Skip to main content

Walkthrough · Intermediate · 20 minutes of reading

How to Understand Website Firewalls

How to understand what a web application firewall does, where it sits, and what you might ever change, without the guessing — the steps in order, the snag ahead of time, and the tip our support team repeats daily.

The short answer

One line covers it: understand what a web application firewall does, where it sits, and what you might ever change — a intermediate-level job of roughly 20 minutes of reading.

Below is the full run of steps, the error most people trip over, and the short cut worth remembering. On Hosting & Domains plans several steps are already automated away — the guide marks each one.

By the Hosting & Domains team · Reviewed 18 August 2026

Intermediate

Skill rating

Quick

Time budget

5

Steps in total

24/7

Support on call

No prior knowledge assumed — a hosting account, a browser and 20 minutes of reading of attention is the whole entry requirement. Every instruction runs on our platform exactly as printed, and carries over to any standard cPanel host.

First rule: read the snag section before you start, not afterwards. It was distilled from the tickets of everyone who tried the other order.

The whole job in one view

Set out end to end, the route is: see where it sits in the queue, map the layers you already have, know what drives the matching, handle false positives calmly and skim the reporting.

No part of this needs code or a terminal unless the guide says so plainly — and where it does, the exact commands are printed. The step-by-step is below, with the surrounding sections supplying the context that makes it hold.

The well-worn snag

Switching the whole WAF off the first time it catches a legitimate form. A false positive needs one narrow exception written for it, whereas dropping the entire firewall to rescue a contact form trades a paper cut for an open wound.

It earns a section of its own because it is no obscure edge case — it is the single commonest reason this task reaches a support queue. Knowing it in advance turns the whole job from risky into routine.

The support desk's own short cut

The firewall stops the known and the automated; your update discipline handles the rest. Each covers the other's blind side, which is exactly why neither is enough alone.

Habits this small are what separate the people who find hosting effortless from the people who find it draining. The same tools on both sides — a different way of working.

The steps already done before you arrive

Steps that never deserved your time are taken out: certificates issue and reissue themselves, the installer handles application setup, the daily copy absorbs the what-ifs, and per-site settings live in a panel rather than a configuration file. The guide covers the remainder — the part that is actually about your site.

Stopped mid-guide at an awkward hour? That is exactly what round-the-clock support is for — say which step you are on and we take it from there.

The filtering that absorbs an attack well before it reaches the site

Why this job is shorter on our plans

Tutorials written against imaginary hosting go stale fast. Ours are written against the real thing: the same panel, installer and defaults waiting in your account.

Order an annual plan and the first year of the name's registration is on us.

  • Every step checked exactly as published
  • The snag named before it arrives
  • The dull steps taken out of your way
  • People reachable at any hour you stall

Why Hosting & Domains

Standard on every plan

5 steps, nothing padded

Each stage is a few minutes of steady clicking, and the fiddly moments are labelled fiddly.

Honest about how big it is

Understand what a web application firewall does, where it sits, and what you might ever change is a intermediate-level job — set aside 20 minutes of reading, with the platform-absorbed steps marked.

Works exactly as printed

Every step is proven on the platform we run — none of the 'your host may vary' hedging.

Help that keeps your hours, not ours

Stuck on step three at midnight? Support answers at any hour, mid-walkthrough included.

The snag, flagged up front

The classic error for this particular task is named before step one, which is how 20 minutes of reading stays 20 minutes of reading.

Taken from real tickets

These guides came out of the support queue, so every snag flagged is one people genuinely hit.

Quick Start

Order placed to site online

  1. 1

    See where it sits in the queue

    A web application firewall reads HTTP requests before your application sees them, throwing away exploit patterns such as injections, path traversal and probes for known CVEs as they go past.

  2. 2

    Map the layers you already have

    Our protected plans carry Imunify360's WAF at server level, plugins add rules inside the application, and some sites put another at the CDN edge. The layers reinforce one another rather than compete.

  3. 3

    Know what drives the matching

    Requests are matched against rule sets that get refreshed as new threats surface. That refresh cadence is the real product, since a stale rule set is decoration.

  4. 4

    Handle false positives calmly

    Now and then a legitimate request looks like an attack, for instance a form message full of SQL-flavoured text. The remedy is an exception for that rule on that path, never switching the firewall off.

  5. 5

    Skim the reporting

    The blocked-attack count shows the internet's ordinary background noise, and a spike on the graph marks the moment your site drew somebody's particular attention.

Built In

Fitted to every plan

  • WordPress Toolkit, with the updates seen to for you
  • Money back within 30 days on hosting plans, 7 on reseller
  • LiteSpeed caching in the server itself rather than bolted on by plugin
  • NVMe SSD storage on every tier, not only the dear ones
  • Spam and virus screening on every mailbox by default
  • The name's first year included when you order annually
  • Your existing site brought across by our engineers, at no charge
  • No set-up charge at any point, and no joining fee
  • cPanel, which is what most of the industry already runs
  • A renewal figure identical to the one you registered at

Frequently Asked

The questions that come up most

Do I have to configure the server firewall?

Not at all. From the first day of your plan it is running on maintained rule sets. Your only involvement is the occasional exception when a legitimate action trips a rule, and support tunes that in minutes over chat.

Are a WAF and DDoS protection the same thing?

They solve different problems. A WAF reads the contents of each request, looking for exploits. DDoS mitigation absorbs raw volume aimed at flattening the server. Both stand in front of your site; one reads and the other counts.

Can I choose the PHP version myself?

Yes — PHP is set per site from the control panel, so a legacy application and a current one can run side by side in one account. Extensions and per-site tuning are on the same screen, and none of it goes near a support ticket.

Will the renewal cost more than the first term?

No. The rate you order at is the rate you renew at, year after year. There is no introductory teaser here, so no second-year jump is waiting — the hosting line stays a fixed figure your accounts can plan around.

Keep reading

Changing hosts? Run through our checklist first.

A plain order of work for a move nobody visiting will notice: which files go over first, how to carry the mail across without losing a message, when exactly to repoint DNS, and the two mistakes behind nearly every outage we are asked to rescue.

What arrives is the checklist, and then the occasional note on keeping a site quick. Leave whenever you like; the privacy policy covers the rest.

Register it, then build on it.

Every plan carries the essentials other hosts bill as extras — and support that answers.

View VPS Hosting plans