WEB APPLICATION FIREWALL

Websites and APIs.
An added layer of application security.

Combine application attack protection, access rules and SCDN acceleration to configure protection before the request reaches the origin server, making security fit the actual business.

Included in SCDN · Standard and higher

Standard and higher plans on every network include WAF. Personal and Basic do not.

Website and API requests go into SCDN's built-in WAF, which is handled with a combination of application detection, access rules, and CC policies. Requests that meet the rules will continue to be returned to the source, and requests that hit the blocking rules will be blocked.
PROTECTION FOR YOUR APPLICATION

Configure protection around your requests

From request content to access source, set appropriate rules for different business paths.

Application attack protection

Configure application protection rules around common web threats such as SQL injection, XSS, and file inclusion to filter abnormal requests.

Rules for your workload

Combining rules based on URL, IP, Referer, region, User-Agent and other conditions, and working with black and white lists to refine the access scope.

Works with CC protection

Combine application request inspection with CC protection policies, and configure processing methods for page access, login portals, and interface calls respectively.

Acceleration and security, together

Manage domain names, origin servers, caches and security rules through SCDN, allowing content distribution and application protection to work along the same access path.

BUILT AROUND YOUR BUSINESS

Match protection to your traffic

01

E-commerce and transactions

Configure rules around key paths such as login, order, and payment callback to verify that normal transaction requests can be completed.

View the solution
02

Enterprise SaaS & APIs

Distinguish between user access and system calls, set access control and exceptions by interface, and retain the business's own account and permission verification.

View the solution
03

Game websites and account endpoints

Configure application protection for the official website, event pages and web login interface; game client communication can be combined with SDK shield or DDoS-protected IP solution.

View the solution
INCLUDED WITH SCDN

Included from Standard, with no separate purchase

Select a line based on the business access area, and then choose a plan that includes WAF.

WAF eligibility by network
SCDN networkWAF not includedWAF included
Mainland ChinaPersonal, BasicStandard, Professional, Business
Overseas OptimizedOverseas Personal, Overseas BasicOverseas Standard, Overseas Professional
Asia-Pacific OptimizedAsia-Pacific Personal, Asia-Pacific BasicAsia-Pacific Standard, Asia-Pacific Professional, Asia-Pacific Business
FROM CONNECTION TO PROTECTION

From integration to rule validation

  1. 01

    Choose an eligible plan

    Choose Mainland China, Overseas Optimized or Asia-Pacific Optimized routes according to user distribution, and choose Standard and higher plans.

  2. 02

    Connect your domain and configure rules

    Fill in the domain name and origin server, and configure the resolution according to the console prompts; then set the rules according to the website path, access source and business requirements.

  3. 03

    Test key application requests

    Check login, order placement, interface calls and third-party callbacks; adjust rules and necessary exceptions based on business results.

QUESTIONS & ANSWERS

Frequently asked questions

Do I need to purchase WAF separately?

WAF is included with Standard and higher SCDN plans on every network. Personal and Basic do not include WAF. Check the eligibility marks in the plan table.

How do website acceleration and WAF work together?

After the domain name is connected to the SCDN plan that supports WAF, cache, origin return and application protection rules can be set in the same website configuration. Access policies can be planned separately for static resources and dynamic interfaces.

Can I protect APIs?

Configure access rules for compatible HTTP(S) APIs. Test CC challenges and exceptions for system calls and payment callbacks, so browser challenges do not interrupt API traffic. Your application still needs authentication and access controls.

How to choose between WAF and Anycast-Boundless?

For website acceleration and application layer protection, you can choose the SCDN plan including WAF; multi-region network entrance, own business access and return-to-origin path planning can further evaluate Anycast-Boundless.

Have other questions?Contact a technical advisor

BUILD WITH CONFIDENCE

Make every connection safer.

From personal projects to corporate operations, find the protection solution that's right for you.

Contact us