Hi,
We have Jira and Bitbucket DataCenter On-Premises.
Our security team requires that a WAF be placed in front of our BitBucket servers, filtering data coming from Jira (Bitbucket and Jira behing hosted in a different security zones).
Is there configuration guidelines, or can you please help us identify the right rules :
- Application language
- Allowed parameters, headers length
- Any whitelisting for parameters
- Response status codes
- Anything else 
Best regards