The Web Application Firewall (WAF) checks every request against the OWASP Core Rule Set and detects attacks such as SQL injection, cross-site scripting or command execution. You will find it in the Firewall tab with the sub-tabs Settings, Exceptions and Log.
Mode
- Detect only: Attacks are logged but not blocked. Every new site starts like this - the overview shows the date until which this test phase runs.
- Block: Detected attacks are rejected with an error page including a reference (
SC-403-WAF). - Off: no checks. Only use this briefly for troubleshooting - without the firewall, your website is not protected against attacks.
Once the test phase is over, the overview shows “Recommendation: activate blocking”. Then check the WAF log for false positives, create exceptions and switch to Block.
Check level and application profiles
- Level 1: basic protection with very few false positives - right for most websites.
- Level 2: additional rules, occasional false positives - for websites with increased protection requirements.
- Level 3: very strict, more frequent false positives - only useful with exceptions for your application.
Application profiles exclude known false positives of widely used applications: WordPress, WooCommerce, Shopware, Laravel, WoltLab, Hostware and API (JSON). Choose what runs on the site.
Attack categories
Under Attack categories you switch entire groups of rules on or off: scanner detection, protocol violations, protocol attacks, multipart attacks, local and remote files (LFI/RFI), command execution, PHP attacks, general attacks, cross-site scripting, SQL injection, session fixation and Java attacks. This is better than switching off individual rules if a category is irrelevant for your application - for example Java on a PHP website. Categories that are switched off are no longer detected, which is why the card shows a warning.
WAF log
The Log sub-tab lists all requests with rule matches from the last 30 days: time, reference, method, address, client IP, rules and action (“Blocked” or “Detected only” with the anomaly score). Matched content is shortened and sensitive values are masked. Filter by action, rule or search term; new events arrive automatically every 5 minutes, instantly with ↻. A click on the arrow shows all matches of a request with message and matched content.
Check reference
Every ShieldCache error page shows an error code and a reference. If a visitor contacts you with a reference, click Check reference at the top of the site and enter it. You will see what happened to the request: status, address, duration, user agent and all firewall matches. From there you can create an exception directly or allow the IP.
Exceptions per path
If legitimate access triggers rules - for example an editor in the admin area or an interface - create an exception. The selected rules are then switched off for this path only, and all others continue to check.
- In the WAF log, click Exception in the row of the false positive. Path and rules are pre-filled.
- Check the path and under “Applies to” choose Exactly this path or Starts with. Keep the exception as narrow as possible.
- Choose the action: Release switches the rules off and no longer logs anything. Release & log no longer blocks, but still shows matches in the WAF log with the label “released by exception” - ideal for observing an exception first. From a log entry, “Release & log” is suggested.
- Click Save and then Apply at the top.
All exceptions are listed in the Exceptions sub-tab, up to 100 per site. “Release & log” only works with request rules (910000 to 944999). The attack rules 910000 to 944999 and 950000 to 956999 can be switched off; the evaluation rules always remain active.
Exception instead of switching off site-wide
In the settings you can also switch off rules for the whole site. This then applies to all paths. An exception for the affected path only is almost always better.
How long does the test phase in “Detect only” mode last?
New sites start in “Detect only” mode, and the overview shows the end date. After that, the mode remains until you change it yourself - the overview then recommends switching.
Are IP addresses stored in the WAF log?
IP addresses are only stored in full in the log for 7 days, after which they are shortened (IPv4 to the /24 network, IPv6 to /48, label “shortened”). After 30 days, the entries are deleted. To search for a shortened IP, use the shortened form.