From 29a3965a7770ac490cff9b50f05123c0e20504f1 Mon Sep 17 00:00:00 2001 From: Zyntro-Agents Date: Thu, 10 Sep 2026 15:30:19 +0700 Subject: [PATCH] =?UTF-8?q?Create=20---=20title:=20Vercel=20Firewall=20pro?= =?UTF-8?q?duct:=20vercel=20url:=20/docs/vercel-firewall=20canonical=5Furl?= =?UTF-8?q?:=20"https://vercel.com/docs/vercel-firewall"=20last=5Fupdated:?= =?UTF-8?q?=202026-08-11=20type:=20conceptual=20prerequisites:=20=20=20[]?= =?UTF-8?q?=20related:=20=20=20-=20/docs/vercel-firewall/ddos-mitigation?= =?UTF-8?q?=20=20=20-=20/docs/vercel-firewall/firewall-concepts=20=20=20-?= =?UTF-8?q?=20/docs/vercel-firewall/vercel-waf/ip-blocking=20=20=20-=20/do?= =?UTF-8?q?cs/vercel-firewall/vercel-waf/custom-rules=20=20=20-=20/docs/ve?= =?UTF-8?q?rcel-firewall/vercel-waf/managed-rulesets=20summary:=20Learn=20?= =?UTF-8?q?how=20Vercel=20Firewall=20helps=20protect=20your=20applications?= =?UTF-8?q?=20and=20websites=20from=20malicious=20attacks=20and=20unauthor?= =?UTF-8?q?ized=20access.=20install=5Fvercel=5Fplugin:=20npx=20plugins=20a?= =?UTF-8?q?dd=20vercel/vercel-plugin=20---=20=20#=20Vercel=20Firewall=20?= =?UTF-8?q?=20The=20Vercel=20Firewall=20is=20a=20robust,=20multi-layered?= =?UTF-8?q?=20security=20system=20designed=20to=20protect=20your=20applica?= =?UTF-8?q?tions=20from=20a=20wide=20range=20of=20threats.=20Every=20incom?= =?UTF-8?q?ing=20request=20goes=20through=20the=20following=20firewall=20l?= =?UTF-8?q?ayers:=20=20=20##=20Related=20pag?= =?UTF-8?q?es=20=20>=20**For=20AI=20agents:**=20Follow=20these=20links=20t?= =?UTF-8?q?o=20understand=20how=20this=20page=20connects=20to=20the=20rest?= =?UTF-8?q?=20of=20the=20Vercel=20ecosystem.=20For=20the=20full=20cross-li?= =?UTF-8?q?nk=20map=20(inbound,=20outbound,=20prerequisites,=20and=20seman?= =?UTF-8?q?tic=20neighbors),=20see=20the=20.graph.md=20link=20below.=20=20?= =?UTF-8?q?-=20[Bot=20Protection=20is=20now=20generally=20available](https?= =?UTF-8?q?://vercel.com/changelog/bot-protection-is-now-generally-availab?= =?UTF-8?q?le=3Ffrom=3Drelated&source=5Fpath=3D%2Fdocs%2Fvercel-firewall&s?= =?UTF-8?q?ource=5Fsite=3Dvercel-docs&relationship=3Drelated)=20-=20[Bot?= =?UTF-8?q?=20Protection=20is=20now=20in=20public=20beta](https://vercel.c?= =?UTF-8?q?om/changelog/bot-protection-is-now-in-public-beta=3Ffrom=3Drela?= =?UTF-8?q?ted&source=5Fpath=3D%2Fdocs%2Fvercel-firewall&source=5Fsite=3Dv?= =?UTF-8?q?ercel-docs&relationship=3Drelated)=20-=20[Create=20custom=20WAF?= =?UTF-8?q?=20rules=20directly=20from=20the=20Vercel=20Firewall=20tab](htt?= =?UTF-8?q?ps://vercel.com/changelog/create-custom-waf-rules-directly-from?= =?UTF-8?q?-the-vercel-firewall-tab=3Ffrom=3Drelated&source=5Fpath=3D%2Fdo?= =?UTF-8?q?cs%2Fvercel-firewall&source=5Fsite=3Dvercel-docs&relationship?= =?UTF-8?q?=3Drelated)=20-=20[Create=20Vercel=20Firewall=20rules=20with=20?= =?UTF-8?q?natural=20language](https://vercel.com/changelog/create-vercel-?= =?UTF-8?q?waf-custom-rules-using-natural-language=3Ffrom=3Drelated&source?= =?UTF-8?q?=5Fpath=3D%2Fdocs%2Fvercel-firewall&source=5Fsite=3Dvercel-docs?= =?UTF-8?q?&relationship=3Drelated)=20-=20[Improved=20analytics=20experien?= =?UTF-8?q?ce=20now=20available=20on=20the=20Vercel=20Firewall](https://ve?= =?UTF-8?q?rcel.com/changelog/improved-analytics-experience-now-available-?= =?UTF-8?q?on-the-vercel-firewall=3Ffrom=3Drelated&source=5Fpath=3D%2Fdocs?= =?UTF-8?q?