Web application firewall
NullWard inspects requests with the OWASP Core Rule Set (CRS 4) and any custom rule sets you add. It also inspects responses. Turn the WAF on for a service Open the service and go to Security: Turn on WAF Enabled. Choose a WAF Mode: Block: enforce the rules and show the block page. Audit only: log what would have been blocked, without blocking. Audit-only events appear under Security Events > WAF Events with the Audit only filter. Notifications and behaviour scoring are skipped in this mode. Leave OWASP Core Rule Set on. Turning it off leaves only your custom rule sets. [!TIP] Run a new service in Audit only for a while, review its WAF events, and add whitelist rules for any false positives. Then switch it to Block. How blocking decisions are made The CRS uses anomaly scoring. Each matching rule adds points by severity: critical 5, error 4, warning 3, notice 2. A request is blocked when its total reaches the Inbound Anomaly Score Threshold, and a response when its total reaches the Outbound Anomaly Score Threshold. Global WAF settings are under Settings > WAF Engine: Setting Default Notes Paranoia Level 1 1–4. Higher levels catch more evasion techniques but produce more false positives. Most deployments use 1 or 2. Inbound Anomaly Score Threshold 5 5 is strict: one critical rule blocks. 10 is a common starting point for production. 25 or more is close to detection-only. Outbound Anomaly Score Threshold 4 Applies to responses. Allowed HTTP Methods GET HEAD POST OPTIONS Space-separated. WAF Audit Logging Off Detailed per-request rule logs, for troubleshooting only. Request bodies Request bodies are inspected up to the Body Inspection Limit (default 128 KiB), however they are sent: with a Content-Length, chunked, or over HTTP/2 or HTTP/3. Over-Limit Bodies decides what happens to larger bodies: partial (default): the first part is inspected and the whole body is forwarded. An attack placed entirely after the limit isn't inspected. reject: larger bodies are refused with HTTP 413 and recorded as a WAF block. Each service can override both settings in its Security section. Raising the limit costs memory and CPU on every large request. [!NOTE] Binary uploads, such as container image pushes (application/octet-stream), are inspected too, and the CRS often blocks them. Give those endpoints a WAF bypass path or a whitelist rule. Response inspection Response headers are always checked. Turn on Response Body Inspection under Settings > WAF Engine to also check text/html, text/plain and text/xml responses, up to the Response Inspection Limit (default 128 KiB). The check looks for data leaks: SQL errors, stack traces, server error pages, directory listings and web shells. If a response reaches the outbound threshold, the visitor gets the block page instead (in audit mode the response is sent and the event is logged). Compressed responses, JSON, images, downloads, server-sent events and WebSockets aren't inspected. This setting is off by default. Whitelist rules A whitelist rule switches off specific rules for specific requests, so you can fix a false positive without weakening protection elsewhere. A rule matches when all of its conditions match: Service: one service, or Global (\*) for all. Path Pattern (regex): for example ^/api/upload$. Methods: for example POST, PUT, or * for all. Rule IDs: the rules to switch off, for example 942100, or * for all. Expires At (optional): the rule stops applying after this time. The listed rules are removed for matching requests. The rest of the rule set still runs, including the anomaly threshold. Create a rule from a WAF event The fastest way to handle a false positive: Go to Security Events > WAF Events. Events are grouped by service, path and rule, with a hit count. Click Create Rule on the event. The form is pre-filled with the service, the exact path, the method and the rule ID. Widen the path if you need to. Normalized (all IDs) matches the same path with any IDs in it, for example every…
NullWard documentation