WAF Switcher

WAF Protection

The master switch, applied to the web ACLs selected above. Turning it off puts a terminating allow everything rule ahead of every other rule, so no rule in those ACLs is evaluated at all. Break-glass only.

 
    Intelligent Threat Protection

    Bot Control, Anti-DDoS and Account Takeover Prevention, plus the token rule that depends on them, on the web ACLs selected above. Turning this off switches them to count — they keep producing metrics but stop acting on traffic. Every other rule keeps protecting the API.