OVHcloud WAF vocabulary

Glossary

Terms you will meet in the OWAF console, CRS docs, and on this protected demo site.

OWAF

Short name for OVHcloud WAF — the managed Web Application Firewall securing this site.

Anomaly score

Points accumulated from CRS rule matches. In Blocking mode, exceeding the threshold yields 403.

Blocking mode

Rejects requests whose anomaly score meets or exceeds the threshold. Origin never sees them.

Detection mode

Logs matches but still proxies traffic — ideal for baselining before enforcement.

Disabled mode

WAF enforcement off; traffic passes without CRS decisions (still via the OWAF path in alpha).

CRS 4.x

OWASP Core Rule Set version used by OWAF for SQLi, XSS, RCE, LFI, SSTI, scanners, and more.

Paranoia level

CRS strictness (four levels in OWAF). Higher levels catch more — and can raise false positives.

Virtual patch

A custom OWAF rule that blocks exploitation of a CVE until the application itself is patched.

WAF Console

Admin UI at labs.waf.ovh.net where policies, stats, and rules are managed.

Ingress IP

Address your domain must point to so clients reach OWAF first (step 3 of alpha onboarding).

Origin / backend

The application behind OWAF — here, the nginx container serving files from /var/www/waf.

European sovereignty

Requests, logs, and rules stay on OVHcloud infrastructure (alpha: Gravelines, eu-west-gra).

This site is an OWAF-protected origin

Browse the demo content freely; security decisions for hostile traffic happen on OVHcloud WAF, documented at labs.ovhcloud.com/en/owaf.