Blocking or observation
The one setting that really matters after the cutover — and the only one that can leave you unprotected.
4 minUpdated
Each site has an inspection mode, set under Tools → Infrastructure. It does not decide *whether* rules run, but what happens to a request they recognise as an attack.
| Mode | Rules run | Threat is logged | Request is refused |
|---|---|---|---|
| Blocking | yes | yes | yes |
| Observation | yes | yes | no |
In observation, the site is not protected
Attacks are seen, recorded, and passed on to your server. It is a tuning phase of a few days, not a destination. The mode badge is deliberately shown in amber and never in green.
Why start in observation
An application firewall judges request content. On a real site some legitimate pages look like an attack: a quote form where people paste code, an internal search field, an integration sending XML. Without an observation phase you discover these in production, on real customers, on cutover day.
How long
Long enough for your normal traffic to have played out: a few days on a brochure site, a full order cycle on a shop. The signal to switch is not a duration but the triggered-rules table showing nothing but attacks.
Not to be confused
Observation is not the firewall being off. Off means nothing is inspected or logged; in observation everything is inspected and logged, only the refusal is suspended. A lapsed subscription produces a third case: no inspection at all.
This page did not answer your question?
Contact us