The protocol validation policy group verifies the HTTP and HTTPS protocols used by clients to request content from your website’s origin server. If the request meets the protocol-specific requirements, the transaction is allowed, while all non-compliant transactions are blocked.
You can review the Protocol validation policy group and enable or disable its policies in the Gcore Customer Portal:
1. Navigate to WAAP > Domains.
2. Find the domain where you want to configure the policy group and click the domain name to open it.
3. On the Policies page that opens, click Protocol validation to expand the section and adjust the policies.
InfoAll protocol validation policies are enabled by default. To enable or disable a policy, turn on the toggle near that policy.
Service protocol validation
Block clients that try to interfere with the service’s internal calls, such as tampering with cookies or request headers.
Enforce HTTP RFC requirements that define how the client is supposed to interact with the server. If the requests don’t meet the RFC standards, the client will be challenged with CAPTCHA or JavaScript validation. Clients that fail to pass the validation will be blocked.