It seems like your browser didn't download the required fonts. Please revise your security settings and try again.
Barracuda WAF-as-a-Service

Barracuda Campus is getting an upgrade!

We are excited to announce that Barracuda Campus will migrate to a new platform around mid-January 2026. Please see the announcement on the Campus Dashboard to find out more.

Header Allow/Deny Rules

  • Last updated on

You can enforce strict limitations on incoming headers intended for a service . You can sanitize HTTP headers that carry sensitive information, including information that identifies the client and some application-specific state information, passed as one or more HTTP headers. You can configure a header ACL to prevent specific attack types, block metacharacters, and block specific Header Names.

You can specify whether, when an active rule is broken, the request is blocked or monitored (tracked in a log).