Hexa WAF evaluates inbound HTTP requests before they reach the origin. It combines the managed rule catalog with customer-defined allow, log, and block rules.
This capability is backed by the Hexa Shield control plane and reverse-proxy architecture described in the project documentation.
Managed rule catalog for common application-layer attack indicators
Custom allow, log, and block rules
Per-domain WAF enable/disable controls
Security-event visibility for matched requests
Immediate configuration invalidation across proxy nodes through Redis
Each product is managed from the same Hexa Shield account and domain model instead of requiring separate control panels.
Traffic reaches the Hexa Shield proxy
Managed WAF rules inspect the request
Customer custom rules are evaluated
Matched actions are logged or enforced
Allowed traffic continues to the customer origin