (default): Distributes requests to all addresses in turn. All addresses have equal weight by default; you can adjust weights to route more traffic to higher-capacity servers. Use this when you need even load distribution across multiple origin servers.<br>- IP hash: Routes requests from the same client IP to the same server for a period of time, maintaining session consistency. Combined with weight settings, higher-capacity servers handle proportionally more traffic. Use this when your application requires session persistence. Note that uneven load distribution may occur in edge cases.<br>- Least time: Uses intelligent DNS resolution to route each request to the server with the lowest latency across the entire link from the protection node to the origin.

    Traffic marking

    Adds information about client requests to HTTP headers for use by downstream systems:<br>- Originating Port: Specifies the header that records the client's originating port. The default header is X-Forwarded-ClientSrcPort. To use a custom header, enter the header name here.<br>- Originating IP Address: Specifies the header that records the client's originating IP address. The default header is X-Forwarded-For. To use a custom header, enter the header name here.<br>- Custom Header: Adds up to five custom HTTP headers to back-to-origin requests. Do not use the following reserved headers: X-Forwarded-ClientSrcPort, X-Forwarded-ProxyPort, X-Forwarded-For. Do not use standard HTTP headers (such as Host, User-Agent, Connection, Upgrade) or widely-used custom headers (such as X-Real-IP, X-True-IP, X-Client-IP, Web-Server-Type, WL-Proxy-Client-IP, EagleEye-RPCID, EagleEye-TraceID, X-Forwarded-Cluster, X-Forwarded-Proto). Using these reserved headers overwrites their original values.

    Cookie settings

    Controls how Anti-DDoS Proxy handles cookies:<br>- Delivery Status (enabled by default): Anti-DDoS Proxy inserts cookies into client responses to distinguish clients and collect fingerprint information. Disabling this switch prevents Anti-DDoS Proxy from actively assessing and defending against HTTP flood attacks through HTTP flood mitigation rules.<br>- Secure Attribute (disabled by default): When enabled, cookies are delivered only over HTTPS connections, protecting them from interception. Enable this setting if your website uses HTTPS exclusively.

    Other settings

    Fine-tune connection and request handling:<br>- Configure New Connection Timeout Period: Timeout for establishing a connection to the origin server. Valid values: 1 to 10 seconds.<br>- Configure Read Connection Timeout Period: Timeout for the origin server to respond to a read request. Valid values: 10 to 300 seconds.<br>- Configure Write Connection Timeout Period: Timeout for Anti-DDoS Proxy to send all data to the origin server. Valid values: 10 to 300 seconds.<br>- Retry Back-to-origin Requests: When enabled, if a requested resource is not in cache, the cache server retrieves it from an upper-level cache or the origin server.<br>- Back-to-origin Persistent Connections: When enabled, the TCP connection between the cache server and origin server stays open after each request, reducing connection setup overhead.<br>- Requests Reusing Persistent Connections: The maximum number of HTTP requests sent over a single persistent TCP connection. Valid values: 10 to 1,000. Set this to a value less than or equal to the limit configured on the origin server (such as WAF or SLB) to prevent connection failures.<br>- Timeout Period of Idle Persistent Connections: How long an idle persistent TCP connection is kept open before being closed. Valid values: 10 to 30 seconds. Set this to a value less than or equal to the timeout configured on the origin server to prevent connection failures.<br>- Upper Limit for HTTP/2 Streams: The maximum number of concurrent HTTP/2 streams between the client and Anti-DDoS Proxy. Valid values: 16 to 32. Available only when HTTP/2 is enabled. To set a higher limit, contact your account manager.

  6. Copy the CNAME provided by Anti-DDoS Proxy.

Step 3: Update the DNS record

Point your domain name to the Anti-DDoS Proxy CNAME obtained in Step 2. The steps below use Alibaba Cloud DNS as an example. If you use a third-party DNS provider, refer to your provider's documentation.

  1. Log on to the DNS console.

  2. On the Domain Name Resolution page, find your domain name and click Settings in the Actions column.

  3. On the Settings page, find the existing DNS record and click Edit in the Actions column.

    If the DNS record does not exist in the list, click Add Record to create one.
  4. In the Modify Record (or Add Record) panel, set Record Type to CNAME and set Record Value to the Anti-DDoS Proxy CNAME.

  5. Click OK and wait for the change to propagate.

  6. Open a browser and verify that your website is accessible.

What's next