Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Protect Your Drupal Website with a WAF

This guide shows how a WAF can guard your Drupal site and which settings are worth turning on.

Firewall2 min read9 steps

What is a WAF?

WAF stands for Web Application Firewall. Think of it as a guard at the door of your website. It checks every visitor request and blocks the ones that look harmful.

Drupal is a popular tool for building websites. Because many people use it, attackers know its weak spots. A WAF helps stop common attacks before they reach your site.

What a WAF can block

  • SQL injection: a trick where an attacker types database commands into a form.
  • Cross-site scripting (XSS): a trick that places bad code on your pages.
  • Bad bots: programs that guess passwords or scan for weak spots.

Steps

  1. Ask Hostvento support whether a WAF is part of your plan. You can open a support ticket.
  2. Take a backup of your Drupal files and database first. A backup is a safe copy you can restore if something breaks.
  3. Open the WAF dashboard that comes with your service. Your welcome email or support can tell you where it is.
  4. Turn the WAF on. Pick the mode called "protection" or "blocking" if you see a choice.
  5. Switch on the rule groups for SQL injection and cross-site scripting.
  6. Switch on bot protection if it is offered.
  7. Add a rate limit on your login page, /user/login. A rate limit allows only a few tries in a short time. This slows down password guessing.
  8. Protect the admin area, /admin. If you always work from the same place, allow only your own IP address there. An IP address is the number that identifies your internet connection.
  9. Visit your site and click through the main pages, forms and the admin area. Make sure everything still works.
Tip: If a page stops working after you turn on the WAF, a rule may be too strict. Check the WAF log for the blocked request and ask support to relax that one rule.

Other ways to stay safe

  • Update Drupal core and modules often. A WAF helps, but updates fix the real holes.
  • Remove modules and themes you do not use.
  • Use long, unique passwords for every admin user.
  • Keep regular backups.

Quick recap

  • A WAF checks visitors and blocks harmful requests.
  • Back up your site before changing anything.
  • Turn on SQL injection, XSS and bot rules.
  • Rate limit the login page and restrict the admin area.
  • Test your site afterwards and keep Drupal updated.