Back to WAF Simulator

Policy Designer

Test Policy

Policy Settings

🚀 Supports advanced features like CAPTCHA, JS Challenge

Managed Rule Sets

OWASP 3.2
Core web application protection

Global Exclusions

Query: returnUrl
Regex: ^/safe/.*$

Custom Rules

10
Block Admin Paths
Prevent access to administrative endpoints
BLOCK
When: Path starts with "/admin"
20
Block Malicious Bots
Block known security scanning tools
BLOCK
When: User-Agent matches regex "(sqlmap|nikto|curl/\\d+)"
30
Log Large Requests
Monitor requests with large body size
LOG
When: Body size greater than 1 MB