Skip to main content

Can specific paths or IP addresses be excluded from WAF protection?

Yes. Specific paths or IP addresses can be excluded, so the filter does not interfere with internal or critical services. Exclusions are configured by Aegister on request: tell your point of contact which path or address to exclude and we apply it for you.

Which addresses should my origin accept traffic from?

To prevent WAF bypass, configure your origin to accept web traffic only from Cloud Defender. Aegister gives you the addresses to allow when your domain is activated: see step 4 of the activation guide.

Can I downgrade from HTTPS to HTTP between the WAF and the protected site?

Yes, you can downgrade from HTTPS to HTTP between the WAF and the protected site, though this weakens security and we do not recommend it.

What advantages does Cloud Defender offer over solutions like AWS Cloudfront + WAF?

Cloud Defender provides IP masking, DDoS protection, a conventional WAF, and caching. What sets it apart is that it blocks traffic from malicious sources automatically, using threat intelligence data from OneFirewall. If an attacker is identified during an attack on another target, the system blocks that source from reaching your site.

Why does the blocked total not add up against the list of attacking sources?

Requests blocked before Cloud Defender began capturing the client’s address carry our CDN’s address rather than the sender’s. They are counted in the total, because they really were blocked, but they cannot be attributed to a source, so they are absent from the attacker table and reported separately in the sentence beneath the total.

My domain says “Not active” but the site is up. Why?

A domain reads Not active if the licence is not live or the health checks do not pass. The licence decides first: if it has expired, the domain is Not active even though its proxy still answers, because we are no longer contracted to protect it.

Who receives the weekly report and the alerts?

The weekly report and the email alerts are being rolled out and are not sent to customers yet. Once they are, they go only to the people ticked for Cloud Defender on Organizations → Organization users. Nothing is sent on the basis of somebody’s role, and an organization with nobody ticked receives nothing. An Owner can change it. Licence and renewal notices are separate: those go to Owners and to the administrative point of contact.