Type | SaaS WAF | CLB WAF |
Use case | It is suitable for all users (Tencent Cloud users and local IDC users) and can be connected through domain names by means of DNS resolution and scheduling. | It is suitable for Tencent Cloud users who have already used or plan to use Layer-7 CLB, API Gateway, or Serverless Cloud Function (SCF), as well as for those who want to combine WAF protection capabilities with APISIX or custom application gateway services. |
Strength | It is widely applicable to users in and outside Tencent Cloud. | Imperceptible connection to WAF with millisecond-level latency is implemented, which does not require adjustment of your existing network architecture. Website business forwarding and security protection are isolated from each other, and quick bypass is supported, ensuring that your website business is secure, stable, and reliable. Multi-region connection is supported. |
How to choose | If you need to protect both Tencent Cloud-hosted and local websites or layer-7 CLB is not used for your Tencent Cloud resources, you are recommended to use SaaS WAF. | If you are using or plan to use Layer-7 CLB, API Gateway, or Serverless Cloud Function (SCF) on Tencent Cloud, and have requirements for web security protection, bot traffic management, CCPC compliance, or website security operations, it is recommended to use CLB WAF. |
Region | You need to select a region when purchasing SaaS WAF | You need to select a region in the console after purchasing CLB WAF. |

Connect Type | Connect Steps |
CLB Domain Onboarding | Configure the domain and Layer-7 Load Balancer (CLB) resources (listeners) in the WAF console. This allows bypass threat detection and cleansing of HTTP/HTTPS traffic passing through the load balancer listener, achieving separation of business forwarding and security protection. |
CLB Instance Object Onboarding | Enable Layer-7 Load Balancer (CLB) instance connect to WAF in the WAF console. This allows bypass threat detection and cleansing of HTTP/HTTPS traffic passing through the load balancer instance, achieving separation of business forwarding and security protection. |
API Gateway and Serverless Cloud Function Domain Onboarding | Enable WAF protection through the API Gateway console (refer to API Gateway product documentation) and SCF console, then configure the domain in the WAF console. This allows bypass threat detection and cleansing of HTTP/HTTPS traffic passing through the API Gateway and SCF, achieving separation of business forwarding and security protection. |
API Gateway Instance Object Onboarding | Enable WAF protection in the API Gateway console (refer to API Gateway product documentation) and in the WAF console, then enable API Gateway (instance) connect to WAF. This allows bypass threat detection and cleansing of HTTP/HTTPS traffic passing through the API Gateway instance, achieving separation of business forwarding and security protection. |



Feedback