If you are reading this, the request passed the firewall and reached the origin.
These should each be blocked with a 403 and appear in the Attack log:
curl --path-as-is, because a browser
and curl both resolve ../ before sending itThe dashboard is at panel.waf.1ti.click:9443.