WAF setup
We connect and configure a WAF (Web Application Firewall) — Cloudflare, ModSecurity or analog: filtering malicious requests, protection against typical attacks (OWASP Top 10), rules for your site. To cut off automated attacks and reduce the risk of exploiting vulnerabilities. Honestly upfront: a WAF substantially reduces risk and cuts off mass attacks, but does NOT guarantee 'invulnerability' and does not replace fixing code holes; and it requires rule setup, otherwise it falsely blocks or lets through.
WAF setup — overview

WAF setup is a project: we connect a WAF (cloud, e.g. Cloudflare, or server-side ModSecurity), enable base rule sets (OWASP CRS), configure rules for your stack, modes (block/challenge/log), exclusions for legitimate traffic, basic bot protection and protection against common attacks (injections, XSS patterns, scanners). Honestly about the effect and limits, this is key: a WAF is an important protection layer: it cuts off mass automated attacks, scanners and typical exploits, substantially reducing risk; but it does NOT make the site 'invulnerable' and does NOT fix the vulnerabilities themselves — it is a filter in front of the application, while a code hole must be fixed separately (a targeted attack can bypass a WAF). A WAF is part of defense-in-depth, not the only protection. Honestly about false positives: WAF rules are a balance; too strict block legitimate users/features, too lax let through; setup and tuning for your traffic are needed (see a separate tuning service). Honestly about cost: a cloud WAF is a third-party service with its own plans (Cloudflare has a free base one, advanced is paid, directly), billed separately. Honestly about access: access to DNS/server is needed. Honestly about maintenance: threats change — rules need upkeep. An important boundary: this is WAF setup, not fine rule tuning as separate deep work (766), not DDoS protection (738 — adjacent) and not code audit/fixing. Picture this: instead of 'any scanner and bot hammers your application directly' — a filter cutting off mass malicious traffic. The base price starts from 18,000 ₽ per project; it depends on the WAF and rule complexity (the service plan — separate).
Problems we solve
- The site is open to scanners, bots and typical attacks directly.
- There is no malicious-request filter in front of the application.
- Known attack patterns (injections, XSS) are not cut off.
- The WAF is not set up or is 'as is', without rules for the site.
What's included in the WAF setup service
- Connecting the WAF (cloud/ModSecurity)
- Base rule sets (OWASP CRS)
- Rules for your stack and modes (block/challenge/log)
- Exclusions for legitimate traffic
- Basic bot and common-attack protection
- Checking for false positives
- Indicating boundaries (WAF ≠ fixing vulnerabilities)
- Handover and review with you
What you get
- Mass automated attacks are cut off
- Reduced risk of exploiting typical vulnerabilities
- A filter in front of the application (defense-in-depth)
- Less malicious traffic (invulnerability — not guaranteed)
How the work goes: steps
- We clarify the stack, traffic, WAF; collect DNS/server access
- We connect the WAF, enable rules, set up exclusions
- We check false positives, review with you
Why PDV Expert
- Fixed price and timeline — no surprises on the invoice.
- Report and recommendations in plain language — clear without a technical background.
- In touch at every step and answering questions about the result.
FAQ
Will a WAF make the site invulnerable?
No. A WAF substantially reduces risk and cuts off mass attacks/scanners, but does not make the site invulnerable or fix the vulnerabilities themselves — it is a filter in front of the application, a code hole must be fixed separately, and a targeted attack can bypass a WAF. It is part of protection, not the only one.
Won't a WAF block real users?
It can, if rules are too strict — it is a balance. Too lax let attacks through, too strict block the legitimate. So we configure for your traffic and check false positives; fine tuning is a separate service.
Is the WAF plan included in the price?
No. A cloud WAF is a third-party service: there is a free base one (Cloudflare), advanced features are paid, directly to the service, separate from our setup. ModSecurity is free but needs a server and upkeep.
About the provider
The «WAF setup» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.