Site quality · Site security

WAF setup

We connect and configure a WAF (Web Application Firewall) — Cloudflare, ModSecurity or analog: filtering malicious requests, protection against typical attacks (OWASP Top 10), rules for your site. To cut off automated attacks and reduce the risk of exploiting vulnerabilities. Honestly upfront: a WAF substantially reduces risk and cuts off mass attacks, but does NOT guarantee 'invulnerability' and does not replace fixing code holes; and it requires rule setup, otherwise it falsely blocks or lets through.

Price
$3,600
Duration
usually 4–7 business days; depends on the WAF

WAF setup — overview

WAF setup — price, timeline & scope

WAF setup is a project: we connect a WAF (cloud, e.g. Cloudflare, or server-side ModSecurity), enable base rule sets (OWASP CRS), configure rules for your stack, modes (block/challenge/log), exclusions for legitimate traffic, basic bot protection and protection against common attacks (injections, XSS patterns, scanners). Honestly about the effect and limits, this is key: a WAF is an important protection layer: it cuts off mass automated attacks, scanners and typical exploits, substantially reducing risk; but it does NOT make the site 'invulnerable' and does NOT fix the vulnerabilities themselves — it is a filter in front of the application, while a code hole must be fixed separately (a targeted attack can bypass a WAF). A WAF is part of defense-in-depth, not the only protection. Honestly about false positives: WAF rules are a balance; too strict block legitimate users/features, too lax let through; setup and tuning for your traffic are needed (see a separate tuning service). Honestly about cost: a cloud WAF is a third-party service with its own plans (Cloudflare has a free base one, advanced is paid, directly), billed separately. Honestly about access: access to DNS/server is needed. Honestly about maintenance: threats change — rules need upkeep. An important boundary: this is WAF setup, not fine rule tuning as separate deep work (766), not DDoS protection (738 — adjacent) and not code audit/fixing. Picture this: instead of 'any scanner and bot hammers your application directly' — a filter cutting off mass malicious traffic. The base price starts from 18,000 ₽ per project; it depends on the WAF and rule complexity (the service plan — separate).

Problems we solve

  • The site is open to scanners, bots and typical attacks directly.
  • There is no malicious-request filter in front of the application.
  • Known attack patterns (injections, XSS) are not cut off.
  • The WAF is not set up or is 'as is', without rules for the site.

What's included in the WAF setup service

  • Connecting the WAF (cloud/ModSecurity)
  • Base rule sets (OWASP CRS)
  • Rules for your stack and modes (block/challenge/log)
  • Exclusions for legitimate traffic
  • Basic bot and common-attack protection
  • Checking for false positives
  • Indicating boundaries (WAF ≠ fixing vulnerabilities)
  • Handover and review with you

What you get

  • Mass automated attacks are cut off
  • Reduced risk of exploiting typical vulnerabilities
  • A filter in front of the application (defense-in-depth)
  • Less malicious traffic (invulnerability — not guaranteed)

How the work goes: steps

  • We clarify the stack, traffic, WAF; collect DNS/server access
  • We connect the WAF, enable rules, set up exclusions
  • We check false positives, review with you

Why PDV Expert

  • Fixed price and timeline — no surprises on the invoice.
  • Report and recommendations in plain language — clear without a technical background.
  • In touch at every step and answering questions about the result.

FAQ

  • Will a WAF make the site invulnerable?

    No. A WAF substantially reduces risk and cuts off mass attacks/scanners, but does not make the site invulnerable or fix the vulnerabilities themselves — it is a filter in front of the application, a code hole must be fixed separately, and a targeted attack can bypass a WAF. It is part of protection, not the only one.

  • Won't a WAF block real users?

    It can, if rules are too strict — it is a balance. Too lax let attacks through, too strict block the legitimate. So we configure for your traffic and check false positives; fine tuning is a separate service.

  • Is the WAF plan included in the price?

    No. A cloud WAF is a third-party service: there is a free base one (Cloudflare), advanced features are paid, directly to the service, separate from our setup. ModSecurity is free but needs a server and upkeep.

About the provider

The «WAF setup» service is provided by PDV Expert — a team specialising in «Site quality». We work under contract and deliver a written report with recommendations.

Prepared by PDV Expert · updated