The Web Application Firewall (WAF) inspects every request to your hostnames and blocks malicious ones before they're redirected. It's powered by the OWASP Core Rule Set, a widely used collection of rules against common attack patterns such as SQL injection, cross-site scripting and suspicious payloads. Available from the Business plan and up.
How it works
- Every incoming request to your hostnames is checked against the OWASP rules on our edge network, in real time.
- A request that matches a rule is blocked. It never reaches your redirect destination.
- Blocked requests show up in your analytics under the traffic type WAF blocked, so you can see what was stopped.
Enabling and overriding
Enable the WAF under More, Firewall. Enabled at team level, it applies to all your hostnames by default. You can override the team setting per hostname to switch the WAF on or off for specific domains.