Monitoring flagged sources

The Next-Gen WAF monitors and flags sources (e.g., IP addresses) that exhibit repeat malicious behavior. This guide describes how to view and interact with sources that the Next-Gen WAF flagged within your data retention period.

Viewing flagged sources from the Events page

Use the Events page to view all sources that the Next-Gen WAF flagged within your data retention period as a result of criteria you set via threshold configurations and enabled CVE, API, and ATO signals.

  1. Fastly control panel
  2. Next-Gen WAF control panel

To view the Events page in the Fastly control panel:

  1. Log in to the Fastly control panel.
  2. Go to Security > Next-Gen WAF > Events.
  3. From the workspaces bar, click the menu Menu icon to the right of the workspace name and select a workspace.

For any IP address on the Events page, click the document icon Document icon to access the Event detail page for that event. The Event detail page displays event-related information. You can use this information to help determine how to handle the IP address and then:

  • click Remove flag to remove the IP address from the flag list.
  • click Convert to rule to create a rule that is based on select characteristics of the event.

Viewing suspicious, flagged, and rate limited sources

Fastly flags three types of sources: Suspicious IPs, Flagged IPs, and Rate Limited Sources. To access these lists of sources, follow the instructions for your control panel below:

  1. Fastly control panel
  2. Next-Gen WAF control panel

Use the Monitor page in the Fastly control panel to view sources that have been rate limited via the Advanced Rate Limiting feature:

  1. Log in to the Fastly control panel.
  2. Go to Security > Next-Gen WAF > Monitor.
  3. From the workspaces bar, click the menu Menu icon to the right of the workspace name and select a workspace.

Suspicious IPs tab

IMPORTANT: This feature only applies to Next-Gen WAF customers with access to the Next-Gen WAF control panel.

The Suspicious IPs tab shows sources that had requests containing attack payloads of a concerning volume but that did not exceed the decision threshold of flagged IPs. Once the threshold is met or exceeded, an IP address will be flagged and added to the Flagged IPs list. The Suspicious IPs tab helps anticipate which IPs may soon be flagged.

Clicking on an IP address in the Suspicious IPs list will take you to the Requests page with a search for that IP address already applied.

Flagged IPs tab

IMPORTANT: This feature only applies to Next-Gen WAF customers with access to the Next-Gen WAF control panel.

The Flagged IPs tab shows all IP flagging events. Sources can be flagged through threshold configurations and enabled CVE, API, and ATO signals.

Clicking on an IP address in the Flagged IPs list will take you to the Requests page with a search for that IP address already applied.

Rate Limited Sources tab

IMPORTANT: Rate Limit rules are only included with the Premier platform and certain packaged offerings. They are not included as part of the Professional or Essential platforms.

The Rate Limited Sources tab shows all sources that have been rate limited via the Advanced Rate Limiting feature. Rate limit rules are a type of rule that allow you to define arbitrary conditions and automatically begin to block, deceive, or tag requests that pass a specifically defined threshold.

The tab also provides controls for managing sources that have been rate limited, including:

  • refreshing the list with the latest sources.
  • removing specific sources from the rate limited sources list.
  • creating request rules to allow, block, or deceive specific sources.