Security (Imunify360, ModSecurity)

Understanding and Implementing Web Application Firewall (WAF)

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (8 sections)

A web application firewall (WAF) inspects each HTTP request before it reaches your website and blocks the ones that look like attacks. It is one of the most useful layers of protection for a website, but it is often misunderstood: it doesn't fix vulnerable code, and it doesn't replace updates. This guide explains what a WAF does, where it can run, how to put one in place, and what is already done for you on Domain India hosting.

Key takeaways

A WAF reads web requests (URLs, form fields, headers, uploads) and blocks known attack patterns such as SQL injection and cross-site scripting. It can run inside your web server (ModSecurity), in front of it as a reverse proxy or CDN, or as a CMS plugin. On Domain India shared hosting, a server-wide WAF is already running and managed for you; you report false positives by ticket. On your own VPS, you install and tune one yourself, starting in detection-only mode.

1. What a WAF is, and how it differs from a firewall

A network firewall decides which connections are allowed: which IP addresses and ports can reach the server. A WAF works one level higher. It reads the content of each web request and decides whether that request is safe to pass to your application.

QuestionNetwork firewallWeb application firewall
What does it look at?IP addresses, ports, protocolsURLs, parameters, headers, cookies, request bodies
What does it stop?Connections to closed ports, blocked IP addressesSQL injection, XSS, path traversal, malicious uploads, bad bots
ExampleCSF, nftables, a cloud security groupModSecurity, Coraza, a CDN's WAF, a WordPress security plugin

You need both. The firewall keeps unwanted services unreachable; the WAF protects the website that has to stay reachable.

2. What a WAF stops, and what it doesn't

A WAF is good at
  • Blocking common injection attacks (SQL injection, cross-site scripting, command injection)
  • Stopping path traversal and file-inclusion attempts
  • Filtering known vulnerability scanners and abusive bots
  • Giving you time to patch after a new plugin flaw is published
A WAF can't
  • Fix a vulnerable plugin, theme or custom code
  • Stop someone who logs in with a stolen password
  • Understand your business logic (a valid-looking request that abuses a feature)
  • Absorb a large network flood on its own; that needs upstream DDoS protection

Treat a WAF as a safety net, not a cure. The fixes that last are updates, strong passwords with two-factor authentication, and code that validates input. OWASP Top 10: practical defence for PHP and Node.js covers those.

3. How a WAF decides what to block

Most WAFs combine a few techniques:

  • Signatures (a negative security model). A ruleset describes known attack patterns. The best-known free ruleset is the OWASP Core Rule Set (CRS); hosting servers often use commercial rulesets instead.
  • Anomaly scoring. Instead of blocking on the first match, each suspicious sign adds to a score, and the request is blocked only when the total passes a threshold. This reduces false positives. The CRS works this way.
  • Allow-listing (a positive security model). Only requests that match what the application expects are allowed. It is very strong but takes work to maintain, so it is mostly used for APIs.
  • Rate limiting and bot rules. Too many requests from one source, or clients that behave like scanners, are slowed down or blocked.

A WAF can usually run in two modes: detection only, where it logs matches but blocks nothing, and blocking, where matching requests get an error, usually 403 Forbidden.

4. Where a WAF can run

TypeWhere it runsExamplesGood for
Host-basedInside the web server on your own machineModSecurity with Apache, CorazaFull control; no extra service to pay for
Reverse proxy or CDNA service in front of your serverCloudflare and other CDN WAFsStopping traffic before it reaches you; also hides your server's address
Application pluginInside the CMSWordPress security pluginsSites without server access; understands the CMS

A proxy or CDN WAF has to decrypt HTTPS to inspect it, so the provider terminates TLS for your domain. That is normal for these services, but it means they see your traffic. Choose a provider you trust, and keep HTTPS between the proxy and your server too.

Layers can be combined. A CDN WAF in front of a server-level WAF is common, and does no harm as long as you know which layer blocked a request when you troubleshoot. For CDN setup, see the complete Cloudflare setup guide.

