Apps & Web
Web Application Firewall WAF
A layer that inspects requests to your web application and blocks application-layer attacks such as SQL injection, XSS, bots and API abuse. A classic firewall sees this traffic as "valid HTTPS" and does not stop it.
When you need it
- If you have a web application that takes user logins, forms or payments
- If your mobile app connects to an API
- If you process card data (required by PCI DSS 6.4)
- If patching/developing your application is slow (a WAF provides "virtual patching")
When you do not need it
- If you have no internet-facing applications.
- If you have a static brochure site, the CDN's basic rule set is enough.
- If your application runs on a SaaS platform such as Shopify, Wix or Ticimax, protection is on the platform.
Between the internet and the web server, terminating TLS. Cloud WAF (with a CDN) for cloud applications; appliance/virtual WAF for critical on-premises applications.



