Web application firewalls are a specialist security control with real complexity in their deployment, tuning, and operation. This guide covers how WAFs work, what to look for when evaluating options, and the pitfalls that undermine most implementations.
A web application firewall is one of the more complex security investments an organisation can make – not because the concept is difficult, but because the gap between deploying a WAF and having one that actually works is wider than most organisations anticipate. Default configurations provide baseline protection but rarely match the specific applications they are meant to defend. Without tuning, monitoring, and ongoing maintenance, a WAF can provide false confidence rather than genuine protection.
This guide covers how WAFs work, what to look for when evaluating options, and the mistakes that undermine most implementations.
A web application firewall monitors, filters, and blocks HTTP and HTTPS traffic to and from web applications. Where a traditional network firewall operates at the network layer, a WAF works at the application layer – giving it visibility into the actual content of web requests, not just their headers and routing information.
This distinction matters. Next-generation firewalls can inspect traffic using deep packet inspection and are designed for general network security. A WAF is a specialist tool, purpose-built to understand web application logic, parse HTTP requests in detail, and defend against attacks that exploit application-layer vulnerabilities.
Modern WAFs use several detection methods, typically in combination.
WAFs can be deployed in three ways. Cloud-based WAFs route traffic through the provider’s infrastructure, offering rapid deployment, automatic updates, and scalability without hardware. They suit organisations with limited security staff or distributed cloud environments, though you are dependent on the provider’s infrastructure. On-premise WAFs run within your own data centre, giving complete control and keeping traffic within your environment – better for organisations with data sovereignty requirements, but at the cost of greater operational overhead. Hybrid approaches combine both, often using on-premise WAFs for data centre applications alongside cloud-based protection for public-facing services.
The right choice depends on where your applications run, how your traffic flows, and the level of control your compliance obligations require.
Your WAF needs to handle traffic spikes without becoming a bottleneck. Cloud-based WAFs typically scale automatically. On-premise solutions require capacity planning. Ask vendors about throughput capacity, latency impact, and performance during DDoS conditions. A WAF that cannot keep pace with legitimate traffic during peak periods will affect user experience.
A WAF operates within a broader security ecosystem and needs to work with it effectively.
SIEM integration allows your WAF to feed logs and alerts into your security information and event management platform. Ensure the WAF supports standard log formats and can stream events to your chosen SIEM.
Identity and access management integration enables the WAF to make decisions based on user identity rather than just IP addresses, supporting more granular policies.
DevOps and CI/CD pipeline integration matters if your development teams deploy frequently. WAF rules should be version-controlled and deployable alongside application code.
Network infrastructure compatibility is essential – verify the solution works with your existing load balancers, CDNs, and SSL/TLS configuration.
Automated rule updates incorporate new threat intelligence without manual intervention. Machine learning capabilities identify emerging threats based on behavioural patterns. Comprehensive analytics provide visibility into attack trends and whether legitimate traffic is being affected. Real-time alerting with intelligent aggregation helps teams focus on genuine threats rather than noise.
A WAF is not a set-and-forget solution. Applications change, new vulnerabilities emerge, and attack techniques evolve. Consider the operational burden honestly.
Managed WAF services handle rule maintenance, tuning, and monitoring. This reduces overhead but may offer less flexibility. Self-managed solutions give complete control but require skilled staff to maintain and tune the WAF effectively. A misconfigured WAF can block legitimate traffic or leave security gaps.
Be realistic about your team’s capacity. A sophisticated WAF that sits misconfigured because no one has time to manage it provides less protection than a simpler, well-maintained solution.
Regulated organisations need WAFs that support their specific compliance obligations. For NHS and healthcare organisations, this means demonstrating protection of patient data and meeting NHS England security standards. For public sector organisations working with sensitive data, audit trails need to satisfy the relevant regulatory framework. Look for WAFs that provide compliance-specific reporting and retain logs for the duration your obligations require.
Cloud Gateway’s Secure Application Access delivers WAF capability as part of the managed platform, within the Protect pillar, alongside Managed Firewall, Secure Internet Access (SWG), and Secure Private Access (ZTNA). WAF capability integrates with the broader security and connectivity stack, with consistent policy applied across cloud, on-premise, and remote access scenarios under one operating model.
For regulated organisations, WAF logs and security events feed into the same visibility layer as network traffic and access records, supporting the continuous compliance evidence that DSPT, CAF, and PSN assessments expect. UK-based infrastructure and operations address data sovereignty requirements.
For more on how Secure Application Access works and how it fits within the platform, see our Secure Application Access page and our platform page.