DDoS protection stops floods automatically — but sometimes you want precise, application-specific control. This release ships a full Web Application Firewall with custom rules.
Write rules that match on request path, headers, method, country or client fingerprint, then decide whether to allow, block or challenge the request. Rules are authored in the dashboard with typed fields and dropdowns (no fragile freeform syntax) and enforced at the edge across every point of presence — no origin round-trip.
It is the foundation the newer IP reputation filtering builds on, letting you combine "who" and "what" in a single policy. To understand the attacks these rules stop, read What is a Layer 7 DDoS attack?