Match Mode Field Description

Last Updated At: 2025-11-13 14:45:28

When setting allowlist rules, custom allow rules, custom access control, and CC protection rules, you need to configure the match method in the rules to define the request features to match. This article introduces the fields supported by the rule matching condition and their definitions.

Custom Rule Scenario

Module Name Description
Set allowlist rule Allow requests with specified characteristics to pass without testing by the rule engine.
Set custom allow rule Allow requests with specified characteristics to pass without testing by all or specific protection modules.
Note:

Protection modules: Web Protection - Rules Engine, Web Protection - malicious file detection, IP blocking, Access Control - Region Blocking, Access Control - Custom Rules, CC protection, Data leakage prevention, IP Blocklist/Allowlist, Bot Protection, API security, Mini Program Traffic Risk Control, Large Model Security

Set Access Control Rule Control access of public network users through feature matching.
Set CC protection rule Handle statistical objects with frequency anomalies that hit the match condition.

Matching Condition

Matching condition refers to the request features that Web Application Firewall (WAF) needs to detect. When setting an allowlist rule, custom allow rule, custom access control, or CC protection rule, you define the matching condition to specify the request features to detect. If a request meets the match condition set within the rules, it hits the corresponding rule. WAF then handles the request based on the rule action set in the rules (such as observation, block, or redirect).

The matching condition consists of match field, parameters, operator, and content. On the right, you can select whether the match field is case sensitive.