docs

Firewall

Overview

The Firewall lets you create edge rules that control traffic before it reaches your storefront. Rules are evaluated at the platform edge, so blocked, challenged, or throttled requests never consume your application's resources.

Firewall rules come in two types:

  • Security Rules - block, challenge, or allow traffic based on IP address, country, or bot characteristics.
  • Rate Limiting - throttle high-volume traffic based on request count over a time window.

Where to find it

Both rule types live in Shops ➜ [Shop] ➜ Hosting ➜ Settings ➜ Firewall. Configuration is per-environment - use the environment selector at the top right of the Settings page to switch between environments.

Firewall page in the SCAYLE Panel showing the Security rules and Rate limiting rules sections, both empty

The Firewall page with both rule sections - empty state"

Availability

Firewall rules - both types - are available only in live environments. Non-live environments (Development, QA, Staging) do not support Firewall rules.

Rule limits

Each live environment supports:

  • Up to 5 Security Rules (up to 50 IPs or CIDR ranges per rule)
  • Up to 5 Rate limiting rules

The two limits count separately, so a live environment can have up to 10 Firewall rules total (5 of each type). Please reach out to your SCAYLE Account Manager if your use case requires more.

Rule status

Every Firewall rule (both Security Rules and Rate Limiting) is either Enabled or Disabled.

  • Enabled - the rule is active at the edge and evaluated against incoming traffic.
  • Disabled - the rule is saved to your configuration but not enforced.

You can toggle a rule's status when creating or editing it.

Saving changes

Both Security Rules and Rate Limiting share a single Save changes button at the top right of the Firewall page. It becomes active when you make any change (add, edit, delete, or reorder a rule).

When there are unsaved changes, a banner at the top of the page reads:

"Firewall rules were changed. Save changes to propagate them to the edge provider."

Clicking Save changes propagates your entire Firewall configuration in one operation. Propagation to the edge is fast but not instantaneous - if you test a rule immediately after saving and see unexpected behaviour, give it a moment and try again