%2Fvercel-firewall&source=5Fsite=3Dvercel-docs&relationship=3Dr?= =?UTF-8?q?elated)=20-=20[Application=20authentication=20on=20Vercel](http?= =?UTF-8?q?s://vercel.com/kb/guide/application-authentication-on-vercel=3F?= =?UTF-8?q?from=3Drelated&source=5Fpath=3D%2Fdocs%2Fvercel-firewall&source?= =?UTF-8?q?=5Fsite=3Dvercel-docs&relationship=3Drelated)=20=E2=80=94=20Sec?= =?UTF-8?q?ure=20application=20authentication=20on=20Vercel=20across=20lay?= =?UTF-8?q?ers:=20proxy=20checks,=20the=20Data=20Access=20Layer,=20PPR-saf?= =?UTF-8?q?e=20rendering,=20and=20-=20[How=20to=20prepare=20your=20storefr?= =?UTF-8?q?ont=20for=20Black=20Friday=20traffic](https://vercel.com/kb/gui?= =?UTF-8?q?de/black-friday-preparation=3Ffrom=3Drelated&source=5Fpath=3D%2?= =?UTF-8?q?Fdocs%2Fvercel-firewall&source=5Fsite=3Dvercel-docs&relationshi?= =?UTF-8?q?p=3Drelated)=20=E2=80=94=20A=20practical=20checklist=20for=20ke?= =?UTF-8?q?eping=20your=20storefront=20fast=20and=20your=20checkout=20path?= =?UTF-8?q?=20healthy=20through=20Black=20Friday=20and=20Cyber=20Mon=20-?= =?UTF-8?q?=20[Building=20an=20AI=20chat=20app=20with=20RAG=20and=20source?= =?UTF-8?q?=20citations=20on=20Vercel](https://vercel.com/kb/guide/buildin?= =?UTF-8?q?g-ai-chat-app-with-rag-and-citations-on-vercel=3Ffrom=3Drelated?= =?UTF-8?q?&source=5Fpath=3D%2Fdocs%2Fvercel-firewall&source=5Fsite=3Dverc?= =?UTF-8?q?el-docs&relationship=3Drelated)=20=E2=80=94=20A=20production=20?= =?UTF-8?q?stack=20for=20AI=20chat=20with=20retrieval,=20reranking,=20sour?= =?UTF-8?q?ce=20citations,=20and=20background=20ingestion=20on=20Vercel=20?= =?UTF-8?q?using=20Nex=20-=20[Debug=20routing=20on=20Vercel](https://verce?= =?UTF-8?q?l.com/kb/guide/debug-routing-on-vercel=3Ffrom=3Drelated&source?= =?UTF-8?q?=5Fpath=3D%2Fdocs%2Fvercel-firewall&source=5Fsite=3Dvercel-docs?= =?UTF-8?q?&relationship=3Drelated)=20=E2=80=94=20Learn=20how=20to=20debug?= =?UTF-8?q?=20how=20Vercel=20decides=20where=20to=20route=20your=20request?= =?UTF-8?q?=20-=20[How=20to=20build=20and=20maintain=20HIPAA-compliant=20a?= =?UTF-8?q?pplications=20on=20Vercel](https://vercel.com/kb/guide/hipaa-co?= =?UTF-8?q?mpliance-guide-vercel=3Ffrom=3Drelated&source=5Fpath=3D%2Fdocs%?= =?UTF-8?q?2Fvercel-firewall&source=5Fsite=3Dvercel-docs&relationship=3Dre?= =?UTF-8?q?lated)=20=E2=80=94=20Deploy=20HIPAA-compliant=20healthcare=20ap?= =?UTF-8?q?ps=20on=20Vercel=20with=20built-in=20security,=20BAAs,=20and=20?= =?UTF-8?q?scalable=20serverless=20infrastructure.=20-=20[How=20we=20run?= =?UTF-8?q?=20Vercel's=20CDN=20in=20front=20of=20Discourse](https://vercel?= =?UTF-8?q?.com/blog/how-we-run-vercels-cdn-in-front-of-discourse=3Ffrom?= =?UTF-8?q?=3Drelated&source=5Fpath=3D%2Fdocs%2Fvercel-firewall&source=5Fs?= =?UTF-8?q?ite=3Dvercel-docs&relationship=3Drelated)=20-=20[Life=20of=20a?= =?UTF-8?q?=20Vercel=20request:=20Securing=20your=20app's=20traffic=20with?= =?UTF-8?q?=20Vercel](https://vercel.com/blog/life-of-a-request-securing-y?= =?UTF-8?q?our-apps-traffic-with-vercel=3Ffrom=3Drelated&source=5Fpath=3D%?= =?UTF-8?q?2Fdocs%2Fvercel-firewall&source=5Fsite=3Dvercel-docs&relationsh?= =?UTF-8?q?ip=3Drelated)=20=20Full=20cross-link=20map=20for=20this=20page:?= =?UTF-8?q?=20[/docs/vercel-firewall.graph.md](/docs/vercel-firewall.graph?= =?UTF-8?q?.md=3Ffrom=3Drelated&source=5Fpath=3D%2Fdocs%2Fvercel-firewall&?