What is a WAF?
A WAF is a Web Application Firewall. It sits in front of your website and checks every request. If a request looks harmful, it stops it. Think of a guard who checks bags at a gate.
Turning a WAF on is not enough. You should test it, just like you test a smoke alarm.
Steps
- Open your WAF dashboard and check that it says the WAF is on and in blocking mode. In "detect only" mode it logs attacks but does not stop them.
- Open a normal page of your site, such as
https://example.com/. Use your own domain. It should load as usual. - Add a harmless fake attack to the web address. Type this at the end of your address and press Enter:
https://example.com/?test=<script>alert(1)</script>
This looks like a cross-site scripting attack. It is only a test and does no harm. A working WAF usually shows a "403 Forbidden" or "blocked" page. Code 403 means "you are not allowed in".
- Try a fake database attack. Add this to your address:
https://example.com/?id=1' OR '1'='1
This looks like a SQL injection attempt. SQL is the language databases understand. A good WAF blocks it.
- You can also test from a terminal with the
curltool:
curl -I "https://example.com/?test=<script>alert(1)</script>"
This asks only for the page headers. Look at the first line. A result of 403 means the request was blocked.
- Go back to the WAF dashboard and open the logs. You should see your test requests listed as blocked.
- Load your normal pages again. Make sure real visitors are still allowed in.
If nothing was blocked
- Check that the WAF is switched on for your domain.
- Check that the right rule groups are enabled.
- Make sure your domain really points through the WAF. This depends on your DNS settings. DNS is the internet's phone book for website names.
- Ask Hostvento support for help. You can open a support ticket.
Quick recap
- Test only your own site.
- Send harmless fake attacks in the web address.
- A blocked request shows a 403 page.
- Confirm the blocks appear in the WAF log.
- Check that normal visitors still get in.