What is WAF (Web Application Firewall)?
Definition
A WAF (web application firewall) is a security layer that inspects incoming HTTP requests to a web application, including their content, and allows, blocks or challenges them according to rules. Where a network firewall looks at IP addresses and ports, a WAF evaluates the URL, headers, cookies and request body. It is used to filter common attacks such as SQL injection and XSS, rein in abusive bots and buy time until vulnerabilities are patched.
Also known as: WAF, web app firewall, application firewall, layer 7 firewall

Picking up where the network firewall stops
Once a traditional firewall opens port 443, everything arriving on that port gets through regardless of what it contains. A WAF works at the HTTP layer (layer 7 of the OSI model) and reads the request itself: which path is being called, what is in the query string, whether the form or JSON body contains a suspicious pattern, whether the user agent and request rate look normal.
| Network firewall | WAF | |
|---|---|---|
| Looks at | IP, port, protocol | URL, headers, cookies, request body |
| Typical question | “May this address reach this port?” | “Does this request look like an attack?” |
| Where it runs | Network edge or the host | A reverse proxy in front of the app, a CDN edge, or a web server module |
OWASP describes a WAF as an application firewall for HTTP applications that applies a set of rules to the HTTP conversation. In practice you meet three deployment styles: at the edge of a CDN or security service such as Cloudflare, in front of a cloud provider's load balancer, or as a module inside Nginx or Apache.
What the rules actually do
- Managed rule sets recognise common attack patterns such as injection and XSS, the staples of the OWASP Top 10, and are kept current by the vendor or community. OWASP's open-source Core Rule Set is the best-known example.
- Custom rules encode site-specific limits: the admin area only from certain countries or IPs, certain paths only with certain methods.
- Rate limiting and bot management slow down clients hammering a login form and present a challenge to suspicious traffic.
- Virtual patching blocks requests targeting a newly disclosed flaw in a plugin you use, buying time until the code is updated.
False positives: locking out good bots and real people
The most common WAF problem is not missed attacks but blocked legitimate traffic. An editor saving a blog post that explains SQL can trip an injection rule; a mobile app sending a large JSON body can be rejected. The quieter loss happens with search and AI crawlers:
- If Googlebot hits a challenge page or receives
403or429responses, crawl rate drops, new pages are discovered late, and sustained blocking can push pages out of the index. - Aggressive bot rules can also stop the AI crawlers that fetch pages for AI search and assistant answers, so your content cannot be cited. Blocking model-training crawlers can be a deliberate choice, but that decision belongs in robots.txt and your bot settings, not as a side effect of a WAF rule.
- Allowing by user agent is not enough, because user agents are trivial to fake. Google recommends verifying Googlebot with a reverse and forward DNS lookup or against its published IP ranges, and most WAF products offer a ready-made “verified bots” category.
Running new rules in log-only mode first, reviewing blocked requests regularly and watching Search Console's crawl stats for sudden drops surface these problems early. Doruva's GEO Checker also reports whether search and AI crawlers are being stopped by a bot challenge.
A WAF is not a patch
A WAF is an extra layer, not a substitute for secure code. Its rules match patterns, so they will never recognise every attack, and they need tuning as the application changes. It also only sees traffic that passes through it: if the origin server's IP is known and the server accepts direct connections, requests can skip the WAF entirely. Restricting the origin to accept traffic only from the WAF or CDN provider's addresses is part of a correct setup, not an optional extra.

