Guides
Plain-English WAF explainers for campus and agency teams. Start with count mode, then operate without breaking forms.
Getting started
What is WAF count mode? (and why you start there)
Count mode lets campus and agency teams put a WAF in front of production without blocking real users on day one — observe ~24 hours, then promote what's safe to block.
What's safe to block on a WAF?
Learn what's safe to block on a managed WAF. Rules start in count; Promote Copilot explains Promote, Hold, or Needs allowlist — you still click once.
Operations & false positives
Campus DDoS response: keep .edu sites up under flood
Campus DDoS response for .edu and agency sites — first-hour playbook, origin IP lock-down, count→promote during recovery, and status/comms when the flood hits.
Hide your origin IP behind a WAF (and allowlist edge IPs only)
Origin IP bypass DDoS walks around your edge. Hide the origin IP behind a WAF and allowlist edge IPs only — the durable fix for campus and agency sites.
WAF false positives on forms: stop blocking legitimate POSTs
Why WAFs block registration, admissions, and government forms — multipart uploads, CSRF tokens, odd field names, payment callbacks — and how count-first stopping of false positives works.
WAF bot management for campus and agency sites
WAF bot management for campuses and agencies — stop scrapers, admissions form spam, and credential stuffing without day-one false positives. Count → promote.
Virtual patching websites with a managed WAF
Virtual patching at the edge buys time before CMS updates land. Managed WAF rules start in count; promote what's safe to block — Copilot explains, you click.
Emergency virtual patching when a CMS CVE drops
Friday CMS CVE? Put an emergency virtual patch at the edge in count first, then promote what's safe while WordPress and Drupal teams patch. Copilot explains — you click.
What a WAF 403 page means (and why you start in count)
A branded 403 is what visitors see after you promote a rule to block. Count mode comes first. Promote Copilot explains what's safe — you still click once.
Platforms
Managed WAF for WordPress without a plugin
Edge-managed WAF for WordPress — no security plugin. Cover campus departmental sites, plugin lag, and upload/form abuse with count → promote.
Managed WAF for Shopify without app spam
Edge-managed WAF for Shopify — no security app. Cover custom and headless storefronts, marketing domains you control, and cart/checkout Ajax with count → promote.
Managed WAF for Magento without an extension
Edge-managed WAF for Magento and Adobe Commerce — no security extension. Cover campus bookstores, StyleSmuggler-class zero-days, and payment paths with count → promote.
Managed WAF for Drupal without a module
Edge-managed WAF for Drupal — no security module. Cover campus multi-site estates, contrib lag, and virtual patch XSS with count → promote.
Public sector
Managed WAF for government websites
City website firewall for permits, benefits, and FOIA. How a managed WAF for government websites handles public sector WAF false positives and origin IP lock-down — count first, then promote.
Managed WAF for higher education websites
Managed WAF for higher education — university website firewall, college website WAF, campus managed WAF. Count → promote; admissions forms stay up.
WAF for student portals without breaking SSO
WAF for student portals without breaking SSO — count-first SIS, LMS, and IdP callbacks. Stop login stuffing; keep real students. Count → promote.
Security basics
What is a WAF (Web Application Firewall)?
A plain-English explanation of what a web application firewall (WAF) is, what it protects against, and how a managed WAF works.
The OWASP Top 10, explained simply
A simple explanation of the OWASP Top 10 web application risks and how a web application firewall mitigates them.
HTTP security headers, explained
What the important HTTP security headers do — HSTS, Content-Security-Policy, X-Frame-Options, and more — and why they matter.