tencent cloud

Web Application Firewall

Step 2: Add a domain and bind it to CLB

Download
Modo Foco
Tamanho da Fonte
Última atualização: 2026-08-03 16:49:33
Traduzido por IA
If your Web service has Tencent Cloud Application Load Balancer (CLB) enabled, you can enable precise domain protection and object default policy protection in your cloud-native WAF instance. This document guides you on how to add precise domain protection and bind the load balancer in the WAF console.

Operation Step

1. Log in to the WAF console. In the left sidebar, choose Connection Management > Domain Onboarding.
2. On the Domain Connection page, click Add Domain, select a cloud-native WAF instance, configure the relevant parameters, and click OK.
Field Description
Associated instance: Select the Cloud-native type and the corresponding Cloud-native WAF instance name.
Domain name: In the domain input box, enter the domain to protect, for example, clb.technicalsupport.cn.
Traffic source: Select CLB.
Use proxy: Select whether to use proxy services such as Anti-DDoS, CDN, or Cloud Acceleration based on your actual business requirements.
Select No: Requests received by WAF come directly from the client. WAF uses the IP address that establishes the connection with the client as the client IP address.
Select Yes: Requests received by WAF come from other layer-7 proxy services. To obtain the real client IP address for security analysis, you need to configure the client IP address determination method:
First IP in X-Forwarded-For
Network layer remote_ip (prevent XFF forgery)
IP in the specified header
Note:
It is recommended to store the client IP address in a custom Header within your business application and configure the corresponding Header field in WAF. This approach reduces the risk of attackers bypassing WAF protection rules by forging the XFF field, thereby enhancing business security.
Outside Mainland China: Select based on actual requirements.
Protected Object Group: Select the protected object group corresponding to the bound web rule template. The custom web rule template takes effect automatically.
Select the CLB Listener for the Domain: Select and configure the listener information for the access domains based on your actual requirements.
Note:
1. WAF supports protection for traffic from application cloud-native instances on both public and private networks. You can view and filter this traffic using the network type field.
2. Protection for traffic from private network application CLB instances is supported only in the Enterprise Edition and above. Editions below Enterprise Edition can be supported after being upgraded to the Enterprise Edition.
3. This feature supports access for domains associated with empty listeners (listeners without bound backend services). It is designed to protect the Web traffic generated by the default domain of a CLB instance listener and by object access to the CLB instance (for example, via a custom domain like api.example.com or direct access through the CLB's VIP).
Remarks: Enter remarks for the domain name (optional) to facilitate subsequent management and identification of the domain's purpose.
Tag: Configure resource tags for access domains. Tags can be assigned based on tag keys and values. After tags are configured, you can search for and filter domain names by tags in the domain list. Tags can also be used for billing and permission management.
Click Add Tag to add a new tag key-value pair.
You can use the Key-Value Clipboard to batch paste existing tag key-value pairs.
The system supports quickly selecting previously used tags from the Historical Records.
3. Click OK to return to the Domain Access page. On the Domain Access page, you can view information such as the domain name protected by SaaS WAF clb.technicalsupport.cn, the CLB instance's ID, name, protection mode, and origin-pull address.


Following Steps

After you have added the domain name and bound the CLB, you can proceed to Step 3: Verification Test.


Ajuda e Suporte

Esta página foi útil?

comentários