What is a WAF?
WAF stands for Web Application Firewall. Think of it as a guard at the door of your website. It checks every visitor request and blocks the ones that look harmful.
Drupal is a popular tool for building websites. Because many people use it, attackers know its weak spots. A WAF helps stop common attacks before they reach your site.
What a WAF can block
- SQL injection: a trick where an attacker types database commands into a form.
- Cross-site scripting (XSS): a trick that places bad code on your pages.
- Bad bots: programs that guess passwords or scan for weak spots.
Steps
- Ask Hostvento support whether a WAF is part of your plan. You can open a support ticket.
- Take a backup of your Drupal files and database first. A backup is a safe copy you can restore if something breaks.
- Open the WAF dashboard that comes with your service. Your welcome email or support can tell you where it is.
- Turn the WAF on. Pick the mode called "protection" or "blocking" if you see a choice.
- Switch on the rule groups for SQL injection and cross-site scripting.
- Switch on bot protection if it is offered.
- Add a rate limit on your login page,
/user/login. A rate limit allows only a few tries in a short time. This slows down password guessing. - Protect the admin area,
/admin. If you always work from the same place, allow only your own IP address there. An IP address is the number that identifies your internet connection. - Visit your site and click through the main pages, forms and the admin area. Make sure everything still works.
Tip: If a page stops working after you turn on the WAF, a rule may be too strict. Check the WAF log for the blocked request and ask support to relax that one rule.
Other ways to stay safe
- Update Drupal core and modules often. A WAF helps, but updates fix the real holes.
- Remove modules and themes you do not use.
- Use long, unique passwords for every admin user.
- Keep regular backups.
Quick recap
- A WAF checks visitors and blocks harmful requests.
- Back up your site before changing anything.
- Turn on SQL injection, XSS and bot rules.
- Rate limit the login page and restrict the admin area.
- Test your site afterwards and keep Drupal updated.