5. The WAF on Domain India shared hosting

On shared hosting you don't need to install anything. We checked our servers directly (measured on our servers, 20 and 23 September 2026):

  • The cPanel servers run ModSecurity in Apache with Imunify360's full ruleset, including application-specific rules for common CMSs.
  • Imunify360 also runs on our DirectAdmin servers.
  • WordPress sites on the cPanel servers get an additional WordPress-specific WAF layer, on by default.
  • The protection is configured server-wide, so every account gets the same rules whatever plan it is on.

Customers can't switch the WAF off or edit its rules. That is deliberate: on a shared server, one site with its firewall off puts everyone at risk. If a rule blocks something legitimate, open a ticket with the exact URL, the time and your public IP address. Details, and how to recognise a WAF block, are in ModSecurity: logs, configuration and important limits. The Imunify360 side is covered in the Imunify360 WAF guide.

Don't add WAF directives to .htaccess

Lines such as SecRuleEngine Off in .htaccess are not accepted on our servers and cause a 500 error. Ask support instead.

6. Implementing a WAF on your own VPS

On a VPS you have root access, so the WAF is yours to install and run. A sensible path:

  1. Choose the engine.
    With Apache, ModSecurity 2 and the OWASP CRS come from your distribution's package repositories. With nginx, you need ModSecurity 3 with a connector module built for your nginx version, or you can put a reverse-proxy or CDN WAF in front instead.
  2. Start in detection-only mode.
    Set SecRuleEngine DetectionOnly, so the WAF logs what it would block without breaking anything.
  3. Use the site normally for a few days.
    Log in, save content, submit forms, upload files and run checkouts, then read the logs.
  4. Tune the false positives.
    Remove a single rule for a single URL, or stop a rule checking one field, rather than disabling rules everywhere.
  5. Switch to blocking.
    Set SecRuleEngine On, reload the web server and watch the logs closely for the first week.
  6. Keep it updated.
    Update the ruleset with your system packages, and rotate the audit log, which grows quickly and can contain personal data.

The exact commands, log locations, body-size limits and exclusion syntax are in the ModSecurity guide. Security on a VPS is your responsibility; also work through the VPS security checklist.

7. Where Domain India fits

If you want the WAF handled for you, shared hosting includes the server-wide protection described above, with rules, updates and exceptions managed by us.

cPanel Starter
₹125/mo + GST
  • 25 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 10 Email Accounts
See plan details

If your application needs its own WAF configuration, a VPS gives you root access to install and tune it yourself. VPS plans are self-managed.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Prices on the cards are Domain India list prices and exclude 18% GST.

Frequently asked questions

What is a web application firewall?

A web application firewall inspects the content of web requests, such as URLs, form fields and headers, and blocks those that match attack patterns like SQL injection or cross-site scripting. A network firewall, by contrast, only decides which IP addresses and ports can connect.

Does a WAF make my website secure on its own?

No. A WAF blocks many common attacks, but it can't fix a vulnerable plugin, stop a login with a stolen password or understand your business logic. Keep software updated and use two-factor authentication as well.

Does Domain India shared hosting include a WAF?

Yes. Our cPanel servers run ModSecurity with Imunify360's full ruleset, configured server-wide for every account, and Imunify360 also runs on our DirectAdmin servers. It is managed by us and customers can't switch it off.

What should I do if the WAF blocks something legitimate on my site?

Open a support ticket with the full URL, the exact date and time of the block, your public IP address and what you were doing. Support can then find the rule in the logs and decide whether a safe exception is possible.

How do I add a WAF to my own VPS?

With Apache, install ModSecurity and the OWASP Core Rule Set from your distribution's packages, run it in detection-only mode first, tune the false positives, then switch to blocking. With nginx, use ModSecurity 3 with a connector or put a CDN or proxy WAF in front.

Can I use Cloudflare's WAF with Domain India hosting?

You can put a CDN such as Cloudflare in front of a site hosted with us by pointing the domain's DNS to it. Its WAF then filters traffic before it reaches our servers, and the server-level WAF still applies.

Ready to protect your site? Choose cPanel hosting for a managed WAF, pick a VPS to run your own, or open a ticket if a rule is blocking your site.

Blocked by a security rule?

Send us the URL, the time and your IP address, and we will check which rule fired.

Open a ticket

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
What Is a WAF? Web Application Firewalls Explained