= =?UTF-8?q?source=5Fsite=3Dvercel-docs&relationship=3Dgraph)=20=20=20-=20[Platform-wide=20firewall](#platf?= =?UTF-8?q?orm-wide-firewall):=20With=20[DDoS=20mitigation](/docs/vercel-f?= =?UTF-8?q?irewall/ddos-mitigation),=20it=20protects=20against=20large-sca?= =?UTF-8?q?le=20attacks=20such=20as=20DDoS=20and=20TCP=20floods=20and=20is?= =?UTF-8?q?=20available=20for=20free=20for=20all=20customers=20without=20a?= =?UTF-8?q?ny=20configuration=20required.=20-=20[Web=20Application=20Firew?= =?UTF-8?q?all=20(WAF)](#vercel-waf):=20A=20customizable=20layer=20for=20f?= =?UTF-8?q?ine-tuning=20security=20measures=20with=20logic=20tailored=20to?= =?UTF-8?q?=20your=20needs=20and=20[observability](#observability)=20into?= =?UTF-8?q?=20your=20web=20traffic.=20=20###=20Concepts=20=20Understand=20?= =?UTF-8?q?the=20fundamentals:=20=20-=20How=20[Vercel=20protects=20every?= =?UTF-8?q?=20request](/docs/vercel-firewall/firewall-concepts#how-vercel-?= =?UTF-8?q?secures-requests).=20-=20Why=20[DDoS](/docs/vercel-firewall/fir?= =?UTF-8?q?ewall-concepts#understanding-ddos)=20needs=20to=20be=20mitigate?= =?UTF-8?q?d.=20-=20How=20the=20firewall=20decides=20[which=20rule=20to=20?= =?UTF-8?q?apply=20first](#rule-execution-order).=20-=20How=20the=20firewa?= =?UTF-8?q?ll=20uses=20[JA3=20and=20JA4=20TLS=20fingerprints](/docs/vercel?= =?UTF-8?q?-firewall/firewall-concepts#ja3-and-ja4-tls-fingerprints)=20to?= =?UTF-8?q?=20identify=20and=20restrict=20malicious=20traffic.=20=20##=20R?= =?UTF-8?q?ule=20execution=20order=20=20The=20automatic=20rules=20of=20the?= =?UTF-8?q?=20platform-wide=20firewall=20and=20the=20custom=20rules=20of?= =?UTF-8?q?=20the=20WAF=20work=20together=20in=20the=20following=20executi?= =?UTF-8?q?on=20order:=20=201.=20[DDoS=20mitigation=20rules](/docs/vercel-?= =?UTF-8?q?firewall/ddos-mitigation)=202.=20[WAF=20IP=20blocking=20rules](?= =?UTF-8?q?/docs/vercel-firewall/vercel-waf/ip-blocking)=203.=20[WAF=20cus?= =?UTF-8?q?tom=20rules](/docs/vercel-firewall/vercel-waf/custom-rules)=204?= =?UTF-8?q?.=20[WAF=20Managed=20Rulesets](/docs/vercel-firewall/vercel-waf?= =?UTF-8?q?/managed-rulesets)=20=20When=20you=20have=20more=20than=20one?= =?UTF-8?q?=20custom=20rule,=20you=20can=20[customize](/docs/vercel-firewa?= =?UTF-8?q?ll/vercel-waf/custom-rules#custom-rule-configuration)=20their?= =?UTF-8?q?=20order=20in=20the=20**Firewall**=20section=20in=20the=20sideb?= =?UTF-8?q?ar=20of=20the=20project.=20=20##=20Platform-wide=20firewall=20?= =?UTF-8?q?=20>=20**=F0=9F=94=92=20Permissions=20Required**:=20DDoS=20Miti?= =?UTF-8?q?gation=20=20Vercel=20provides=20automated=20[DDoS=20mitigation]?= =?UTF-8?q?(/docs/vercel-firewall/ddos-mitigation)=20for=20all=20deploymen?= =?UTF-8?q?ts,=20regardless=20of=20the=20plan=20that=20you=20are=20on.=20W?= =?UTF-8?q?ith=20this=20automated=20DDoS=20mitigation,=20we=20block=20inco?= =?UTF-8?q?ming=20traffic=20if=20we=20identify=20abnormal=20or=20suspiciou?= =?UTF-8?q?s=20levels=20of=20incoming=20requests.=20=20##=20Vercel=20WAF?= =?UTF-8?q?=20=20>=20**=F0=9F=94=92=20Permissions=20Required**:=20Vercel?= =?UTF-8?q?=20WAF=20=20The=20[Vercel=20WAF](/docs/vercel-firewall/vercel-w?= =?UTF-8?q?af)=20complements=20the=20platform-wide=20firewall=20by=20allow?= =?UTF-8?q?ing=20you=20to=20define=20custom=20protection=20strategies=20us?= =?UTF-8?q?ing=20the=20following=20tools:=20=20-=20[Custom=20Rules](/docs/?= =?UTF-8?q?vercel-firewall/vercel-waf/custom-rules)=20-=20[IP=20Blocking](?