CDN WAF & Security

Protect your websites with the built-in Web Application Firewall.

WAF Features

    1. OWASP Rules - Core Rule Set protection
    2. Custom Rules - Create your own rules
    3. Rate Limiting - Prevent abuse
    4. Bot Management - Block bad bots
    5. DDoS Protection - Layer 3/4/7 mitigation

Enable WAF

  1. Go to CDN β†’ Domain β†’ Security
  2. Toggle WAF to enabled
  3. Select protection level

Protection Levels

LevelDescription
OffNo WAF protection
LowBlock obvious attacks
MediumBalanced protection
HighMaximum protection (may have false positives)

Custom Rules

Create rules to block or allow specific traffic:

IF request.uri contains "/admin"
AND ip.src not in {office_ips}
THEN block

Rate Limiting

Prevent abuse with rate limits:

SettingExample
Requests per minute100
ActionChallenge or Block
BypassKnown good IPs

Security Headers

Add security headers automatically:

    1. X-Frame-Options
    2. X-Content-Type-Options
    3. X-XSS-Protection
    4. Content-Security-Policy

Β© 2026 ZoneCloud. All rights reserved.