FPT Cloud WAF v1.0
I. Highlights
FPT Smart Cloud introduces FPT Cloud WAF v1.0 as part of the FPT Security Platform (FSP) — a SaaS Web Application Firewall operating as a reverse proxy to protect web applications and APIs from OWASP Top 10 attacks, malicious bots, and abnormal traffic.
This release delivers a complete feature set for FSP Admins to self-manage the full domain protection lifecycle: fast onboarding via a 3-step wizard, multi-layer security policy configuration (IP Rules → Rate Limit → WAF/OWASP), and real-time WAF log monitoring. With a clear pipeline architecture and intuitive interface, WAF v1.0 helps Security and DevOps teams reduce setup time and improve web application risk control — with log data stored 100% in Vietnam.
II. Released Features
1. Domain List — Manage the domain list
a. Description
The Domains screen provides a centralized view of all domains protected by FPT Cloud WAF in the tenant. FSP Admins can monitor protection status and TLS certificate health, search and filter, and delete domains no longer in use.
b. Features
- Domain table: Domain · Status · Origin · Certificate · Added At · Actions
- Status badge:
Protected(green) /Unprotected(red + dynamic tooltip: "Certificate expired" / "WAF is disabled") - Certificate display: normal · near-expiry ≤ 30 days (amber ⚠) · expired (red ✗)
- Real-time search by domain name or origin address
- Filter by Status (Protected/Unprotected) and Certificate (Valid/Expired); AND logic
- Delete domain with confirm dialog (type
deleteto confirm) - Pagination: 10 per page default; options 10/25/50/100
c. Capacity
- Supports managing multiple domains per tenant
- Pagination optimized for large domain counts
2. Add Domain Wizard — Add a new domain
a. Description
A 3-step wizard lets FSP Admins onboard new domains to FPT Cloud WAF: (1) Domain & Origin, (2) TLS Certificate, (3) Provision — completing provisioning to achieve Protected status.
b. Features
- Step 1 — Domain & Origin: enter Domain name, Origin address (domain/IPv4), Protocol (https/http), Port; submit-time validation with inline errors
- Step 2 — TLS Certificate: upload/paste Certificate PEM + Private Key PEM (required), Certificate Chain (optional); "Validate Certificate" → Certificate Metadata Panel (Common name · Issuer · Expiry · Key algorithm · Subject alternative names · Domain match)
- Step 3 — Provision: displays CNAME record + WAF egress IPs (with Copy buttons); "Start Provisioning" → blocking loading modal
- Success: "{domain} is now active" dialog → "Go To Domain List" or "Add Another Domain"
- Failure: "Provisioning Failed" dialog + reason + 3 remediation suggestions + "Retry Provisioning"
- Back/Next preserves entered data; cross-field validation:
https+ port80→ error - Mutual exclusion: paste text ↔ file upload per Certificate and Private Key field
c. Capacity
- Supports certificates from any standard CA (DigiCert, GlobalSign, etc.) in PEM/CRT format
- Supports Origin address as domain name or IPv4 (public + private RFC1918)
3. Domain Details — View and manage domain
a. Description
Domain Details lets FSP Admins view protection status, origin health, TLS certificate, and access Security Policies for a specific domain. Two tabs: Overview and Security Policies.
b. Features
- WAF Protection Toggle: enable/disable WAF with confirm dialog; WAF Off → warning panel replaces tab content
- Origin card: origin address + Health status (Healthy/Unhealthy) + "Check Now" button
- Certificate card: Source · Issuer · Expires (amber near-expiry / red expired) + "Manage Certificate →" button
- Manage Certificate popup: upload/paste new cert + key → Validate → Save Changes → Certificate card updates immediately
- Domain status badge (Protected/Unprotected) consistent with Domain List
- Domain not found → toast "Domain not found." → auto-redirect to Domain List
c. Capacity
- TLS certificate can be updated at any time without re-provisioning
4. Security Policies — Configure security policy
a. Description
The Security Policies tab lets FSP Admins configure multi-layer security for each domain via a 3-step pipeline: IP Rules → Rate Limit → WAF/OWASP. All changes are drafted and applied together via "Save Changes".
b. Features
- Pipeline UI: 3 step buttons (1. IP Rules · 2. Rate Limit · 3. WAF / OWASP) — clear rule evaluation order; IP Allow bypasses directly to Origin
- Step 1 — IP Rules: Add/Edit/Delete IP/CIDR rules (comma-separated multi-value on Add); Action Allow/Block; ordered by Priority
- Step 2 — Rate Limit: Add/Edit/Delete rate limit rules (Priority · Path · Threshold · Window · Action Block/Challenge · Scope Per IP/Per IP+Path); Challenge Settings card with Browser Verification Challenge preview
- Step 3 — WAF/OWASP:
- Paranoia Level slider (PL1–PL4) with real-time description update
- FPT Managed Rules — read-only table (Rule ID · Name · Category: Fraud/CVE/Webshell/Bot/Upload)
- Custom Rules (Priority · Rule name · Match conditions AND · Action: Block/Allow/Challenge/Log only)
- Save/Discard: always visible; disabled in Clean state, enabled in Dirty state; Discard requires confirm dialog
- Navigation guard: attempt to leave while Dirty → "Unsaved Changes" dialog (Stay / Leave Anyway)
c. Capacity
- Supports multiple IP/CIDR rules, rate limit rules, and custom rules per domain
- Custom Rule supports multiple AND conditions (Field/Operator/Value)
5. WAF Logs — Traffic log monitoring
a. Description
The Logs screen provides a traffic log of all WAF activity across all tenant domains, helping FSP Admins monitor blocked requests, investigate attack patterns, and verify policy effectiveness.
b. Features
- Log table: Time · Domain · Source IP · Attack Type · Action
- Action badge: Blocked (red) · Allowed (green) · Challenged ✓ (light) · Challenged ✗ (amber)
- 20 Attack Types mapped from OWASP CRS rule IDs (SQL Injection, XSS, RCE, LFI, RFI, SSRF, DoS, IP Reputation, Scanner, Web Shell, etc.)
- Real-time search by Source IP (Like %text%)
- Filter by Domain (dynamic from tenant) · Attack Type · Action · Time range (Last 1h/6h/24h/7d/30d)
- All filters combine with AND; × button clears each filter individually
- "Refresh" → inserts new logs at the top (preserves filters); toast "No new logs" if nothing new
- Pagination: 25 per page default; options 10/25/50/100; counter "Showing X–Y of N"
c. Capacity
- Supports display and pagination of large log datasets
- Log data stored 100% in Vietnam (data residency compliant)