How NullWard works
NullWard is a reverse proxy with a web application firewall built in. You point your domains at NullWard, tell it where each application lives, and every request is checked before it reaches your application. The request pipeline Each request that arrives on the HTTP or HTTPS port goes through these steps, in order: Routing. The Host header picks the service: one application, with one or more hostnames and one or more backend destinations. IP checks. Per-service IP allowlists run first. Then come the global blocklist, threat feed blocks, and IP reputation lookups if you turned them on for the service. Bot challenge (optional). Visitors complete a Cloudflare Turnstile, Google reCAPTCHA or hCaptcha challenge before reaching the application. Authentication (optional). Visitors sign in with OIDC, LDAP, an emailed one-time code, Basic auth or a trusted header before they can reach the application. Access limits (optional). Path access rules, the waiting room (licensed) and per-service rate limits. Visitors over a rate limit get HTTP 429. Malware scanning (optional). Uploaded files are scanned with ClamAV. Web application firewall. The OWASP Core Rule Set and any custom rule sets inspect the request headers and body. Matching rules add to an anomaly score, and the request is blocked when the score reaches the threshold. ML WAF (licensed, optional). A machine-learning model scores the request for anomalies the rules don't catch. Proxy. The request is forwarded to a healthy backend over HTTP, HTTPS or HTTP/3, directly or through an application tunnel. Response inspection. Response headers are always checked. Text and HTML response bodies can also be checked for data leaks such as SQL errors and stack traces. A blocked visitor sees a block page that you can brand under Administration > Block Pages. Every block is recorded, and repeated bad behaviour from one IP address adds to that address's behaviour score. When the score reaches the threshold, the address is blocked automatically. Components Component Role NullWard The proxy, WAF and admin dashboard: one container. SurrealDB v2 Stores all configuration: services, rules, users and settings. Nearly every setting is changed in the dashboard and applied without a restart. Valkey ML WAF training data, rate-limit counters and caches. ClamAV (optional) Malware scanning of uploads. Ports Port Protocol Purpose Who needs to reach it 7050 TCP Proxy, HTTP Everyone (publish as port 80) 7443 TCP Proxy, HTTPS Everyone (publish as port 443) 7443 UDP HTTP/3 (QUIC), only when turned on Everyone (publish as 443/udp) 7052 TCP Management: admin dashboard and API Administrators only, from trusted IP addresses 7055 UDP Application tunnels (WireGuard), only when used Your tunnel connectors 7057 UDP Cluster mesh (WireGuard), only when clustered Other NullWard nodes The management port is deliberately separate from the public proxy ports, so it can be firewalled off from the internet. See Deploy with Docker Compose. Licensing NullWard is free to use, for both commercial and personal use, without a license. The paid features require a license, and any valid license unlocks all of them: the ML WAF, application tunnels, the waiting room (queue), high availability (clustering) and HTTP/3. See License.
NullWard documentation