A firewall that lives inside your deployment, not in front of it.
Ignite WAF installs as software beside your Lucee/CFML application. Every request is evaluated on your host, against rules you control, before it ever reaches your app code.
Everything an operator needs, nothing an agency can't run.
Beyond request filtering, the admin panel covers the surrounding work of actually operating a firewall day to day.
CSP security audit
Fetches your live Content-Security-Policy header and grades it A–F across 40+ directive checks — on demand or on a schedule, results emailed to your team.
Quick scan
A broader sweep covering TLS configuration, cookie flags, CORS, clickjacking protection, and exposed paths — same A–F grading.
Velocity jail
Rolling-window rate limiting tracks request bursts per IP and automatically jails offenders — releasable by an operator with the right permission.
Geo resolution
Every request is attributed a country via MaxMind GeoIP2, with a bundled MMDB file and REST fallback — no outbound call required for the common case.
Portable across engines
Ships with adapters for MSSQL, MySQL, and PostgreSQL behind a shared SQL-dialect layer — MSSQL is the primary target, the others are there when you need them.
Granular permissions
Per-user, per-site access control with a fixed permission catalog — logs, config, users, sites, and reports can each be scoped independently per operator.
What happens between the socket and your app.
Every inbound request runs through the same ordered pipeline. The first rule that matches decides the outcome — everything else is skipped.
Request arrives
TCP connection hits your host directly — no upstream hop.
IP rule check
Address or CIDR range matched against allow/deny lists.
Path & UA check
Route and client string matched against configured patterns.
Signature match
Body and query matched against known attack regexes.
Rate check
Rolling window checked; repeat offenders enter velocity jail.
Deny
Request dropped, decision and rule logged.
Beside your app, not between it and the internet.
A proxy WAF puts a third party's network between your users and your server. Ignite WAF runs as a process on the same host as your application, registered as a request filter in front of your Lucee handler — not a separate network hop, port, or DNS change.
Five rule types, one evaluation order.
Rules are stored per site and evaluated in the order shown in the pipeline above. Each type has its own matcher and its own log entry.
- IP rulesAllow or deny a single address or CIDR range. Evaluated first, cheapest check in the pipeline.
- Path rulesDeny requests to routes that shouldn't exist on a CFML host — WordPress paths, dotfiles, admin probes.
- User-agent rulesMatch against known scraper and bad-client strings, independent of IP reputation.
- Signature rulesRegex match against query string and body for known injection and traversal patterns.
- Rate limitRolling-window counter per IP. Exceeding the threshold moves the address into velocity jail.
// evaluated top to bottom, first match wins { "type": "path", "pattern": "^/wp-login\.php$", "action": "deny", "log": true }, { "type": "signature", "pattern": "(?i)(\bor\b\s+1=1|union\s+select)", "action": "deny" }, { "type": "rate_limit", "window_seconds": 60, "max_requests": 600, "jail_minutes": 15 }
Every rule is editable from the same interface that logs it.
Changes take effect on the next request — no redeploy, no restart.
Run the pipeline above against your own traffic.
Create an account and get a 14-day trial — no card required.