Skip to main content
Claim your .com from $2.99 — free WHOIS privacy included

Learning Hub · Intermediate · 20 minutes of reading

How to Understand Website Firewalls

Everything you need to know what a WAF does, where it sits, and what to configure — the steps, the gotcha, and the tip the support desk gives everyone.

The short answer

In one line: know what a WAF does, where it sits, and what to configure — a intermediate-level job taking 20 minutes of reading.

The walkthrough below covers each step, the mistake most people make, and the shortcut worth knowing. On HostingAlly plans, several of the steps are handled for you — we note where.

Intermediate

Skill level

5

Steps to done

Free

Support included

Tested

On our platform

This guide assumes no prior expertise — just a hosting account, a browser, and 20 minutes of reading of attention. Every instruction works on our platform exactly as written, and translates to any standard cPanel host.

Rule of the road: read the gotcha section before you begin, not after — it's harvested from the support tickets of people who didn't.

What you'll do, at a glance

Here's the complete route: place it in the stack, know your active layers, understand rule-based blocking, handle false positives calmly and read the reports occasionally.

None of the stages requires code or a terminal unless the guide explicitly says so — and where it does, the exact commands are given. The full step-by-step sits below; the surrounding sections cover the context that makes it stick.

The classic gotcha

Disabling the entire WAF because one form got blocked — the false-positive fix is a targeted exception; turning off the firewall to fix a form is treating a splinter with amputation.

It's worth internalising because it's not a rare edge case — it's the single most common way this task generates a support ticket. Knowing it in advance converts the whole job from risky to routine.

From the support desk: the shortcut

The WAF catches the known and automated; your update habit catches the rest — the two protections cover each other's blind spots, which is why neither alone is the answer.

Small habits like this are the real difference between people who find hosting easy and people who find it stressful — the tools are identical; the workflow isn't.

Where our platform does this for you

We've automated the steps that don't deserve your time: certificates issue and renew themselves, the installer handles application setup, daily backups cover the what-if, and per-site settings live in a panel instead of config files. The guide above covers what's left — the part that's actually about your site.

Stuck mid-task at an odd hour? That's what 24/7 human support is for — describe where you are in this guide and we'll take it from there.

Shield icon representing DDoS protection and site security

Why this is simpler on HostingAlly

Tutorials age badly when they're written against imaginary hosting. These are written against ours — the same panel, installer and defaults you'll actually see.

Our team migrates existing sites free of charge, typically within 24 hours and with zero downtime.

  • Step-by-step, tested as written
  • The gotcha flagged before you hit it
  • Automation covers the boring steps
  • 24/7 support if you get stuck

Why HostingAlly

What you get with every plan

No jargon tax

Terms are explained in place or linked to the glossary — nothing assumes you already know.

Automation where it belongs

SSL, backups and installs run themselves here — the guide covers only what's genuinely yours to do.

Written from real tickets

Our guides come from the support desk — the gotchas are the ones people actually hit.

The undo is always named

Where a step could bite, the guide says so and gives the reversal.

Help on standby

Stuck at step three at midnight? Support answers around the clock, mid-guide included.

Works as written

Every step tested on our own platform — no 'your host may vary' hand-waving.

Getting Started

How to get going

  1. 1

    Place it in the stack

    A web application firewall inspects HTTP requests before your application handles them — filtering exploit patterns (injections, traversal, known CVE probes) out of the stream.

  2. 2

    Know your active layers

    Our protected plans run Imunify360's WAF at server level; plugins add application-level rules; some sites add CDN-edge WAFs — layers complement, not compete.

  3. 3

    Understand rule-based blocking

    WAFs match request patterns against rule sets updated as threats emerge — the update cadence is the product; stale rules are decorative.

  4. 4

    Handle false positives calmly

    Occasionally legitimate requests match attack patterns (a form post containing SQL-ish text) — allowlisting that specific rule for that path is the fix, not disabling the WAF.

  5. 5

    Read the reports occasionally

    Blocked-attack counts contextualise the internet's background hostility — and spikes in the graph flag when your site attracted deliberate attention.

Included

What's covered on our plans

  • Free website migration handled by our team
  • cPanel — the industry-standard control panel
  • 24/7 support from real people
  • NVMe SSD storage as standard
  • 99.9% uptime commitment, monitored around the clock
  • Renewal prices that match signup prices
  • Email accounts on your own domain
  • Free domain for the first year on annual plans
  • Per-site PHP version selection
  • Free SSL certificate on every plan, renewed automatically

FAQ

Your questions, answered

Do I need to configure the server-level WAF myself?

No — it runs with maintained rule sets out of the box on protected plans. Your involvement is exception-handling if a legitimate action ever trips a rule, which support can tune in minutes.

WAF versus DDoS protection — same thing?

Different threats — the WAF inspects request content for exploits; DDoS mitigation absorbs request volume meant to overwhelm. Both stand in front of your site; one reads, the other counts.

Can I host more than one website on a plan?

On the Pro tier and above, yes — multiple sites with their own domains, email and SSL under one account. If the extra sites belong to clients rather than you, reseller hosting gives each one proper isolation instead.

Is SSL really included at no cost?

On every plan, with no exceptions — certificates are issued automatically when your domain points to us and renew themselves before expiry. The encryption is identical to paid DV certificates; paid tiers exist only for wildcard convenience or organisation-level validation.

Are backups included, and can I restore them myself?

Daily automatic backups are standard, restorable from the panel in minutes — files, databases or both, at 3am without a ticket if that's when you need it. For extra cover, you're welcome to run your own offsite copies alongside.

How long does it take to get started?

Minutes — hosting activates on payment, the domain (free for year one on annual plans) connects immediately, and one-click installers put WordPress or 400+ other apps live the same sitting. If you have an existing site, our team migrates it free, usually within 24 hours.

Do you include email with hosting?

Yes — mailboxes on your own domain come with every hosting plan, with webmail, IMAP/POP/SMTP access and spam filtering. Standalone email hosting also exists for domains whose websites live elsewhere.

Put an ally behind your website.

Free SSL, free migration, honest renewals and 24/7 human support. That's the whole pitch.

See Hosting Plans