Traffic & pipeline overview across all your domains
Requests (24h)
--
WAF blocks (24h)
--
Domains protected
--
Cert expiry, soonest
--
🛡️ Attack Overview -- last 24h, blocked requests only
🌐 Origin Domains
🌐 1. Public Ingress (Edge)
🛡️ 2. Inspection
🎯 3. Target Origin (Backend)
Action
Hostname
SSL Mode
Cert Expiration
WAF Rule Engine
Target IP / Hostname
Check Type
Origin Health
Manage
↪️ Redirect-Only Domains
Hostname
Redirects To
Code
Manage
⚖️ Security & Service Disclaimers
Before you continue, please review how ShieldIngress works and where responsibility is shared between us and you:
ShieldIngress mitigates common attacks -- it doesn't guarantee protection against everything, and you're responsible for your own application security.
WAF rules can occasionally flag legitimate traffic; you're responsible for tuning and monitoring your own rules.
Traffic is decrypted at our edge (including request bodies) to inspect it, then forwarded to your origin -- body content is inspected but never stored.
Access logs are kept for 14 days and include raw (non-anonymized) IP addresses.
Bandwidth/request figures per plan are informational, not hard limits or automatic protection against traffic spikes.
💡 Every plan starts with a 7-day free trial -- your card is charged automatically when it ends, unless you cancel first. "Manage Billing" opens Stripe's own secure billing portal in a new tab -- payment details, invoices, and cancellation all happen there, never on this page.
🔔 Real-Time Alerts
Loading…
📡 System Status
Loading…
📊 Analytics
💡 Live traffic for this domain, sampled every ~15s.
--current sessions open right now
Requests
Response codes
Bandwidth
Top Client IPs (last 60s)
Client IP
Req/min
Loading…
Top Pages (1h)
Path
Requests
Loading…
💡 Requests flagged or blocked by the WAF, most recent first. Kept for 14 days. Does not auto-refresh -- use Refresh or change the time window to update.
Window:
Time
Client IP
URI
Rule
Action
Loading…
💡 Requests to this domain, most recent first. Kept for 14 days -- for the bigger picture over time, see the Overview charts. Does not auto-refresh -- use Refresh or change the time window to update.
Window:
Time
Client IP
Country
Method
Path
Status
Time (ms)
Bytes
Backend Server
User Agent
Loading…
🕐 Change Log
💡 Every edit within the domain's currently open draft is snapshotted automatically. Revert restores IP/redirect/rate-limit/bot-challenge rules and load-balancing settings within that draft to an earlier point -- it never affects other domains, and never deploys anywhere on its own. To deploy a finished draft to staging or production, use 🚀 Revisions & Deploy instead.
🚀 Revisions & Deploy
💡
🔍 Compare Revisions
🚧 Maintenance Mode
💡 One maintenance config per domain. Turn it on instantly, or set a schedule window and it'll activate/deactivate itself automatically (checked every minute).
💡 Shown on a simple maintenance page (500 characters max).
🕐 Schedule a window (optional)
💡 Activates/deactivates automatically at these times, independent of the on-demand switch above.
👥 Team
💡 owner: full access + manage team. admin: full domain/config access. viewer: read-only everywhere.
🔐 Account Security
💡 Two-factor authentication adds a second step (a code from an authenticator app) when logging in, on top of your password. This is per-person -- each team member sets up their own.
Loading…
2FA is currently off
2FA is currently on
Scan this with your authenticator app (Google Authenticator, 1Password, Authy, etc.), or enter the code manually.
2FA enabled
Save these backup codes somewhere safe -- each works once, if you ever lose access to your authenticator app. They will not be shown again.
📜 Audit Log
💡 Every config-changing action taken by anyone on your team, most recent first.
Edit Configuration for
Redirect Settings
🔒 Current Edge Nodes
Allowing traffic only from these IPs on your origin's firewall improves security -- it stops anyone from bypassing ShieldIngress (and its WAF/rules) by connecting to your origin directly.
Connection Settings
Origin Servers
Primary Server
🔀 Path-Based Routing
💡Paths that don't match any group below still load-balance across every server as usual. Pick more than one server for a group to load-balance between just those.
⚠️ Has no effect until at least one path route exists below -- with zero groups, this is automatically ignored so the domain never goes fully dark from this toggle alone.
1. Path(s) for this group
2. Server(s) to route these path(s) to
+ define a brand-new server instead
3. Load balancing for this group (optional)
💡Retries and timeouts apply even to a single server. Algorithm and persistence only matter once this group has 2+ servers.
⚖️ Load Balancing
💡Applies across all origin servers for this domain. Off by default -- turn on to customize.
🚫 IP Access Rules
💡Block, or allow only, a specific IP or CIDR block from a path on this domain. Use * as a wildcard, e.g. /*.json or /files/secret_*/ -- a path with no * matches it and everything under it, like a prefix. Rules take effect within a few seconds. The ↑/↓ order doesn't affect enforcement -- each rule is self-contained -- it's just for organizing your own list.
✏️ Editing an existing rule -- saving will replace it.
🌍 Geo Blocking
💡Block, or allow only, specific countries from a path on this domain. Use * as a wildcard, same as IP Access Rules. Country data refreshes weekly.
✏️ Editing an existing rule -- saving will replace it.
↪️ Redirects & Rewrites
💡Redirect sends the browser a 3xx to a new URL. Rewrite silently changes the path sent to your backend -- the visitor's URL never changes. If a path also has an IP block rule, the block always takes priority.
✏️ Editing an existing rule -- saving will replace it.
⏱️ Rate Limiting
💡Limit how many requests a single client IP can make to a path within a time window. Use * as a wildcard, same as IP Access Rules. Clients over the limit get an HTTP 429 until the window resets.
✏️ Editing an existing rule -- saving will replace it.
🤖 Bot Challenge
💡Serve suspicious visitors a short JavaScript challenge before letting them through. "Heuristic" only challenges requests missing basic browser signals (no User-Agent or Accept-Language) -- real browsers pass unnoticed. "Always Challenge" locks a path down for every visitor, e.g. a login page. Use * as a wildcard, same as IP Access Rules.
✏️ Editing an existing rule -- saving will replace it.
🔒 Allowed Methods
💡Restrict which HTTP methods are allowed on specific paths -- e.g. only POST/PUT/DELETE on /api/upload. Each rule is self-contained: it only affects the path(s) you list here, every other path keeps accepting every method exactly as before. Note: your WAF's own default policy separately restricts non-standard methods (PUT/DELETE/PATCH) regardless of this setting -- if a method you allow here still gets blocked, check the WAF & Security tab or exempt it via the WAF Rule Builder.
⚠️ Off by default, and your rules stay saved either way -- toggle to pause enforcement without deleting them.
🛡️ Security Headers
💡Checks your live site's HTTP response for common security headers, then lets ShieldIngress add or remove them at the edge -- no changes to your own app required. Fixes are saved into this draft like any other rule: they only take effect once you save and deploy this revision.
Click "Check Now" to scan this domain's live HTTP response headers.
Applies once you save & deploy this revision.
Domain Ownership Verification
💡This domain won't be routed on the edge or issued an SSL certificate until you prove you control it. Add either one of these -- you only need one.
Name:
Value:
Serve this exact text (no extra whitespace) at:
🛡️ WAF Rule Builder
💡 The specific rule that fired -- matching requests will skip only this rule, not WAF inspection entirely.
💡 The rule keeps checking everything else it normally would -- only this one field is excluded from it (e.g. ARGS:content on a post editor's save endpoint, so 941320/942100-style rules stop false-positiving on legitimate rich-text HTML).