REQUEST POLICY

Traffic Controls

Apply operational controls before deeper application inspection. Combine rate policies, address decisions, country rules, bot signals, and route-specific settings around the behavior of your application.

CAPABILITIES

What it provides

  • L7 flood controls and configured block policies.
  • Geographic filtering backed by the configured GeoIP data.
  • Bot checks and supported client fingerprint signals.
  • Per-path IP rules, login protection, and scoped inspection exceptions.

DEPLOYMENT WORKFLOW

How to use it

  1. 01

    Map public endpoints, trusted proxy behavior, and expected request volumes.

  2. 02

    Configure the relevant WAF controls and path rules for the project.

  3. 03

    Review real traffic and decision logs, then adjust policy scope before tightening enforcement.

CONFIGURATION & OPERATION

Where it fits in your setup

Traffic controls live in project WAF configuration. Early flood, block, geographic, and bot controls remain effective even when a later inspection path exception is configured.

COVERAGE & LIMITS

What to account for

GeoIP data can be inaccurate and bot signals can change. Proxy topology affects the client address available to the WAF. Rate policies must account for shared IP addresses, legitimate bursts, and application workflows.

Put the policy into practice.

Follow the documentation and validate with your own workload.

Open documentation →