Skip to content

Enable the WAF for an HTTP Tunnel

Enable Localtonet’s WAF to inspect your HTTP tunnel traffic and block or challenge suspicious requests.

  1. Open the Localtonet dashboard, navigate to your HTTP tunnel, and click WAF.
  2. Enable the WAF with Mode: Detection. Let it run for a day or two, then review the Events tab for flagged legitimate requests. Detection mode logs events without blocking or challenging traffic.
  3. In the Security tab, whitelist your IP address and any trusted service or webhook sender IPs that must bypass WAF checks. You can alternatively whitelist a specific webhook path.
  4. After adjusting false-positive rules or whitelist entries, switch to Prevention mode and start with Standard sensitivity.

Troubleshooting false positives

If legitimate users receive unexpected challenges, switch back to Detection mode from the Configuration tab. In Events, identify the triggering rule, then disable it or add a whitelist entry before returning to Prevention mode. Switching modes requires no restart and does not remove event history.

support