OWAF
Short name for OVHcloud WAF — the managed Web Application Firewall securing this site.
OVHcloud WAF vocabulary
Terms you will meet in the OWAF console, CRS docs, and on this protected demo site.
Short name for OVHcloud WAF — the managed Web Application Firewall securing this site.
Points accumulated from CRS rule matches. In Blocking mode, exceeding the threshold yields 403.
Rejects requests whose anomaly score meets or exceeds the threshold. Origin never sees them.
Logs matches but still proxies traffic — ideal for baselining before enforcement.
WAF enforcement off; traffic passes without CRS decisions (still via the OWAF path in alpha).
OWASP Core Rule Set version used by OWAF for SQLi, XSS, RCE, LFI, SSTI, scanners, and more.
CRS strictness (four levels in OWAF). Higher levels catch more — and can raise false positives.
A custom OWAF rule that blocks exploitation of a CVE until the application itself is patched.
Admin UI at labs.waf.ovh.net where policies, stats, and rules are managed.
Address your domain must point to so clients reach OWAF first (step 3 of alpha onboarding).
The application behind OWAF — here, the nginx container serving files from /var/www/waf.
Requests, logs, and rules stay on OVHcloud infrastructure (alpha: Gravelines, eu-west-gra).
Browse the demo content freely; security decisions for hostile traffic happen on OVHcloud WAF, documented at labs.ovhcloud.com/en/owaf.