Advanced mode
Start with Simple mode
This panel defines the base rule used by back-end targets and, by default, public requests.
Configure location matching
- Choose Whitelist or Blacklist.
- Enter two-letter country codes.
- Add state or region values with
CC:State:Nameonly when the provider supports that precision. - Turn on ASN matching only when every selected provider returns ASN data.

Trust proxy input carefully
Add a server header only when a trusted reverse proxy sets and sanitizes it. Extra IP allow and block lists accept individual IPs, CIDR ranges, and AS numbers.

Request, response, and runtime behavior

| Group | Controls | Use |
|---|---|---|
| Location matching | Matching rule, country lists, ASN | Defines the base geographic and network rule. |
| Proxy and IP overrides | Server keys, extra IP allow and block lists | Uses trusted proxy input and explicit network exceptions. |
| Request protection | Bad signatures, file upload checks, metadata protection | Rejects suspicious input independently of location. |
| Blocked response | Response code, redirect URL, response message | Controls the back-end response when validation blocks a request. |
| Runtime behavior | Validation timing, simulation mode | Chooses when checks run and whether they enforce or only log. |
Some upload and metadata fields appear only when their parent control or host debug feature is enabled.