Threat protection
Besides the WAF, NullWard can block bad traffic by IP address, reputation and behaviour, challenge bots, and scan uploads for malware. These features are under Threat Intelligence and Malware Detection in the sidebar, and are turned on per service. Blocklist Threat Intelligence > Blocklist lists every blocked IP address and range, with its source: Manual: added by an administrator. Behavior: blocked automatically when its behaviour score reached the threshold. IP Intel: blocked because of its reputation. Feed: imported from a threat feed. Click Block IP to block an IP or CIDR range, for all services or one service, for a set number of minutes (0 = permanent). Unblock removes a block. In a cluster, manual, behaviour and IP-intel blocks apply on every node. Behaviour scoring and automatic blocking Every WAF block, rate-limit hit, failed sign-in and (optionally) backend 4xx error adds points to the client IP's behaviour score. Points fade over time. When the score reaches the Auto-Block Threshold, the IP is blocked on all services for the Block Duration. Settings are under Settings > Behavior Scoring: Setting Default Auto-Block Threshold 100 Scoring Window (minutes) 60 Block Duration (minutes) 30 (0 = permanent) WAF Block Weight 10 Rate Limit Weight 3 Auth Failure Weight 34 Tunnel Auth Failure Weight 25 HTTP Error Weight 2 With the defaults, 10 WAF blocks or 3 failed sign-ins within the window block an IP. Threat Intelligence > Behavior Scores shows current scores, with buttons to reset a score or block the IP. To make sure your own networks are never auto-blocked, add them under Settings > Trusted IPs. Trusted addresses are exempt from behaviour scoring and auto-blocking on all services. Threat feeds Threat Intelligence > Threat Feeds imports lists of known-bad IPs into the blocklist on a schedule. Feed types: CrowdSec: pull the community blocklist, and optionally push your own detections. Needs a CrowdSec API key. AbuseIPDB: pull addresses reported with high confidence. Needs an AbuseIPDB API key. Plain Text URL: any URL that returns one IP or CIDR per line. Comments starting with # are ignored. Feed Library adds well-known public feeds in one click, including IPsum, Blocklist.de, GreenSnow, Binary Defense and Emerging Threats. For each feed you set the Pull Interval, the Block Duration for imported addresses, and a Max Entries cap. Each node pulls its feeds itself. Deleting a feed removes its addresses from the blocklist. IP intelligence Threat Intelligence > IP Intel connects a reputation service (AltusIris or IPLocate) that scores each visitor IP from 0 to 100. Add the provider with its API key and a block Threshold, and use Test to look up an address. Then turn it on per service under IP Intelligence: Lookup Mode: Synchronous checks before the request continues. Asynchronous lets the request through and blocks the IP on that service if it's flagged. Action Override: block, log only or challenge. Block Classifications and Blocked Countries: block by threat type or by country. IP Intel Bypass IPs / CIDRs: addresses that are never checked. Private addresses are never looked up. If the provider can't be reached, requests are allowed. IP allowlists An IP allowlist restricts a service to known networks, for example an internal tool that only your office and VPN should reach. Create a list under Threat Intelligence > IP Allowlists with Add Allowlist, entering one IP or CIDR per line. On the service, under IP Allowlist, select the list. The allowlist is checked before every other security layer. All other IP addresses get a 403. To restrict the admin dashboard itself, use Settings > Security > Admin IP Allowlist. See Deploy with Docker Compose. Bot detection Bot detection makes visitors pass a CAPTCHA-style challenge before reaching a service. Add a provider under Access Control > Bot Providers: Cloudflare Turnstile, Google reCAPTCHA or hCaptcha, with its site key and secret key. On the service, under Bot Detection, turn on Bot…
NullWard documentation