LINK11
English

Web Application Firewall — in practice

Published on 2026-07-31 · 7 min read
Web Application Firewall — in practice

What this is about

What matters is not the packet rate but how expensive a single request is for the origin. Filtering only at the origin means you have already paid for the capacity you meant to protect. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. What matters is not the packet rate but how expensive a single request is for the origin.

Before any rule change, it should be clear what share of real traffic would be affected. What matters is not the packet rate but how expensive a single request is for the origin. The threshold that was right yesterday is wrong again after a marketing campaign goes out. Before any rule change, it should be clear what share of real traffic would be affected. Before any rule change, it should be clear what share of real traffic would be affected. What matters is not the packet rate but how expensive a single request is for the origin.

What matters is not the packet rate but how expensive a single request is for the origin. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. Filtering only at the origin means you have already paid for the capacity you meant to protect. When in doubt: observe before blocking — a false positive costs more than a scan that got through.

  • The threshold that was right yesterday is wrong again after a marketing campaign goes out.
  • Before any rule change, it should be clear what share of real traffic would be affected.
  • The threshold that was right yesterday is wrong again after a marketing campaign goes out.

What happens in practice

Before any rule change, it should be clear what share of real traffic would be affected. The threshold that was right yesterday is wrong again after a marketing campaign goes out. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety.

What matters is not the packet rate but how expensive a single request is for the origin. Before any rule change, it should be clear what share of real traffic would be affected. When in doubt: observe before blocking — a false positive costs more than a scan that got through. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. The threshold that was right yesterday is wrong again after a marketing campaign goes out.

A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. The threshold that was right yesterday is wrong again after a marketing campaign goes out. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. Before any rule change, it should be clear what share of real traffic would be affected. What matters is not the packet rate but how expensive a single request is for the origin.

What we recommend

Before any rule change, it should be clear what share of real traffic would be affected. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. Before any rule change, it should be clear what share of real traffic would be affected. Before any rule change, it should be clear what share of real traffic would be affected.

When in doubt: observe before blocking — a false positive costs more than a scan that got through. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. Before any rule change, it should be clear what share of real traffic would be affected. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. Before any rule change, it should be clear what share of real traffic would be affected.

A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. Before any rule change, it should be clear what share of real traffic would be affected. Filtering only at the origin means you have already paid for the capacity you meant to protect. When in doubt: observe before blocking — a false positive costs more than a scan that got through.

  • The threshold that was right yesterday is wrong again after a marketing campaign goes out.
  • A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety.
  • When in doubt: observe before blocking — a false positive costs more than a scan that got through.

Common mistakes

What matters is not the packet rate but how expensive a single request is for the origin. The threshold that was right yesterday is wrong again after a marketing campaign goes out. Before any rule change, it should be clear what share of real traffic would be affected. Filtering only at the origin means you have already paid for the capacity you meant to protect. When in doubt: observe before blocking — a false positive costs more than a scan that got through.

Filtering only at the origin means you have already paid for the capacity you meant to protect. When in doubt: observe before blocking — a false positive costs more than a scan that got through. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. Filtering only at the origin means you have already paid for the capacity you meant to protect. Before any rule change, it should be clear what share of real traffic would be affected.

In summary

Before any rule change, it should be clear what share of real traffic would be affected. What matters is not the packet rate but how expensive a single request is for the origin. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. Filtering only at the origin means you have already paid for the capacity you meant to protect. A layer 7 attack often looks harmless on the network graph because bandwidth stays unremarkable. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety.

The threshold that was right yesterday is wrong again after a marketing campaign goes out. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. What matters is not the packet rate but how expensive a single request is for the origin. When in doubt: observe before blocking — a false positive costs more than a scan that got through.

Filtering only at the origin means you have already paid for the capacity you meant to protect. When in doubt: observe before blocking — a false positive costs more than a scan that got through. What matters is not the packet rate but how expensive a single request is for the origin. A rule that never fires is more dangerous than no rule — it manufactures a false sense of safety. What matters is not the packet rate but how expensive a single request is for the origin. The threshold that was right yesterday is wrong again after a marketing campaign goes out.