

For a WAF, its protection is in the reverse direction: it positions itself in the middle of data flows between the server and client machines to protect the server from potentially malicious traffic originating from clients. Proxies typically protect client machines’ identities from web servers by positioning itself in the middle of the data flows between client and server machines. How a WAF worksĬonceptually, a WAF works like a reverse proxy. In the Open Systems Interconnection (OSI) seven-layer model, a WAF operates at the application level, which is the seventh and highest level.

A WAF serves two major functions: preventing malicious traffic from reaching web applications hosted on a server and preventing unauthorized data from leaving the web server. A Web Application Firewall, as the term firewall implies, is a middleman that sits between web applications on a web server and the Internet.