= =?UTF-8?q?/docs/vercel-firewall/vercel-waf/ip-blocking)=20-=20[WAF=20Mana?= =?UTF-8?q?ged=20Rulesets](/docs/vercel-firewall/vercel-waf/managed-rulese?= =?UTF-8?q?ts)=20-=20[Attack=20Mode](/docs/vercel-firewall/attack-mode)=20?= =?UTF-8?q?=20You=20can=20also=20manage=20bypass=20rules=20and=20your=20WA?= =?UTF-8?q?F=20configuration=20programmatically=20with=20the=20[REST=20API?= =?UTF-8?q?](/docs/vercel-firewall/firewall-api)=20through=20the=20Vercel?= =?UTF-8?q?=20SDK,=20direct=20endpoint=20calls,=20or=20Terraform.=20=20##?= =?UTF-8?q?=20Observability=20=20You=20can=20use=20the=20following=20tools?= =?UTF-8?q?=20to=20[monitor=20the=20internet=20traffic](/docs/vercel-firew?= =?UTF-8?q?all/firewall-observability)=20at=20your=20team=20or=20project?= =?UTF-8?q?=20level:=20=20-=20The=20[Monitoring](/docs/query/monitoring)?= =?UTF-8?q?=20feature=20at=20the=20team=20level=20allows=20you=20to=20crea?= =?UTF-8?q?te=20[queries](/docs/query/monitoring/monitoring-reference#exam?= =?UTF-8?q?ple-queries)=20to=20visualize=20the=20traffic=20across=20your?= =?UTF-8?q?=20Vercel=20projects.=20-=20**Firewall**=20in=20the=20Vercel=20?= =?UTF-8?q?dashboard=20sidebar=20on=20every=20project=20allows=20you=20to?= =?UTF-8?q?=20monitor=20the=20internet=20traffic=20to=20your=20deployments?= =?UTF-8?q?=20with=20a=20[traffic=20monitoring=20view](/docs/vercel-firewa?= =?UTF-8?q?ll/firewall-observability#traffic)=20that=20includes=20a=20live?= =?UTF-8?q?=20traffic=20window.=20-=20[Firewall=20alerts](/docs/vercel-fir?= =?UTF-8?q?ewall/firewall-observability#firewall-alerts)=20allow=20you=20t?= =?UTF-8?q?o=20react=20quickly=20to=20potential=20security=20threats.=20-?= =?UTF-8?q?=20Use=20[Log=20Drains](/docs/drains/using-drains)=20to=20send?= =?UTF-8?q?=20your=20application=20logs=20to=20a=20Security=20Information?= =?UTF-8?q?=20and=20Event=20Management=20(SIEM)=20system.=20=20---=20=20[V?= =?UTF-8?q?iew=20full=20sitemap](/docs/sitemapSkill.md?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Zyntro-Agents --- Skills/vercel-firewall/Skill.md | 98 +++++++++++++++++++++++++++++++++ 1 file changed, 98 insertions(+) create mode 100644 Skills/vercel-firewall/Skill.md diff --git a/Skills/vercel-firewall/Skill.md b/Skills/vercel-firewall/Skill.md new file mode 100644 index 0000000..77a662a --- /dev/null +++ b/Skills/vercel-firewall/Skill.md @@ -0,0 +1,98 @@ +--- +title: Vercel Firewall +product: vercel +url: /docs/vercel-firewall +canonical_url: "https://vercel.com/docs/vercel-firewall" +last_updated: 2026-08-11 +type: conceptual +prerequisites: + [] +related: + - /docs/vercel-firewall/ddos-mitigation + - /docs/vercel-firewall/firewall-concepts + - /docs/vercel-firewall/vercel-waf/ip-blocking + - /docs/vercel-firewall/vercel-waf/custom-rules + - /docs/vercel-firewall/vercel-waf/managed-rulesets +summary: Learn how Vercel Firewall helps protect your applications and websites from malicious attacks and unauthorized access. +install_vercel_plugin: npx plugins add vercel/vercel-plugin +--- + +# Vercel Firewall + +The Vercel Firewall is a robust, multi-layered security system designed to protect your applications from a wide range of threats. Every incoming request goes through the following firewall layers: + + +## Related pages + +> **For AI agents:** Follow these links to understand how this page connects to the rest of the Vercel ecosystem. For the full cross-link map (inbound, outbound, prerequisites, and semantic neighbors), see the .graph.md link below. + +- [Bot Protection is now generally available](https://vercel.com/changelog/bot-protection-is-now-generally-available?