tencent cloud

Feedback

WAF Security Protection for API Gateway

Last updated: 2022-06-23 14:23:03

    This document describes how to configure WAF to protect APIs on API Gateway.

    Prerequisites

    Directions

    Step 1. Bind a custom domain name in the API Gateway console

    For more information about how to bind a custom domain name in the API Gateway console, see Custom Domain Name and Certificate.

    Note:

    When a custom domain name is bound to API Gateway, the system will check whether you have configured CNAME and resolved it to the service subdomain name. Therefore, you need to configure CNAME and resolve the custom domain name to the subdomain name of API Gateway, modify the DNS record, and point the custom domain name to the WAF CNAME domain name.

    Step 2. Configure WAF

    1. Log in to the WAF console and select Domain name list on the left sidebar.
    2. On the Domain name list page, select the target instance and click Add domain name.
    3. On the Add domain name page, configure relevant parameters and click OK.
    4. After the configuration is completed, the domain name connection status will become No CNAME records added.

    Step 3. Modify the CNAME record

    1. Modify the CNAME record at your DNS service provider and resolve the custom domain name to the WAF domain name.
    2. Log in to the WAF console, select Domain name list, and you see the Normal protection flag.
    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support