Skip to content

Web Application Firewall rules

Web Application Firewall (WAF) rules protect applications and websites hosted on internal or cloud-based web servers from exploits and attacks.

The firewall acts as a reverse proxy and applies protection and authentication policies to web applications. You can create WAF rules for IPv4 traffic.

WAF rules let you control how requests are handled for web applications. For each path within a domain, you can specify whether the firewall blocks requests, applies WAF protection, redirects requests, or passes requests directly to a backend server. This action-based routing model allows you to apply different routing, protection, and access settings to different parts of an application.

The firewall offers preconfigured WAF rule templates with specific paths and protection policies for Exchange Autodiscover, Exchange General, Exchange Outlook Anywhere, Microsoft Lync, Microsoft Remote Desktop web client, and Microsoft Remote Desktop Gateway.

Restriction

Currently, WAF rules don't support Microsoft Exchange versions later than 2013.

WAF rules are part of firewall rules. To create a WAF rule, you must add a firewall rule and set the action to Protect with web server protection.

Restriction

The firewall doesn't support WAF over route-based IPsec if you use traffic selectors for the subnets. You can use any-to-any route-based connections. See Route-based VPN.

WAF doesn't support WebDAV, so applications such as Nextcloud aren't supported. We recommend that you route such traffic through firewall rules instead of WAF rules.

You can create a maximum of 60 WAF rules. See WAF limitation.

WAF functionality

Using a WAF rule, you can configure different actions for individual paths within a domain. Each WAF rule can contain one or more paths. For each path, you specify how the firewall handles requests that match the path. You can specify the following actions:

  • Block: Returns a specified response to the client and blocks access to the application. New WAF rules include the root path / with the Block action by default. Requests matching blocked paths aren't forwarded to a backend web server.
  • Protect: Applies WAF protection and authentication settings before forwarding requests to a backend web server. This action includes web server protection, authentication, access control, network restrictions, country restrictions, and session handling.
  • Redirect: Returns an HTTP redirection response for specific paths. You can configure the destination URL, protocol, host, and port. Requests aren't forwarded to a backend web server.
  • Passthrough: Forwards traffic directly to a backend server without WAF inspection. Use this action to securely forward WebSocket traffic through a tunnel.

You can assign multiple paths to the same action to apply the same routing and protection behavior to groups of URLs within a domain.

The firewall supports HTTPS with Server Name Indication (SNI), allowing you to create multiple virtual web servers using the same IP address and port. WAF rules support wildcard domains.

For Protect and Passthrough actions, you can associate traffic with backend web servers without configuring DNAT rules or firewall rules. You can distribute traffic across multiple web servers, use backup servers, and maintain session persistence.

Traffic shaping policies in WAF rules allow you to allocate bandwidth and prioritize traffic according to a schedule.

Protection and authentication

Protection policies: You can apply protection policies to WAF rules when you use the Protect action. They allow you to protect web servers from vulnerability exploits, such as cookie, URL, and form manipulation. They also protect web servers from application attacks and cross-site scripting (XSS) attacks. You can specify the filter strength for common threats.

The exceptions you create in WAF rules allow you to skip some types of security checks for the paths and sources you specify.

To prevent slow HTTP denial-of-service (DoS) attacks and enforce TLS version controls, go to Web server > General settings.

Authentication policies: You can apply authentication policies to WAF rules when you use the Protect action. You can specify client networks to allow or block and configure basic or form-based reverse-proxy authentication. Authentication settings allow you to control access to the paths associated with protected applications.

Authentication templates: You can upload pre-configured HTML form templates. For customizable HTML and CSS templates, go to the authentication template help page.

Reserved ports

You can't use some ports for WAF as the firewall reserves them for system services. These ports are reserved even when the services aren't in use. See Reserved ports.

Behavior after upgrading to SFOS 23.0

From SFOS 23.0, WAF rules are managed using the new action-based routing model. Instead of configuring protection settings for an entire application, you can configure different actions for individual paths within a domain to provide more granular control over how requests are handled.

When you upgrade to SFOS 23.0, existing WAF rules are automatically migrated to the new action-based routing model. Existing WAF rules are converted to Protect actions, and existing path-specific routes are preserved. This ensures that applications continue to be protected and routed as before without requiring configuration changes after the upgrade.

After the upgrade, you can modify WAF rules to use Block, Redirect, or Passthrough actions for specific paths while retaining the original configuration for the rest of the application.