๐ง Viewing 's dashboard as Super Admin โ
Return to Admin
Dashboard
Traffic & pipeline overview across all your domains
Requests (24h)
--
WAF blocks (24h)
--
Domains protected
--
Cert expiry, soonest
--
๐ก๏ธ Attack Overview -- last 24h, blocked requests only
๐ Origin Domains
๐ 1. Public Ingress (Edge)
๐ก๏ธ 2. Inspection
๐ฏ 3. Target Origin (Backend)
Action
Hostname
SSL Mode
Cert Expiration
WAF Rule Engine
Target IP / Hostname
Check Type
Origin Health
Manage
โช๏ธ Redirect-Only Domains
Hostname
Redirects To
Code
Manage
โ๏ธ Security & Service Disclaimers
Before you continue, please review how ShieldIngress works and where responsibility is shared between us and you:
ShieldIngress mitigates common attacks -- it doesn't guarantee protection against everything, and you're responsible for your own application security.
WAF rules can occasionally flag legitimate traffic; you're responsible for tuning and monitoring your own rules.
Traffic is decrypted at our edge (including request bodies) to inspect it, then forwarded to your origin -- body content is inspected but never stored.
Access logs are kept for 14 days and include raw (non-anonymized) IP addresses.
Bandwidth/request figures per plan are informational, not hard limits or automatic protection against traffic spikes.
๐ก Every plan starts with a 7-day free trial -- your card is charged automatically when it ends, unless you cancel first. "Manage Billing" opens Stripe's own secure billing portal in a new tab -- payment details, invoices, and cancellation all happen there, never on this page.
๐ Real-Time Alerts
Loadingโฆ
๐ก System Status
Loadingโฆ
๐ Analytics
๐ก Live traffic for this domain, sampled every ~15s.
--current sessions open right now
Requests
Response codes
Bandwidth
Top Client IPs (last 60s)
Client IP
Req/min
Loadingโฆ
Top Pages (1h)
Path
Requests
Loadingโฆ
๐ก Requests flagged or blocked by the WAF, most recent first. Kept for 14 days. Does not auto-refresh -- use Refresh or change the time window to update.
Window:
Time
Client IP
URI
Rule
Action
Loadingโฆ
๐ก Requests to this domain, most recent first. Kept for 14 days -- for the bigger picture over time, see the Overview charts. Does not auto-refresh -- use Refresh or change the time window to update.
Window:
Time
Client IP
Country
Method
Path
Status
Time (ms)
Bytes
Backend Server
User Agent
Loadingโฆ
๐ Change Log
๐ก Every edit within the domain's currently open draft is snapshotted automatically. Revert restores IP/redirect/rate-limit/bot-challenge rules and load-balancing settings within that draft to an earlier point -- it never affects other domains, and never deploys anywhere on its own. To deploy a finished draft to staging or production, use ๐ Revisions & Deploy instead.
๐ Revisions & Deploy
๐ก
๐ง Maintenance Mode
๐ก One maintenance config per domain. Turn it on instantly, or set a schedule window and it'll activate/deactivate itself automatically (checked every minute).
๐ก Shown on a simple maintenance page (500 characters max).
๐ Schedule a window (optional)
๐ก Activates/deactivates automatically at these times, independent of the on-demand switch above.
๐ฅ Team
๐ก owner: full access + manage team. admin: full domain/config access. viewer: read-only everywhere.
๐ Audit Log
๐ก Every config-changing action taken by anyone on your team, most recent first.
Edit Configuration for
Redirect Settings
๐ Current Edge Nodes
Allowing traffic only from these IPs on your origin's firewall improves security -- it stops anyone from bypassing ShieldIngress (and its WAF/rules) by connecting to your origin directly.
Connection Settings
Origin Servers
Primary Server
๐ Path-Based Routing
๐กPaths that don't match any group below still load-balance across every server as usual. Pick more than one server for a group to load-balance between just those.
โ ๏ธ Has no effect until at least one path route exists below -- with zero groups, this is automatically ignored so the domain never goes fully dark from this toggle alone.
1. Path(s) for this group
2. Server(s) to route these path(s) to
+ define a brand-new server instead
3. Load balancing for this group (optional)
๐กRetries and timeouts apply even to a single server. Algorithm and persistence only matter once this group has 2+ servers.
โ๏ธ Load Balancing
๐กApplies across all origin servers for this domain. Off by default -- turn on to customize.
๐ซ IP Access Rules
๐กBlock, or allow only, a specific IP or CIDR block from a path on this domain. Use * as a wildcard, e.g. /*.json or /files/secret_*/ -- a path with no * matches it and everything under it, like a prefix. Rules take effect within a few seconds. The โ/โ order doesn't affect enforcement -- each rule is self-contained -- it's just for organizing your own list.
โ๏ธ Editing an existing rule -- saving will replace it.
๐ Geo Blocking
๐กBlock, or allow only, specific countries from a path on this domain. Use * as a wildcard, same as IP Access Rules. Country data refreshes weekly.
โ๏ธ Editing an existing rule -- saving will replace it.
โช๏ธ Redirects & Rewrites
๐กRedirect sends the browser a 3xx to a new URL. Rewrite silently changes the path sent to your backend -- the visitor's URL never changes. If a path also has an IP block rule, the block always takes priority.
โ๏ธ Editing an existing rule -- saving will replace it.
โฑ๏ธ Rate Limiting
๐กLimit how many requests a single client IP can make to a path within a time window. Use * as a wildcard, same as IP Access Rules. Clients over the limit get an HTTP 429 until the window resets.
โ๏ธ Editing an existing rule -- saving will replace it.
๐ค Bot Challenge
๐กServe suspicious visitors a short JavaScript challenge before letting them through. "Heuristic" only challenges requests missing basic browser signals (no User-Agent or Accept-Language) -- real browsers pass unnoticed. "Always Challenge" locks a path down for every visitor, e.g. a login page. Use * as a wildcard, same as IP Access Rules.
โ๏ธ Editing an existing rule -- saving will replace it.
๐ Allowed Methods
๐กRestrict which HTTP methods are allowed on specific paths -- e.g. only POST/PUT/DELETE on /api/upload. Each rule is self-contained: it only affects the path(s) you list here, every other path keeps accepting every method exactly as before. Note: your WAF's own default policy separately restricts non-standard methods (PUT/DELETE/PATCH) regardless of this setting -- if a method you allow here still gets blocked, check the WAF & Security tab or exempt it via the WAF Rule Builder.
โ ๏ธ Off by default, and your rules stay saved either way -- toggle to pause enforcement without deleting them.
๐ก๏ธ Security Headers
๐กChecks your live site's HTTP response for common security headers, then lets ShieldIngress add or remove them at the edge -- no changes to your own app required. Fixes are saved into this draft like any other rule: they only take effect once you save and deploy this revision.
Click "Check Now" to scan this domain's live HTTP response headers.
Applies once you save & deploy this revision.
Domain Ownership Verification
๐กThis domain won't be routed on the edge or issued an SSL certificate until you prove you control it. Add either one of these -- you only need one.
Name:
Value:
Serve this exact text (no extra whitespace) at:
๐ก๏ธ WAF Rule Builder
๐ก The specific rule that fired -- matching requests will skip only this rule, not WAF inspection entirely.
๐ก The rule keeps checking everything else it normally would -- only this one field is excluded from it (e.g. ARGS:content on a post editor's save endpoint, so 941320/942100-style rules stop false-positiving on legitimate rich-text HTML).