Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Protect Your Website With a Web Application Firewall

This guide explains what a web application firewall is and gives you simple steps to start using one.

Firewall2 min read7 steps

What is a web application firewall?

A web application firewall, or WAF, is a guard in front of your website. It looks at every visit and decides if it is safe. If a visit looks like an attack, it is stopped at the door.

A normal firewall checks which doors (ports) are open. A WAF is smarter. It reads the content of each web request. It can spot tricks such as SQL injection and cross-site scripting. SQL injection tries to fool your database. Cross-site scripting hides bad code in your pages.

Kinds of WAF

  • Server WAF: software on the server, such as ModSecurity. It is common with cPanel and Plesk.
  • Cloud WAF: a service that sits between visitors and your server. Some companies, including content delivery networks, offer this.
  • Plugin WAF: a security plugin inside your website program, such as WordPress.

Ask Hostvento support which kind your plan can use.

Steps to get started

  1. Back up your site. Copy your files and database first.
  2. Find the WAF. In cPanel, open Security, then ModSecurity. In Plesk, open Tools & Settings, then Web Application Firewall.
  3. Turn it on. Switch your domain to On.
  4. Check the rule set. Rules are the list of attacks it knows. A rule set such as OWASP is a good one.
  5. Test your site. Visit pages, log in and send a form. Make sure all works.
  6. Look at the log. The log lists blocked visits. Read it every week.
  7. Fix mistakes. If a good action is blocked, note the rule ID and ask for an exception for that rule.
Tip: If you use a plugin WAF, turn on its learning or test mode first. It watches for a few days and then blocks.

Good habits that work with a WAF

  • Update your website software, themes and plugins.
  • Use long, unique passwords.
  • Remove tools you do not use.
  • Use HTTPS with an SSL certificate.
  • Keep regular backups.

A WAF is a strong layer, but it is not magic. It cannot fix an old, broken plugin. It only makes attacks harder.

Need help? Open a support ticket.

Quick recap

  • A WAF reads each web request and blocks attacks.
  • It can run on the server, in the cloud or as a plugin.
  • Turn it on, load good rules and test your site.
  • Read the logs and fix false positives.
  • Keep updates and backups going.