cdn.pizzaDocumentation

Security

WAF and protection rules

The WAF reduces common attacks but does not replace application fixes.

#Overview

The WAF reduces common attacks but does not replace application fixes.

#Compose a readable policy

Enable the appropriate mode, then add precise country, IP, or supported custom rules. Order and action determine whether a request is allowed, blocked, or challenged.

Challenge customization changes the visitor page, not the validation mechanism. After editing, follow edge synchronization and use preview before exposing traffic.

#Deploy a rule

  1. Describe the threat and expected legitimate exception.

  2. Create the narrowest possible rule.

  3. Preview the challenge and save.

  4. Synchronize, test one blocked and one legitimate request, then monitor.

#State lifecycle

StateMeaning
pendingPolicy compiled; application acknowledgement is pending.
okPolicy hash confirmed by the POP.
legacy_unverifiedResponse accepted without hash proof; verification is limited.
failedThe POP did not accept or confirm the policy.
Customer documentationReference generated from published interfaces