- User-Agent detection. Requests with invalid (known to be malicious) or missing User-Agent strings will be blocked.
- Analysis of traffic sources. Requests from hosting services, TOR exit nodes, proxy, or VPN networks will be required to pass a Handshake (JavaScript validation).
- Behavioral analysis. Requests with unusual user behavior will be challenged or blocked.
- Headless browsers and automated clients. Requests from headless browsers will be tagged by our security cloud (behavioral engine) and will have to pass a Handshake (JavaScript validation).
View and enable common automated services
WAAP allows known bots and services listed in the common automated services policy group. To view the policy group and enable or disable bots: 1. In the Gcore Customer Portal, navigate to WAAP > Domains.
InfoIf you want to add a new bot to the list, contact Gcore support team and provide the details. We’ll consider adding that bot in the future.
Enable the “Let’s Encrypt” policy
Let’s Encrypt is a free, automated, and open certificate authority that provides server-side SSL certificates. Use the following instructions to enable the Let’s Encrypt policy that will validate requests to create or renew SSL certificates: 1. In the Gcore Customer Portal, navigate to WAAP > Domains.