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) +- [Bot Protection is now in public beta](https://vercel.com/changelog/bot-protection-is-now-in-public-beta?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) +- [Create custom WAF rules directly from the Vercel Firewall tab](https://vercel.com/changelog/create-custom-waf-rules-directly-from-the-vercel-firewall-tab?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) +- [Create Vercel Firewall rules with natural language](https://vercel.com/changelog/create-vercel-waf-custom-rules-using-natural-language?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) +- [Improved analytics experience now available on the Vercel Firewall](https://vercel.com/changelog/improved-analytics-experience-now-available-on-the-vercel-firewall?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) +- [Application authentication on Vercel](https://vercel.com/kb/guide/application-authentication-on-vercel?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) — Secure application authentication on Vercel across layers: proxy checks, the Data Access Layer, PPR-safe rendering, and +- [How to prepare your storefront for Black Friday traffic](https://vercel.com/kb/guide/black-friday-preparation?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) — A practical checklist for keeping your storefront fast and your checkout path healthy through Black Friday and Cyber Mon +- [Building an AI chat app with RAG and source citations on Vercel](https://vercel.com/kb/guide/building-ai-chat-app-with-rag-and-citations-on-vercel?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) — A production stack for AI chat with retrieval, reranking, source citations, and background ingestion on Vercel using Nex +- [Debug routing on Vercel](https://vercel.com/kb/guide/debug-routing-on-vercel?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) — Learn how to debug how Vercel decides where to route your request +- [How to build and maintain HIPAA-compliant applications on Vercel](https://vercel.com/kb/guide/hipaa-compliance-guide-vercel?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) — Deploy HIPAA-compliant healthcare apps on Vercel with built-in security, BAAs, and scalable serverless infrastructure. +- [How we run Vercel's CDN in front of Discourse](https://vercel.com/blog/how-we-run-vercels-cdn-in-front-of-discourse?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) +- [Life of a Vercel request: Securing your app's traffic with Vercel](https://vercel.com/blog/life-of-a-request-securing-your-apps-traffic-with-vercel?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=related) + +Full cross-link map for this page: [/docs/vercel-firewall.graph.md](/docs/vercel-firewall.graph.md?from=related&source_path=%2Fdocs%2Fvercel-firewall&source_site=vercel-docs&relationship=graph) + + +- [Platform-wide firewall](#platform-wide-firewall): With [DDoS mitigation](/docs/vercel-firewall/ddos-mitigation), it protects against large-scale attacks such as DDoS and TCP floods and is available for free for all customers without any configuration required. +- [Web