Skip to content

Web application firewall (WAF)

A web application firewall reads each request sent to a website and refuses the ones that match its rules for known attacks. It can run inside WordPress as a plugin, on the web server, or in front of the site. Where it sits decides what it can stop.

By
WP Ministry
Published

In short

  • A firewall can act on a request only where it sees it. One in front of the site turns traffic away before it reaches your server. A plugin sees it after it has arrived.
  • A 403 when you save a post, or a 429 when you work quickly, is often a firewall rule mistaking you for an attack.
  • A firewall filters requests. It does not install updates, and it does not clean a site that is already infected.

A web application firewall, or WAF, is a filter for the requests sent to a website. OWASP defines it as a firewall that applies a set of rules to an HTTP conversation, where the rules generally cover common attacks such as cross-site scripting and SQL injection. A request that matches a rule is refused. The rest go through.

On a WordPress site it can sit in one of three places, and WordPress's hardening guide describes all three.

  • Inside the site, as a plugin. Some plugins write rules into .htaccess, so that the web server refuses a request before WordPress handles it. Others run as WordPress loads and filter from there.
  • On the web server. The firewall is installed beside the web server and filters before WordPress is reached. The guide names ModSecurity as the most popular open-source one. On shared hosting it is the host's to run.
  • In front of the site. The domain's DNS records are changed so that all traffic passes through the firewall's network first. That network forwards the requests it accepts to your server and drops the rest.

What matters is where the refusal happens. A firewall in front turns traffic away before it reaches your server, and WordPress's guidance on password-guessing attacks prefers that for this reason. A plugin acts on a request that has already arrived.

Where you meet it

Mostly you meet a firewall when it refuses you.

  • "403 Forbidden". The status means the server understood the request and refuses to fulfill it. When it appears only as you save a post or send a form, a firewall rule has usually matched something in what you sent.
  • "429 Too Many Requests". The status means too many requests arrived in a given amount of time. A firewall that limits how often one address may call the login page can answer this way.

What goes wrong

  • An ordinary request is taken for an attack. Rule writers call this a false positive. The documentation for the OWASP rule set, which is written to work with ModSecurity, gives a WordPress post containing HTML as its example. If saving or uploading is refused, see how to fix the 403 Forbidden error.
  • A limit is set too low. Real visitors, or you, are refused for working quickly. See how to fix "429 Too Many Requests".
  • It is expected to do more than filter. A firewall does not install updates and does not remove what is already on the site. The hardening guide says plainly that prevention is sometimes not enough and a site may still be hacked. How to protect WordPress from brute force attacks covers the passwords and second factor that a firewall does not replace.
  • The wrong kind is chosen. A plugin will not shield a small server from a flood of traffic, because the traffic has already arrived. WordPress firewalls compared starts with where each kind sits.

Common questions

Is a firewall plugin a real WAF?

Yes. WordPress's hardening guide lists plugins among the things that can act as a firewall for a site. They differ from the other kinds in where they sit, and so in what reaches your server before a rule is applied.

Does my host already run one?

Ask. A firewall at the web server is set up by whoever runs the server, and on shared hosting that is the host. If one of its rules refuses you, only the host can say which and switch it off for your site.

Does a firewall make updates less urgent?

No. WordPress's hardening guide says that once a fix is released, what is needed to exploit the hole is almost certainly public, and that this is one of the main reasons to keep WordPress up to date. A firewall rule may block a known attack. The update removes what is being attacked.

Not sure what is wrong?

Tell us what you see. We reply with the cause and a fixed quote, and the diagnosis is free.