How-to
WAF Managed Rulesets
Learn how to use managed rulesets with the Vercel Web Application Firewall (WAF)Table of Contents
Managed rulesets are collections of predefined WAF rules based on standards such as Open Worldwide Application Security Project (OWASP) Top Ten that you can enable and configure in your project's Firewall dashboard.
WAF Managed Rulesets are available on Enterprise plans . Review pricing information here.
The following ruleset(s) are currently available:
- You need to be a Developer or Viewer in the team to view the Firewall overview page and list the rules
- You need to be a Project administrator or Team member to configure, save and apply any rule and configuration
To enable and configure OWASP Core Ruleset for your project, follow these steps:
- From your project's dashboard, select the Firewall tab
- Select the Configure button
- From the Managed Rulesets section, enable OWASP Core Ruleset
- You can apply the changes with the OWASP rules enabled by default:
- When you make any change, you will see a Review Changes button appear or update on the top right with the number of changes requested
- Select Review Changes and review the changes to be applied
- Select Publish to apply the changes to your production deployment
- Or select what OWASP rules to enable first by selecting Configure from the OWASP Core Ruleset list item
- For the OWASP Core Ruleset configuration page, enable or disable the rule that you would like to apply
- For each enabled rule, select Log Only or Deny from the action drop-down
- Use Log Only first and monitor the live traffic on the Firewall overview page to check that the rule has the desired effect when applied
- Apply the changes
- Monitor the live traffic on the Firewall overview page
Last updated on October 1, 2024
Was this helpful?