Imperva Cyber Community

communities_1.jpg
 View Only
  • 1.  WAF Policy Allowlist doesn't bypass security rules.

    Posted 19 days ago

    Hello

    I have added an IP address to a WAF Policy Allowlist and created a Security Rule which Require CAPTCHA. I was expecting that the Allowlist bypass the security rule but it doesn't, and the connection from the IP address still requires CAPTCHA. Could someone clarify for me what exactly Allowlist bypasses pelase?

    Thank you


    #CloudWAF(formerlyIncapsula)

    ------------------------------
    Piotr Kowalczyk
    Cybersecurity LEad
    Applus
    Barcelona
    ------------------------------


  • 2.  RE: WAF Policy Allowlist doesn't bypass security rules.

    Posted 10 days ago

    The Allowlist does not act as a global trust mechanism. It bypasses WAF Security Policy checks, but Security Rules are evaluated separately. If a request from an Allowlisted IP matches a Security Rule configured with "Require CAPTCHA", the CAPTCHA challenge will still be applied unless the rule explicitly excludes that IP.



    ------------------------------
    Vivek Ghalawat

    ------------------------------



  • 3.  RE: WAF Policy Allowlist doesn't bypass security rules.

    Posted 10 days ago

    Fortunately your answer is wrong. I've just tested and adding IP address to Allow list bypass CAPTCHA requirement set in rule. 



    ------------------------------
    Piotr Kowalczyk
    Cybersecurity LEad
    Applus
    Barcelona
    ------------------------------



  • 4.  RE: WAF Policy Allowlist doesn't bypass security rules.

    Posted 8 days ago
    Thank you for testing and correcting me. It clarifies the actual behavior in this scenario.


    ------------------------------
    Vivek Ghalawat
    ------------------------------