Settings
string
required
Always
ACTION_DENY. A request the firewall doesn’t match moves on to the next policy.Example: block writes to an admin prefix from outside
What the client sees
A blocked request gets403 Forbidden with the code err:frontline:client:firewall_denied and the message Forbidden. The body is JSON or an HTML page depending on the caller’s Accept header. See Gateway errors. The caller isn’t told which policy matched.
No later policies run, and the request doesn’t appear in your request log.
Next steps
Gateway policies
Every match expression type and how they combine.
Rate limit policy
Slow callers down instead of blocking them.