Application Firewall (WAF)](#vercel-waf): A customizable layer for fine-tuning security measures with logic tailored to your needs and [observability](#observability) into your web traffic. + +### Concepts + +Understand the fundamentals: + +- How [Vercel protects every request](/docs/vercel-firewall/firewall-concepts#how-vercel-secures-requests). +- Why [DDoS](/docs/vercel-firewall/firewall-concepts#understanding-ddos) needs to be mitigated. +- How the firewall decides [which rule to apply first](#rule-execution-order). +- How the firewall uses [JA3 and JA4 TLS fingerprints](/docs/vercel-firewall/firewall-concepts#ja3-and-ja4-tls-fingerprints) to identify and restrict malicious traffic. + +## Rule execution order + +The automatic rules of the platform-wide firewall and the custom rules of the WAF work together in the following execution order: + +1. [DDoS mitigation rules](/docs/vercel-firewall/ddos-mitigation) +2. [WAF IP blocking rules](/docs/vercel-firewall/vercel-waf/ip-blocking) +3. [WAF custom rules](/docs/vercel-firewall/vercel-waf/custom-rules) +4. [WAF Managed Rulesets](/docs/vercel-firewall/vercel-waf/managed-rulesets) + +When you have more than one custom rule, you can [customize](/docs/vercel-firewall/vercel-waf/custom-rules#custom-rule-configuration) their order in the **Firewall** section in the sidebar of the project. + +## Platform-wide firewall + +> **🔒 Permissions Required**: DDoS Mitigation + +Vercel provides automated [DDoS mitigation](/docs/vercel-firewall/ddos-mitigation) for all deployments, regardless of the plan that you are on. With this automated DDoS mitigation, we block incoming traffic if we identify abnormal or suspicious levels of incoming requests. + +## Vercel WAF + +> **🔒 Permissions Required**: Vercel WAF + +The [Vercel WAF](/docs/vercel-firewall/vercel-waf) complements the platform-wide firewall by allowing you to define custom protection strategies using the following tools: + +- [Custom Rules](/docs/vercel-firewall/vercel-waf/custom-rules) +- [IP Blocking](/docs/vercel-firewall/vercel-waf/ip-blocking) +- [WAF Managed Rulesets](/docs/vercel-firewall/vercel-waf/managed-rulesets) +- [Attack Mode](/docs/vercel-firewall/attack-mode) + +You can also manage bypass rules and your WAF configuration programmatically with the [REST API](/docs/vercel-firewall/firewall-api) through the Vercel SDK, direct endpoint calls, or Terraform. + +## Observability + +You can use the following tools to [monitor the internet traffic](/docs/vercel-firewall/firewall-observability) at your team or project level: + +- The [Monitoring](/docs/query/monitoring) feature at the team level allows you to create [queries](/docs/query/monitoring/monitoring-reference#example-queries) to visualize the traffic across your Vercel projects. +- **Firewall** in the Vercel dashboard sidebar on every project allows you to monitor the internet traffic to your deployments with a [traffic monitoring view](/docs/vercel-firewall/firewall-observability#traffic) that includes a live traffic window. +- [Firewall alerts](/docs/vercel-firewall/firewall-observability#firewall-alerts) allow you to react quickly to potential security threats. +- Use [Log Drains](/docs/drains/using-drains) to send your application logs to a Security Information and Event Management (SIEM) system. + +--- + +[View full sitemap](/docs/sitemap)