Web Application Firewall 提供以下可用于创建规则集和规则的阶段:
http_request_firewall_customhttp_ratelimithttp_request_firewall_managed
这些阶段存在于账户级别和区域级别。考虑到可用的阶段和两个不同的级别,规则将按以下顺序进行评估:
| 安全功能 | 范围 | 阶段 | 规则集类型 | 在仪表板中的位置 |
|---|---|---|---|---|
| 自定义规则集 |
账户 | http_request_firewall_custom |
custom(创建)root(部署) |
Go to WAF ↗ > Custom rulesets(自定义规则集) 选项卡 |
| 自定义规则 | 区域 | http_request_firewall_custom |
zone |
Go to Security rules ↗ |
| 速率限制规则集 | 账户 | http_ratelimit |
root |
Go to WAF ↗ > Rate limiting rulesets(速率限制规则集) 选项卡 |
| 速率限制规则 | 区域 | http_ratelimit |
zone |
Go to Security rules ↗ |
| 托管规则集 | 账户 | http_request_firewall_managed |
root |
Go to WAF ↗ > Managed rulesets(托管规则集) 选项卡 |
| 托管规则 | 区域 | http_request_firewall_managed |
zone |
Go to Security rules ↗ |
| 安全功能 | 范围 | 阶段 | 规则集类型 | 在仪表板中的位置 |
|---|---|---|---|---|
| 自定义规则集 |
账户 | http_request_firewall_custom |
custom(创建)root(部署) |
Go to WAF ↗ > Custom rulesets(自定义规则集) 选项卡 |
| 自定义规则 | 区域 | http_request_firewall_custom |
zone |
您的区域 > Security(安全性) > WAF > Custom rules(自定义规则) 选项卡 |
| 速率限制规则集 | 账户 | http_ratelimit |
root |
Go to WAF ↗ > Rate limiting rulesets(速率限制规则集) 选项卡 |
| 速率限制规则 | 区域 | http_ratelimit |
zone |
您的区域 > Security(安全性) > WAF > Rate limiting rules(速率限制规则) 选项卡 |
| 托管规则集 | 账户 | http_request_firewall_managed |
root |
Go to WAF ↗ > Managed rulesets(托管规则集) 选项卡 |
| 托管规则 | 区域 | http_request_firewall_managed |
zone |
您的区域 > Security(安全性) > WAF > Managed rules(托管规则) 选项卡 |
要详细了解阶段,请参阅 Ruleset Engine 文档中的阶段。