tencent cloud

Web Application Firewall

Cloud Custom Gateway Connection

Download
Mode fokus
Ukuran font
Terakhir diperbarui: 2026-08-03 16:49:33
Diterjemahkan oleh AI
If your business has deployed a self-built application gateway (such as Nginx, Kong, or APISIX) on Tencent Cloud and requires Web protection, you can connect a cloud-based custom gateway in the WAF console. This connection establishes network connectivity between your self-built gateway and the WAF cluster through an endpoint, enabling security protection for traffic passing through your self-built gateway. This document guides you on how to configure the cloud-based custom gateway connection, including steps such as adding a domain, creating an endpoint, and completing traffic steering.

Step 1: Configuring WAF

1. Log in to the WAF console. At the top of the left sidebar, switch the console to the region where your instance resides (Chinese mainland/Non-Chinese mainland).
2. In the left sidebar, choose Connection Management > Domain Onboarding.
3. On the Domain Onboarding page, click Add Domain.
4. In the Add Domain window, enter the relevant configuration parameters.
Field Description
Associated instance: Select the Cloud-native type and the corresponding Cloud-native WAF instance name.
Domain name: In the domain input box, enter the domain to protect, for example, test.com.
Traffic source: Select Cloud-based Custom Gateway.
Use proxy: Select whether to use proxy services such as Anti-DDoS, CDN, or Cloud Acceleration based on your actual business requirements.
Select No: Requests received by WAF come directly from the client. WAF uses the IP address that establishes the connection with the client as the client IP address.
Select Yes: Requests received by WAF come from other layer-7 proxy services. To obtain the real client IP address for security analysis, you need to configure the client IP address determination method:
First IP in X-Forwarded-For
Network layer remote_ip (prevent XFF forgery)
IP in the specified header
Note:
It is recommended to store the client IP address in a custom Header within your business application and configure the corresponding Header field in WAF. This approach reduces the risk of attackers bypassing WAF protection rules by forging the XFF field, thereby enhancing business security.
Outside Mainland China: Select based on actual requirements.
Protection object group: Select the protected object group corresponding to the bound web rule template. The custom web rule template takes effect automatically.
Remarks: Enter remarks for the domain name (optional) to facilitate subsequent management and identification of the domain's purpose.
Tag: Configure resource tags for access domains. Tags can be assigned based on tag keys and values. After tags are configured, you can search for and filter domain names by tags in the domain list. Tags can also be used for billing and permission management.
Click Add Tag to add a new tag key-value pair.
You can use the Key-Value Clipboard to batch paste existing tag key-value pairs.
The system supports quickly selecting previously used tags from the Historical Records.
5. In the Follow-up Items area in the middle of the Add Domain window, view the service information. This information is used for Step 2: Create Endpoint.


Step 2: Creating Endpoint

1. Go to the VPC console. In the left sidebar, choose Private Link > VPC Endpoint.
2. In the Region drop-down list in the upper-left corner of the Endpoint page, select the region you selected in Step 1: Configuring WAF.
3. Click Create to create an endpoint using the service information obtained in Step 1. For detailed steps, see Creating Endpoints.
4. After the creation is complete, return to the Add Domain window in the WAF console. Click OK to save the domain configuration.
5. You will return to the Domain Access page, where you can view information such as the domain name protected by SaaS WAF, Gateway Instance ID, and name.

Step 3: Verification Test

Enter the URL http://test.com/?test=alert(123) (a request simulating a Web attack) in your browser and access it. The browser returns a block page, indicating that the WAF protection feature is functioning normally.
Attention:
test.com is the example domain name in this case. Replace it with the actual domain name you added.

Bantuan dan Dukungan

Apakah halaman ini membantu?

masukan