How it works
A WAF inspects each HTTP request before it reaches your server and blocks those that match known attack patterns: SQL injection and XSS attempts, probes for known vulnerable plugins, bad bots and abusive request rates. Rules come as managed rulesets kept up to date by the vendor (several are based on the open-source OWASP Core Rule Set) plus custom rules you write, such as closing the admin area to other countries or limiting login attempts per minute.
A distributed denial-of-service (DDoS) attack sends more traffic than a server or network can handle, from thousands of machines at once. Protection works at the network layer (floods of packets) and at the application layer (floods of real-looking HTTP requests), and relies on a provider with enough capacity, spread across many data centres, to absorb the flood. Cloudflare includes unmetered DDoS protection on every plan, the free one included, and AWS Shield Standard is automatic for AWS customers.
Other options include AWS WAF, Google Cloud Armor, Azure WAF, Akamai and Fastly, plus the open-source ModSecurity and Coraza engines. AWS WAF charges about $5 a month per web ACL (a set of rules), $1 a month per rule and $0.60 per million requests; AWS Shield Advanced costs about $3,000 a month on a one-year commitment. A WAF buys time but does not fix the bug underneath, and the origin server should accept traffic only from the WAF so that nobody can go around it.
WAF and DDoS protection pros and cons
Pros
- Blocks common attacks before they reach your code
- Can patch a known hole within minutes while a proper fix is written
- Absorbs floods of traffic that would take a single server down
- Rate limits and bot rules live in the same place
- Cloudflare's free plan already covers many small sites
Cons
- False positives can block real users until the rules are tuned
- No substitute for fixing vulnerabilities in the code
- Full managed rulesets and advanced bot management cost extra
- All traffic passes through a third party that decrypts it
When to use WAF and DDoS protection
Pick it when
- Any public website or API, especially login, search and checkout pages
- You run software, such as WordPress plugins, that may have known holes
- Bots, scrapers or attack traffic are already hitting the site
Skip it when
- Internal tools reachable only over a VPN or private network
- Your host already filters attack traffic and you have no rules of your own to add
WAF and DDoS protection pricing
Free tier
Cloudflare Free includes unmetered DDoS protection, a free managed ruleset and 5 custom rules; Pro is about $20 a month billed yearly ($25 monthly) and Business about $200. Enterprise is custom.
WAF and DDoS protection pricing page (opens in a new tab)Approximate, checked September 2026.What the other tools cost
Related terms
More in Security
Defences