Skip to content

Validation rules and behavior

Configure the base location rule, trusted proxy input, request protection, responses, and runtime behavior.

Updated Aug 23, 2026

Advanced mode Start with Simple mode

This panel defines the base rule used by back-end targets and, by default, public requests.

Configure location matching

  1. Choose Whitelist or Blacklist.
  2. Enter two-letter country codes.
  3. Add state or region values with CC:State:Name only when the provider supports that precision.
  4. Turn on ASN matching only when every selected provider returns ASN data.
Advanced Location matching controls
The base list accepts countries, state or region values, and optional ASN matching.

Trust proxy input carefully

Add a server header only when a trusted reverse proxy sets and sanitizes it. Extra IP allow and block lists accept individual IPs, CIDR ranges, and AS numbers.

Advanced proxy and IP override controls
Proxy headers and explicit network overrides are separate from the country list.

Request, response, and runtime behavior

Advanced request protection, blocked response, and runtime controls
Simulation mode records decisions without blocking and is useful before a broad change.
Group Controls Use
Location matching Matching rule, country lists, ASN Defines the base geographic and network rule.
Proxy and IP overrides Server keys, extra IP allow and block lists Uses trusted proxy input and explicit network exceptions.
Request protection Bad signatures, file upload checks, metadata protection Rejects suspicious input independently of location.
Blocked response Response code, redirect URL, response message Controls the back-end response when validation blocks a request.
Runtime behavior Validation timing, simulation mode Chooses when checks run and whether they enforce or only log.

Some upload and metadata fields appear only when their parent control or host debug feature is enabled.