Security & SSL

Understanding Web Application Firewall (WAF)

Mitigate SQL injections, cross-site scripting (XSS), and automated bots with our built-in container WAF.

3 min read · Updated June 14, 2026

  1. Open your site cockpit and click the Security tab.
  2. Toggle WAF protection on or off. By default, standard OWASP core rule sets are active.
  3. Review the blocked request log to analyze suspicious activity.
  4. To block specific malicious IPs, enter them in the custom blocklist array.
  5. Configure rate-limiting policies to prevent brute-force attacks on login endpoints.

DockSpin WAF runs at the proxy ingress level, intercepting threats before they hit your application runtime. If a legitimate request is blocked (false positive), check the security logs, identify the matching rule ID, and adjust the posture sensitivity slider from strict to balanced. Keep blocklists clean; excessive IP bans can degrade network filtering efficiency.

Open in portalAll guides

Ready to host WordPress, Laravel, or a business site?

DockSpin manages SSL, DNS, backups, and email. You keep the files, SQL, and domain.

Verified backupsPortable site exportAutomatic SSLGoogle Drive backup you control

© 2026 DockSpin · Operated by Pioneer Ventures Technology · Hong Kong

Terms of ServicePrivacy Policy

Understanding Web Application Firewall (WAF)