Cloud Shield / Managed protection
A managed foundation for application security.
Application traffic includes legitimate visitors, automated requests and attempts to exploit your application. Cloud Shield applies managed protection policies to requests in your CDN delivery path, with controls for each protected domain.
Capabilities
Managed protection in practice.
Managed WAF policies
Use managed security policies and default rules as the foundation of your application protection.
Control by application
Review the policies attached to each protected domain and configure them to suit the application behind it.
Visible decisions
Use traffic analytics and security events to review how requests are handled and identify where protection needs adjustment.
Configuration & visibility
Tune protection with the application in view.
Keep policy settings, exceptions and visitor responses together as you refine protection.
- Policies
- Review the protection policies available to a domain and choose which policies apply.
- Policy overrides
- Use targeted overrides when a particular request needs different treatment from the general policy.
- Custom response pages
- Configure page sets for blocked or challenged requests so visitors receive a response appropriate to your application.
- Custom rules
- Add your own request conditions and IP firewall controls on Advanced and Business, within the plan allowances.
How it works
From managed protection to a tuned policy.
- 01
Attach your CDN distribution
Choose the existing Cloud CDN distribution and the application hostnames you want to protect.
- 02
Review the policies
Check the managed policies and settings for the protected domain before refining exceptions.
- 03
Investigate and adjust
Review traffic and security events, check legitimate application flows and make targeted policy changes.
Managed policies and default rules are included in Basic, Advanced and Business. Compare plans
Frequently asked questions
Basic, Advanced and Business include managed policies and default rules. Custom rules and IP firewall rules start on Advanced.
No. Cloud Shield attaches to an existing Cloud CDN distribution and uses its hostnames, origins, routing and TLS configuration. Cloud CDN is billed separately.
Custom page sets let you configure visitor-facing responses for supported block and challenge actions.
Explore Cloud Shield