The Security Metrics dashboard shows Web Application Firewall (WAF)-identified threats. Here, you can review requests that your WAF custom rules have actively blocked or are set to alert for. This enables you to monitor how your WAF rules respond to requests by the parameters you have set and the effectiveness of your security policies.
The Rule Configuration section contains three areas for setting different security policies for your Edge WAF:
Acquia Edge Standard Standard includes pre-set WAF rulesets for common threats, such as the OWASP Top 10, which are active by default. You can review and deactivate specific rules if necessary, but this is generally not recommended.
The OWASP ruleset includes rules for:
Network protocol violations
Create a maximum of 10 custom WAF rules to handle traffic based on your specific needs. A custom WAF rule includes a name, rule logic, a response action and applies to requests that reach all or some of your domains.
Select Create custom rule.
The IP Block List enables you to manage a list of up to 100 IP addresses that you want to block. This list can be applied to custom WAF rules to prevent malicious traffic from these sources from reaching your site. The existing blocklist applies to new domains by default. You can add IPs using two methods:
Large text field: Manually paste up to 100 IP addresses, separated by commas (for example, 192.168.1.1, 192.120.1.4, 192.178.1.2).
File constraints: The file must include a maximum of 100 IP addresses and must be no larger than 5 MB.
If this content did not answer your questions, try searching or contacting our support team for further assistance.
Thu Oct 30 2025 13:14:47 GMT+0000 (Coordinated Universal Time)