Get started with WAF protection

Updated at:

ESA WAF provides four protection policies of increasing complexity, from one-click AI-powered rate limiting to fully custom rules.

Mitigation policies

The table below compares all four policies. Start with the one that fits your needs — you can layer more later.

Policy

Use cases

Complexity

Key benefits

Smart rate limiting

Individual developers and new, small-scale websites

Very Low

One-click, AI-powered protection with zero configuration.

Create rules from security analytics

Proactive identification and mitigation of potential threats on stable websites.

Low

Data-driven insights to pinpoint and quickly respond to anomalous traffic.

Create rules from a rule template

Combat common attacks or address specific protection needs.

Medium

Pre-built templates cover common scenarios for efficient deployment.

Create custom rules

Complex or unique security needs requiring fine-grained control.

High

Flexible enough for complex protection requirements.

Policy 1: Smart rate limiting

This is the fastest way to get started, ideal for users new to web security.

The smart rate limiting feature uses ESA's AI engine to automate rate limiting. Enable the feature and select a protection level. The system learns a baseline from your past seven days of traffic and blocks requests that exceed normal patterns — no manual configuration required. Effective against CC attacks (resource exhaustion) and malicious crawlers.

Use cases

  • Individual developers or startups: Low-traffic websites that need basic CC attack protection with minimal setup.

  • Security beginners: Users unfamiliar with WAF who need one-click protection.

Before you begin

  • Activation time: Takes effect about 10 seconds after enablement.

  • Block duration: IPs that trigger rate limiting are blocked for approximately 24 hours.

  • Handling false positives: If a legitimate IP address is blocked, add it to a whitelist under WAF > Whitelist Rules.

Steps

  1. In the ESA console, select Websites, and in the Website column, click the target site.

  2. In the left navigation pane, choose Security > WAF.

  3. On the Overview tab, find the Smart Rate Limiting section and click Configure. Turn on the Status switch, then configure the Protection Level and Action. We recommend setting the Protection Level to Medium and the Action to Block.

Note

Available protection levels and actions.

Policy 2: Security analytics

Monitor traffic proactively and respond to potential threats.

ESA provides Security Analytics and Events dashboards to inspect requests by IP, path, and User-Agent. When you spot anomalies, create a WAF rule from the dashboard with one click. For example:

  • Block an IP sending repeated malicious requests.

  • Block a crawler disguised as a browser by its User-Agent.

Use cases

  • Growing websites: Detect anomalies early as website traffic grows.

  • Proactive security operations: Stop suspicious behavior, such as rapid directory scanning, before it escalates.

Note

Security Analytics and Events data has approximately 5 minutes of latency.

Steps

  1. On the Security Analytics page, to the right of the filters, click Create rule from filter conditions.

    Note

    On the Request Analytics tab of the Overview module, you can select Create Custom WAF Rule from Filters. On the Bot Analytics tab of the Overview module, you can select Create Bot Management Rule from Filters. On the Rate Limiting Analytics tab of the Overview module, you can select Create WAF Rate Limiting Rule from Filters.

  2. On the new rule page, enter a Rule Name, select an action, and click OK. The rule takes effect immediately.

Policy 3: Rule templates

Use rule templates to combat common attack types.

ESA provides pre-configured rule templates based on real-world attack data: blocking empty-Referer requests, protecting login pages from brute force, and allowlisting IPs. Select a template, fill in the parameters (such as your login URL), and the rule deploys immediately.

Use cases

  • Common attacks: Your website faces brute-force, SQL injection, or similar attacks.

  • Clear protection goals: You know exactly what you need, such as "allow only search engine crawlers".

Note

Read each template's description before use. Misconfigured parameters may block legitimate traffic.

Steps

  1. In the ESA console, select Websites, and in the Website column, click the target site.

  2. In the left navigation pane, choose Security > WAF.

  3. On the Overview tab, select a Rule Template that fits your current scenario, and then click Create.

  4. On the rule creation page, fill in the template parameters as needed, and then click OK. The rule takes effect immediately.

Policy 4: Custom rules

When other policies fall short, use WAF Configuration Rules for fully customized protection.

Custom rules combine request attributes — IP, URL path, headers, cookies, and body — into match conditions. Assign an action (block, observe, or allow) for full control over traffic filtering.

Use cases

  • Advanced security operations: You need fine-grained, multi-condition rules built by experienced security engineers.

  • Special business scenarios: Your application requires tightly integrated rules, such as restricting API access to users with a specific cookie.

  • Responding to complex attacks: You face advanced persistent threats (APTs) with evolving methods that demand adaptive rules.

Example

This example creates a rate limiting rule: if a single IP sends more than 20 requests to www.example.com and image.example.com within 10 seconds, subsequent requests from that IP are challenged with a slider CAPTCHA for 1 minute.

  1. In the ESA console, select Websites, and in the Website column, click the target site.

  2. In the left navigation pane, choose Security > WAF.

  3. On the WAF page, select the Rate Limiting Rules tab, click Create Rule, and then enter the rule information based on the on-screen instructions.

  4. Enter a Rule Name.

  5. Configure If requests match... to filter user requests that meet the rule expression. For the request match fields, see Match fields. In this example, select Hostname for the match type field, select is in for the match operator field, and enter www.example.com and image.example.com in the match value field.

  6. Configure Apply to Cache. Rate limiting reduces the number of requests from clients that share the same characteristics, which lowers the request load on your origin server. However, requests that hit the cache are served directly by ESA and do not reach your origin server. If you do not want rate limiting to apply to cached requests, clear this checkbox.

  7. Configure With the same characteristics... to filter requests that meet the rule expression again.

  8. Configure When the rate exceeds... to set the maximum number of times that the statistical object can match the conditions within the statistical period.

  9. When the action is set to Apply to Matched Requests, the action duration is the same as the statistical period.

  10. WAF counts a request after the response to the request ends. If your traffic contains many large-file requests, the long download times delay the point at which blocking actually starts.

  11. Configure Then execute... to select the action to execute when the request rate reaches the limit. You can apply the action only to requests that exceed the limit, or to all requests that match the characteristics after the limit is exceeded. For more information about the actions, see Actions.

  12. Click OK.