FPT Cloud WAF v1.0
I. Thông tin nổi bật
FPT Smart Cloud giới thiệu FPT Cloud WAF v1.0 thuộc nền tảng FPT Security Platform (FSP) — giải pháp Web Application Firewall dạng SaaS theo mô hình reverse proxy, bảo vệ web application và API khỏi tấn công OWASP Top 10, bot độc hại và lưu lượng bất thường.
Phiên bản này cung cấp bộ tính năng hoàn chỉnh cho FSP Admin tự quản lý toàn bộ vòng đời bảo vệ domain: onboarding nhanh qua wizard 3 bước, cấu hình security policy đa lớp (IP Rules → Rate Limit → WAF/OWASP), và theo dõi WAF logs theo thời gian thực. Dữ liệu log lưu trữ 100% tại Việt Nam.
II. Tính năng released
1. Domain List — Quản lý danh sách domain
a. Description
Màn hình Domains cung cấp cái nhìn tập trung về toàn bộ domain đang được bảo vệ. FSP Admin có thể theo dõi trạng thái bảo vệ, tình trạng TLS certificate, tìm kiếm/lọc và xóa domain không còn sử dụng.
b. Feature
- Bảng domain: Domain · Status · Origin · Certificate · Added At · Actions
- Badge Status:
Protected(xanh) /Unprotected(đỏ + tooltip động: "Certificate expired" / "WAF is disabled") - Certificate display: bình thường · near-expiry ≤ 30 ngày (amber ⚠) · expired (đỏ ✗)
- Tìm kiếm real-time theo domain name hoặc origin address
- Lọc theo Status và Certificate; kết hợp AND
- Xóa domain với confirm dialog (gõ
deleteđể xác nhận) - Phân trang: mặc định 10/page; options 10/25/50/100
c. Capacity
- Quản lý nhiều domain trên cùng tenant
2. Add Domain Wizard — Thêm domain mới
a. Description
Wizard 3 bước cho phép FSP Admin onboarding domain mới: (1) Domain & Origin, (2) TLS Certificate, (3) Provision — domain đạt trạng thái Protected.
b. Feature
- Step 1: Domain name, Origin address (domain/IPv4), Protocol, Port; validate submit-time với inline error
- Step 2: Upload/paste Certificate PEM + Private Key PEM; "Validate Certificate" → Certificate Metadata Panel
- Step 3: CNAME record + WAF egress IPs (nút Copy); "Start Provisioning" → loading modal
- Success: dialog "{domain} is now active" → "Go To Domain List" / "Add Another Domain"
- Failure: dialog lý do + 3 gợi ý + "Retry Provisioning"
- Back/Next giữ dữ liệu; cross-field validation; mutual exclusion paste ↔ upload
c. Capacity
- Hỗ trợ certificate từ mọi CA tiêu chuẩn (PEM/CRT)
- Origin address: domain name hoặc IPv4 (public + private RFC1918)
3. Domain Details — Chi tiết và quản lý domain
a. Description
Domain Details cho phép FSP Admin xem trạng thái bảo vệ, origin health, TLS certificate và truy cập Security Policies. 2 tab: Overview và Security Policies.
b. Feature
- WAF Protection Toggle: bật/tắt WAF kèm confirm dialog; WAF Off → panel cảnh báo thay tab content
- Origin card: địa chỉ origin + Health status + nút "Check Now"
- Certificate card: Source · Issuer · Expires + nút "Manage Certificate →"
- Manage Certificate popup: upload/paste cert + key → Validate → Save Changes → cập nhật ngay
c. Capacity
- Cập nhật TLS Certificate bất kỳ lúc nào mà không cần reprovisioning
4. Security Policies — Cấu hình chính sách bảo mật
a. Description
Tab Security Policies cho phép cấu hình đa lớp bảo mật qua pipeline 3 bước: IP Rules → Rate Limit → WAF/OWASP. Tất cả thay đổi được gom lại và áp dụng qua "Save Changes".
b. Feature
- Pipeline UI: 3 step button (IP Rules · Rate Limit · WAF/OWASP); IP Allow bypass thẳng đến Origin
- IP Rules: Thêm/Sửa/Xóa IP/CIDR rule; Action Allow/Block; sắp xếp theo Priority
- Rate Limit: Thêm/Sửa/Xóa rate limit rule (Priority · Path · Threshold · Window · Action · Scope); Challenge Settings card
- WAF/OWASP: Paranoia Level slider (PL1–PL4); FPT Managed Rules (read-only); Custom Rules (Priority · Name · AND conditions · Action)
- Save/Discard; Navigation guard khi Dirty
c. Capacity
- Nhiều IP/CIDR rule, rate limit rule và custom rule trên cùng domain
- Custom Rule hỗ trợ nhiều điều kiện AND
5. WAF Logs — Nhật ký traffic
a. Description
Màn hình Logs cung cấp nhật ký traffic WAF trên tất cả domain của tenant, hỗ trợ theo dõi và điều tra tấn công.
b. Feature
- Bảng logs: Time · Domain · Source IP · Attack Type · Action
- Badge Action: Blocked (đỏ) · Allowed (xanh) · Challenged ✓ (nhạt) · Challenged ✗ (cam)
- 20 loại Attack Type ánh xạ từ OWASP CRS rule ID
- Tìm kiếm real-time theo Source IP
- Lọc theo Domain · Attack Type · Action · Time range (Last 1h/6h/24h/7d/30d); kết hợp AND
- Nút "Refresh" → chèn log mới lên đầu; toast "No new logs" nếu không có gì mới
- Phân trang: mặc định 25/page; options 10/25/50/100
c. Capacity
- Hỗ trợ hiển thị tập dữ liệu log lớn với phân trang
- Lưu trữ log 100% tại Việt Nam (data residency compliant)