Link11 WAAP
v5
v5
  • Link11 WAAP Documentation
  • Release Notes
  • Known Issues
  • User Guide
    • Introduction to Link11 WAAP
  • How Link11 WAAP Works
    • Traffic Filtering Process
    • Traffic Reporting and Analytics
    • Policy Mapping and Traffic Routing
    • Tagging
    • UI Overview and Common Elements
  • Console UI Walkthrough
    • Analytics
      • Dashboard
      • Events Log
    • Security
      • Global Filters
      • Flow Control Policies
      • Security Policies
      • Rate Limit Rules
      • ACL Profiles
      • Actions
      • Dynamic Rules
      • Quarantined
      • Content Filter
        • Content Filter Profiles
        • Content Filter Rules
    • Sites
      • Server Groups
      • Proxy Templates
      • Mobile Application Groups
      • Backend Services
      • Edge Functions
      • DNS Records
      • SSL
        • Load Balancers
        • Certificates
    • System
      • Interactive Challenge
      • SSO Configuration
      • Purge CDN Cache
      • Users Management
      • Security Alerts
      • Log Exporters
      • Version Control
      • System DB
      • Publish Changes
    • Account
  • Using the product
    • Best Practices
      • Saving and Publishing Your Changes
      • Enabling Passive Challenges
      • Understanding and Diagnosing Traffic Issues
    • How Do I...
      • Authenticate mobile app users
      • Ban, unban, and allowlist traffic sources
      • Bypass Link11 WAAP for loadtesting or other purposes
      • Configure a new path/section of a site
      • Control caching behavior
      • Enable GraphQL traffic
      • Enable mTLS (mutual TLS)
      • Protect sensitive information in logs and analytics
      • Quickly block an attacker
      • Redirect or block HTTP traffic
      • Run custom code
      • Set rate limits and exemptions
      • Stream event data to a SIEM solution or other destination
    • The Link11 WAAP API
      • Overview
      • Internal data structures
      • Using Swagger UI
      • Using curl
  • Reference Information
    • Acronyms
    • API
      • API access to traffic data
      • Types of namespaces
      • Namespace reference
        • ACL Profiles
        • Actions
        • Backend Services
        • Certificates
        • Configs
        • Content Filter Profiles
        • Content Filter Rules
        • Data queries
        • Dynamic Rules
        • Edge Functions
        • Flow Control Policies
        • Global Filters
        • Load Balancers
        • Log Exporters
        • Mobile Application Groups
        • Planets
        • Proxy Templates
        • Rate Limit Rules
        • Security Alerts
        • Security Policies
        • Server Groups
        • Tags
        • Tools
        • Users
    • Hostile Bot Detection / LWCSI
      • Environmental detection and browser verification
      • Client authentication
      • Biometric behavioral verification
    • HTTP Response Codes
    • Log Exporter Output
    • Pattern Matching Syntax
    • Query Filter Syntax and Best Practices
  • Support
Powered by GitBook
On this page

Was this helpful?

Export as PDF
  1. Using the product
  2. How Do I...

Set rate limits and exemptions

Restricting consumption of resources and rate of requests

PreviousRun custom codeNextStream event data to a SIEM solution or other destination

Last updated 1 month ago

Was this helpful?

Different types of rate limits are defined in different parts of the Link11 WAAP interface.

Static rate limits for entire sites/applications: A static rate limiting capability is available via the within . This is simple, IP-based rate limiting that applies globally to every site/application based upon that Proxy Template.

Granular rate limiting: More powerful capabilities are available through , including variable scope, multiple criteria for tracking requestors, actions, and more. These Rules are then associated with specific locations/URLs through .

Global enforcement by traffic source: Requestors who submit excessive requests across the planet can be banned for configured lengths of time. This can be done via .

Creating Rate Limiting Exemptions

To exempt one or more traffic sources from all filtering, follow the instructions here: .

To exempt a traffic source from rate limiting only, do the following:

  1. Determine a unique tag that will identify the traffic source(s).

    • There might already be one in use by the system. For example, to exempt an entire ASN, the for that ASN can be used.

    • If not, then create a that will assign a unique tag to requests from the traffic source(s) in question.

  2. Add the tag to the Exclude filter list in the applicable and .

Proxy Templates
Rate Limit Rules
Security Policies
Dynamic Rules
Bypass Link11 WAAP for Loadtesting or Other Purposes
Global Filter
Rate Limit Rules
Dynamic Rules
system tag
Application IP Rate Limits settings