Skip to main content
A firewall policy tells the gateway to block every request that matches its match expressions. Use it to close internal paths, block a method on a route, or refuse requests with a certain header, without changing your . To add one, open the app, go to Policies, click Add Policy, and pick Firewall. You only need a name, an environment, and match conditions.

Settings

string
required
Always ACTION_DENY. A request the firewall doesn’t match moves on to the next policy.
Example: block writes to an admin prefix from outside
A request must match all the expressions, so the example only blocks requests that match all three. To block two unrelated kinds of request, create two firewall policies. A firewall policy with no match expressions blocks every request to the . That’s a quick way to take a preview environment offline.

What the client sees

A blocked request gets 403 Forbidden with the code err:frontline:client:firewall_denied and the message Forbidden. The body is JSON or an HTML page depending on the caller’s Accept header. See Gateway errors. The caller isn’t told which policy matched. No later policies run, and the request doesn’t appear in your request log.

Next steps

Gateway policies

Every match expression type and how they combine.

Rate limit policy

Slow callers down instead of blocking them.
Last modified on September 29, 2026