tencent cloud

Web Application Firewall

Connection Method Comparison

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-08-03 16:49:33
Diterjemahkan oleh AI
The current Cloud-native WAF supports five traffic source types: CLB instances (private and public network types), Cloud Native Gateway, SCF, cloud-based custom gateways, and hybrid cloud gateways. A comparison is provided below:
Instance type
Scenarios
Core strengths
Access Mode
Supported Region
Applicable to users who are already using or plan to use Tencent Cloud public network or private network cloud-native Layer-7 CLB, such as high-concurrency Web service scenarios.
It supports two modes: mirroring and scrubbing.
It requires no architectural adjustments, supports one-click ByPass, and is stable and reliable.
It supports domain name and instance object access.
The domain name protection method achieves traffic mirroring detection and scrubbing by binding domain names to CLB listeners.
Tokyo, Moscow, Silicon Valley, Toronto, Sao Paulo, Bangkok, Hong Kong (China), Frankfurt, Mumbai, Singapore, Seoul, Riyadh, Jakarta, Virginia
Applicable to Cloud Native Gateway users, such as those in microservices architecture and API open platform scenarios, who need to centrally manage API security.
It supports the scrubbing mode.
The architecture separates forwarding from protection, with the API Gateway side controlling traffic access, resulting in greater reliability.
Associate WAF policies in API Gateway configurations to implement security protection for API traffic, supporting domain and gateway instance access. For details on the traffic access process on the Cloud Native Gateway side, see API Gateway Product Documentation.
Singapore, Hong Kong (China), Jakarta, Seoul, Bangkok, Frankfurt
Applicable to Cloud Function(SCF) users, such as serverless Web applications and event-triggered business protection.
It supports the scrubbing mode.
The architecture separates forwarding from protection, with the SCF side controlling traffic access, resulting in greater reliability.
By integrating SCF triggers with WAF, security filtering is performed on HTTP requests. For details on the traffic access process on the SCF side, see SCF Product Documentation.
Hong Kong (China), Virginia, Silicon Valley, Sao Paulo, Frankfurt, Seoul, Mumbai, Tokyo, Singapore, Bangkok
Applicable to users of self-built application gateways such as Nginx, Kong, and APISIX, who wish to centrally manage their self-built gateways via domain connection methods.
It supports the scrubbing mode.
Network connectivity is achieved through endpoints without requiring adjustments to the gateway architecture.
Add a domain in the WAF console and select Cloud Custom Gateway as the traffic source, then use endpoints to establish network connectivity between the self-built gateway and the WAF cluster.
Frankfurt, Singapore custom access
Applicable to customer traffic in various environments such as cloud and on-premises, hybrid cloud WAF deployment and access.
It is compatible with any environment.
It supports integration via SDK plugins, offering autonomy and control.
The connection method is the same as that of the Cloud Native Gateway, but requires the customer's gateway to integrate the SDK to forward business traffic to Tencent Cloud WAF Hybrid Cloud Protection Cluster.
Customer-defined regions

Domain Name Connection Method Comparison

CLB Instance: Decoupling of service forwarding and security protection is achieved by configuring domain names and layer-7 cloud-native CLB (listener) resources in the WAF console's domain name access section, which enables bypass threat detection and cleansing of HTTP/HTTPS traffic passing through the cloud-native instance's listener.

Cloud Native API Gateway and Cloud Function: After WAF protection is enabled in the API Gateway console (for details, see the API Gateway product documentation) and the SCF console, and domain names are configured in the WAF console's domain name access section, bypass threat detection and cleansing is performed on HTTP/HTTPS traffic passing through the Cloud Native Gateway and SCF gateways, achieving decoupling of service forwarding and security protection.

Cloud Custom Gateway: You can deploy application gateways such as Nginx, Kong, or APISIX on Tencent Cloud. Then, in the WAF console, add your domain name and select the cloud-based custom gateway as the traffic source, using endpoints to establish network connectivity.

Hybrid Cloud Gateway: The customer gateway integrates the SDK and forwards service traffic to the Tencent Cloud WAF hybrid cloud protection cluster.


Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan