Walkthrough · Intermediate · 20 minutes of reading
How to Understand Website Firewalls
How to understand what a web application firewall does, where it sits, and what you might ever change, without the guessing — the steps in order, the snag ahead of time, and the tip our support team repeats daily.
The short answer
One line covers it: understand what a web application firewall does, where it sits, and what you might ever change — a intermediate-level job of roughly 20 minutes of reading.
Below is the full run of steps, the error most people trip over, and the short cut worth remembering. On Hosting & Domains plans several steps are already automated away — the guide marks each one.
By the Hosting & Domains team · Reviewed 18 August 2026
Intermediate
Skill rating
Quick
Time budget
5
Steps in total
24/7
Support on call
No prior knowledge assumed — a hosting account, a browser and 20 minutes of reading of attention is the whole entry requirement. Every instruction runs on our platform exactly as printed, and carries over to any standard cPanel host.
First rule: read the snag section before you start, not afterwards. It was distilled from the tickets of everyone who tried the other order.
The whole job in one view
Set out end to end, the route is: see where it sits in the queue, map the layers you already have, know what drives the matching, handle false positives calmly and skim the reporting.
No part of this needs code or a terminal unless the guide says so plainly — and where it does, the exact commands are printed. The step-by-step is below, with the surrounding sections supplying the context that makes it hold.
The well-worn snag
Switching the whole WAF off the first time it catches a legitimate form. A false positive needs one narrow exception written for it, whereas dropping the entire firewall to rescue a contact form trades a paper cut for an open wound.
It earns a section of its own because it is no obscure edge case — it is the single commonest reason this task reaches a support queue. Knowing it in advance turns the whole job from risky into routine.
The support desk's own short cut
The firewall stops the known and the automated; your update discipline handles the rest. Each covers the other's blind side, which is exactly why neither is enough alone.
Habits this small are what separate the people who find hosting effortless from the people who find it draining. The same tools on both sides — a different way of working.
The steps already done before you arrive
Steps that never deserved your time are taken out: certificates issue and reissue themselves, the installer handles application setup, the daily copy absorbs the what-ifs, and per-site settings live in a panel rather than a configuration file. The guide covers the remainder — the part that is actually about your site.
Stopped mid-guide at an awkward hour? That is exactly what round-the-clock support is for — say which step you are on and we take it from there.

Why this job is shorter on our plans
Tutorials written against imaginary hosting go stale fast. Ours are written against the real thing: the same panel, installer and defaults waiting in your account.
Order an annual plan and the first year of the name's registration is on us.
- Every step checked exactly as published
- The snag named before it arrives
- The dull steps taken out of your way
- People reachable at any hour you stall
Why Hosting & Domains
Standard on every plan
5 steps, nothing padded
Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.
Honest about how big it is
Understand what a web application firewall does, where it sits, and what you might ever change is a intermediate-level job — set aside 20 minutes of reading, with the platform-absorbed steps marked.
Works exactly as printed
Every step is proven on the platform we run — none of the 'your host may vary' hedging.
Help that keeps your hours, not ours
Stuck on step three at midnight? Support answers at any hour, mid-walkthrough included.
The snag, flagged up front
The classic error for this particular task is named before step one, which is how 20 minutes of reading stays 20 minutes of reading.
Taken from real tickets
These guides came out of the support queue, so every snag flagged is one people genuinely hit.
Quick Start
Order placed to site online
- 1
See where it sits in the queue
A web application firewall reads HTTP requests before your application sees them, throwing away exploit patterns such as injections, path traversal and probes for known CVEs as they go past.
- 2
Map the layers you already have
Our protected plans carry Imunify360's WAF at server level, plugins add rules inside the application, and some sites put another at the CDN edge. The layers reinforce one another rather than compete.
- 3
Know what drives the matching
Requests are matched against rule sets that get refreshed as new threats surface. That refresh cadence is the real product, since a stale rule set is decoration.
- 4
Handle false positives calmly
Now and then a legitimate request looks like an attack, for instance a form message full of SQL-flavoured text. The remedy is an exception for that rule on that path, never switching the firewall off.
- 5
Skim the reporting
The blocked-attack count shows the internet's ordinary background noise, and a spike on the graph marks the moment your site drew somebody's particular attention.
Built In
Fitted to every plan
- WordPress Toolkit, with the updates seen to for you
- Money back within 30 days on hosting plans, 7 on reseller
- LiteSpeed caching in the server itself rather than bolted on by plugin
- NVMe SSD storage on every tier, not only the dear ones
- Spam and virus screening on every mailbox by default
- The name's first year included when you order annually
- Your existing site brought across by our engineers, at no charge
- No set-up charge at any point, and no joining fee
- cPanel, which is what most of the industry already runs
- A renewal figure identical to the one you registered at
Frequently Asked
The questions that come up most
Do I have to configure the server firewall?
Not at all. From the first day of your plan it is running on maintained rule sets. Your only involvement is the occasional exception when a legitimate action trips a rule, and support tunes that in minutes over chat.
Are a WAF and DDoS protection the same thing?
They solve different problems. A WAF reads the contents of each request, looking for exploits. DDoS mitigation absorbs raw volume aimed at flattening the server. Both stand in front of your site; one reads and the other counts.
Can I choose the PHP version myself?
Yes — PHP is set per site from the control panel, so a legacy application and a current one can run side by side in one account. Extensions and per-site tuning are on the same screen, and none of it goes near a support ticket.
Will the renewal cost more than the first term?
No. The rate you order at is the rate you renew at, year after year. There is no introductory teaser here, so no second-year jump is waiting — the hosting line stays a fixed figure your accounts can plan around.
Keep reading
How to Clean Up a Hacked Website
A real recovery from a break-in rather than the visible damage tidied away — advanced level, about half a day, done properly.
How to Check DNS Propagation
Find out whether the internet has taken up your DNS change, and why some corners have not — beginner level, about 5 minutes.
DNS (Domain Name System) (Glossary)
The full definition, along with the practical consequence nobody bothers to mention.
VPS Hosting
KVM virtual servers — root access, DDoS filtering, one flat monthly figure.
Plesk Reseller Hosting
Reseller accounts built on Plesk, for teams who get on best with Plesk.
Changing hosts? Run through our checklist first.
A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.
Register it, then build on it.
Every plan carries the essentials other hosts bill as extras — and support that answers.
View VPS Hosting plans