Web application firewall (WAF)

Every revenexx edge includes a managed web application firewall by default — common-attack filtering, bot mitigation, and edge rate limiting, with no setup.

A managed web application firewall protects every revenexx edge by default. It screens traffic before it reaches your application, and it's on for every tenant with no setup and nothing to configure.

What it protects against

  • Common web attacks. Requests are checked against industry-standard rules for patterns like SQL injection and cross-site scripting, and blocked before they reach the origin.
  • Bots and abuse. Automated and abusive sources, and known-bad IPs, are detected and blocked at the edge.
  • Edge rate limiting. Clients that hammer the edge are throttled or temporarily blocked close to the user, before the traffic ever reaches your application.

How it works for you

The firewall runs at the edge, in front of every point of presence, so filtering happens before requests hit the platform and adds almost no latency. It's tuned conservatively to keep legitimate traffic flowing, and it's maintained for you — there's nothing to install, no rules to write, and no plan to upgrade to. It applies to your storefronts and to the API surface alike.

If you believe legitimate traffic is being blocked, or you need a specific exception for an integration, contact us and we'll take a look.

Was this page helpful?