Learning Hub · Intermediate · 20 minutes of reading
How to Understand Website Firewalls
Everything you need to know what a WAF does, where it sits, and what to configure — the steps, the gotcha, and the tip the support desk gives everyone.
The short answer
In one line: know what a WAF does, where it sits, and what to configure — a intermediate-level job taking 20 minutes of reading.
The walkthrough below covers each step, the mistake most people make, and the shortcut worth knowing. On HostingAlly plans, several of the steps are handled for you — we note where.
Intermediate
Skill level
5
Steps to done
Free
Support included
Tested
On our platform
This guide assumes no prior expertise — just a hosting account, a browser, and 20 minutes of reading of attention. Every instruction works on our platform exactly as written, and translates to any standard cPanel host.
Rule of the road: read the gotcha section before you begin, not after — it's harvested from the support tickets of people who didn't.
What you'll do, at a glance
Here's the complete route: place it in the stack, know your active layers, understand rule-based blocking, handle false positives calmly and read the reports occasionally.
None of the stages requires code or a terminal unless the guide explicitly says so — and where it does, the exact commands are given. The full step-by-step sits below; the surrounding sections cover the context that makes it stick.
The classic gotcha
Disabling the entire WAF because one form got blocked — the false-positive fix is a targeted exception; turning off the firewall to fix a form is treating a splinter with amputation.
It's worth internalising because it's not a rare edge case — it's the single most common way this task generates a support ticket. Knowing it in advance converts the whole job from risky to routine.
From the support desk: the shortcut
The WAF catches the known and automated; your update habit catches the rest — the two protections cover each other's blind spots, which is why neither alone is the answer.
Small habits like this are the real difference between people who find hosting easy and people who find it stressful — the tools are identical; the workflow isn't.
Where our platform does this for you
We've automated the steps that don't deserve your time: certificates issue and renew themselves, the installer handles application setup, daily backups cover the what-if, and per-site settings live in a panel instead of config files. The guide above covers what's left — the part that's actually about your site.
Stuck mid-task at an odd hour? That's what 24/7 human support is for — describe where you are in this guide and we'll take it from there.

Why this is simpler on HostingAlly
Tutorials age badly when they're written against imaginary hosting. These are written against ours — the same panel, installer and defaults you'll actually see.
Our team migrates existing sites free of charge, typically within 24 hours and with zero downtime.
- Step-by-step, tested as written
- The gotcha flagged before you hit it
- Automation covers the boring steps
- 24/7 support if you get stuck
Why HostingAlly
What you get with every plan
No jargon tax
Terms are explained in place or linked to the glossary — nothing assumes you already know.
Automation where it belongs
SSL, backups and installs run themselves here — the guide covers only what's genuinely yours to do.
Written from real tickets
Our guides come from the support desk — the gotchas are the ones people actually hit.
The undo is always named
Where a step could bite, the guide says so and gives the reversal.
Help on standby
Stuck at step three at midnight? Support answers around the clock, mid-guide included.
Works as written
Every step tested on our own platform — no 'your host may vary' hand-waving.
Getting Started
How to get going
- 1
Place it in the stack
A web application firewall inspects HTTP requests before your application handles them — filtering exploit patterns (injections, traversal, known CVE probes) out of the stream.
- 2
Know your active layers
Our protected plans run Imunify360's WAF at server level; plugins add application-level rules; some sites add CDN-edge WAFs — layers complement, not compete.
- 3
Understand rule-based blocking
WAFs match request patterns against rule sets updated as threats emerge — the update cadence is the product; stale rules are decorative.
- 4
Handle false positives calmly
Occasionally legitimate requests match attack patterns (a form post containing SQL-ish text) — allowlisting that specific rule for that path is the fix, not disabling the WAF.
- 5
Read the reports occasionally
Blocked-attack counts contextualise the internet's background hostility — and spikes in the graph flag when your site attracted deliberate attention.
Included
What's covered on our plans
- Free website migration handled by our team
- cPanel — the industry-standard control panel
- 24/7 support from real people
- NVMe SSD storage as standard
- 99.9% uptime commitment, monitored around the clock
- Renewal prices that match signup prices
- Email accounts on your own domain
- Free domain for the first year on annual plans
- Per-site PHP version selection
- Free SSL certificate on every plan, renewed automatically
FAQ
Your questions, answered
Do I need to configure the server-level WAF myself?
No — it runs with maintained rule sets out of the box on protected plans. Your involvement is exception-handling if a legitimate action ever trips a rule, which support can tune in minutes.
WAF versus DDoS protection — same thing?
Different threats — the WAF inspects request content for exploits; DDoS mitigation absorbs request volume meant to overwhelm. Both stand in front of your site; one reads, the other counts.
Can I host more than one website on a plan?
On the Pro tier and above, yes — multiple sites with their own domains, email and SSL under one account. If the extra sites belong to clients rather than you, reseller hosting gives each one proper isolation instead.
Is SSL really included at no cost?
On every plan, with no exceptions — certificates are issued automatically when your domain points to us and renew themselves before expiry. The encryption is identical to paid DV certificates; paid tiers exist only for wildcard convenience or organisation-level validation.
Are backups included, and can I restore them myself?
Daily automatic backups are standard, restorable from the panel in minutes — files, databases or both, at 3am without a ticket if that's when you need it. For extra cover, you're welcome to run your own offsite copies alongside.
How long does it take to get started?
Minutes — hosting activates on payment, the domain (free for year one on annual plans) connects immediately, and one-click installers put WordPress or 400+ other apps live the same sitting. If you have an existing site, our team migrates it free, usually within 24 hours.
Do you include email with hosting?
Yes — mailboxes on your own domain come with every hosting plan, with webmail, IMAP/POP/SMTP access and spam filtering. Standalone email hosting also exists for domains whose websites live elsewhere.
Keep exploring
How to Migrate a WordPress Site
Move a WordPress site between hosts with zero visitor-facing downtime — intermediate level, 1–2 hours (or a free ticket to us).
How to Harden a Site With .htaccess
Server-level protections in a few careful lines — advanced level, 30 minutes.
Domain Names
Search, register and transfer domains — first year free on annual hosting.
WordPress Hosting
Managed WordPress with LiteSpeed caching, staging and automatic backups.
Put an ally behind your website.
Free SSL, free migration, honest renewals and 24/7 human support. That's the whole pitch.
See Hosting Plans