

The first WAFs were developed in the 1990s and the open-source WAF ModSecurity was first released in 2002 and is still in high use today. Types of Firewall and Web Application Firewalls This means the WAF is placed between a website’s origin server and a visitor’s browser, and acts as a proxy for the website origin server so that it can inspect traffic and either block it or pass it through to the origin. WAFs were first deployed in data centers, but are now often deployed in the cloud as a reverse proxy. Subsequent firewalls inspect packets based on their state in a connection (ie, if it is part of an ongoing stream of data, the start/end of a data stream or if it does not relate to other packets), and future iterations of firewalls moved into the application layer.īy contrast with firewalls, Web Application Firewalls or WAFs inspect HTTP traffic going to specific web applications, rather than traffic between servers. The first iteration of firewalls looked at individual data packets to determine where each packet came from and if it matched rules that said it could pass through into the network.

Their purpose was to act as a virtual shield between internal networks and servers and external networks (such as the Internet), so that traffic between the two could be monitored and blocked if it was deemed to be suspicious based on preset rules. What is a FirewallĬomputing firewalls were first developed while the Internet was still in its infancy in the 1980s.

Web application firewalls have been around for over 20 years, but recent advancements in how they block bad traffic and are managed by development teams encouraged us to take a look at the history of firewalls, WAFs, and where website security is heading.
