Last update:2026-08-19 18:34:25
Reading time: About 10 minutes
Target audience: Users who have just onboarded a hostname and want to quickly establish an effective protection baseline
Different business types face different threats. Choose the configuration plan that matches your business scenario.
Suitable for corporate websites, content/information sites, and brand portals.
Configuration checklist (in order of priority):
After the observation period ends, see WAF Managed Rules Configuration Guide for instructions on safely switching to Block mode.
Suitable for e-commerce platforms, ticketing sites, and promotional campaign pages. These sites are highly susceptible to bot attacks and traffic abuse.
Configuration checklist:
High-priority actions:
/login, /api/auth): max 20 requests per IP per minuteSuitable for SaaS platforms, open platforms, and mini-program backend APIs that provide external APIs.
Configuration checklist:
Important: For pure API hostnames, configure traffic exceptions that bypass Web Bot Detection in Bot Management to avoid blocking legitimate API requests.
Suitable for video platforms, file download sites, and image CDNs. Traffic abuse is the primary risk for these services.
Configuration checklist: