Configure policies by endpoint
Set WAF and access control conditions around request paths, sources, and behaviors to distinguish user operations from system calls.
Classify access to the console, open API, and static resources, and configure different protection strategies for login, query, and callback while maintaining business compatibility.
Browser users, system calls, and third-party callbacks are accessed differently. Using the same rule for all requests may affect normal API calls.
Set WAF and access control conditions around request paths, sources, and behaviors to distinguish user operations from system calls.
Configure appropriate back-to-origin and caching rules for user information, authentication, and business APIs to avoid caching personalized responses.
For multi-region deployment or self-owned infrastructure business, Anycast-Boundless’ ingress and back-to-source solutions can be further evaluated.
Mark access methods such as login, query, write, webhook and real-time connection.
Configure SCDN, HTTPS and rules, check callbacks and actual protocols used.
Based on normal requests and interception records, the thresholds and necessary exceptions are gradually refined.
Taking key interface availability and false interception as the main observation items, let the protection strategy follow business iterations.
All three types of lines support WebSocket (WS) starting from the Basic, but not the Personal. If you need WAF at the same time, you should choose the Standard or higher. When accessing, you still need to confirm the origin server and connection timeout configuration.
No. Applications still need to maintain account permissions and interface authentication; SCDN plans that support WAF add application layer protection for external access.
Have other questions?Contact a technical advisor
From personal projects to corporate operations, find the protection solution that's right for you.