Security
The Security section of the Cockpit summarizes the security status of your environment: geographic origin of blocked traffic, blocked-request volume, and WAF signals.
Web application firewall
Web Application Firewalls, or WAFs, protect web applications from common malicious attacks such as cross-site-scripting (XSS) and SQL injections. Essentially, they act as a type of wall or shield between your web application and the internet. If you have your own CDN for your project, you’ll likely have your own WAF.
If you choose to go with the default CDN for DX Cloud, you’ll be protected with the Fastly WAF.
The Fastly WAF inspects the web traffic at the HTTP application layer by looking at all HTTP and HTTPS requests (both header and body included). This can be configured specifically for your deployment.
For Fastly WAF defaults, rule packs, and tuning false positives, see Web Application Firewall (WAF) in DX Cloud Operations. In the Cockpit, blocked and passed traffic also shows up under Security statistics and in WAF request logs (filter by WAF tag).
In this section
- Security statistics — view Origin, Requests, and WAF metrics in the Cockpit