Photo by Ellie Storms on Unsplash
Secure Web Applications with SafeLine
Upstream Guardian
Anyone offering a public web service must be prepared for automated scanners, bots, and even targeted attacks. The question is not whether a web server will be attacked, but how well it is protected.
A classic firewall primarily filters on the basis of IP addresses, protocols, and ports; however, for a publicly accessible web server, at least ports 80 (HTTP) and 443 (HTTPS) must be open. The service is then technically accessible to both legitimate visitors and attackers. A legacy firewall cannot evaluate the content of an HTTP request, which is precisely where a web application firewall (WAF) steps in.
How a WAF Works
A WAF typically runs as a reverse proxy between the client and the web server, acting as a web server to the browser and as a client to the actual web server. All the HTTP and HTTPS traffic flows through this additional instance before reaching the application.
Because the WAF sits in the data path, it can inspect, filter, or block requests as needed. The ruleset is similar to that of a traditional firewall but also takes into account protocol details such as headers, URLs, or request rates. The two components are not mutually exclusive but complement each other in a security strategy. A WAF is usually recommended for publicly accessible web applications [1].
Web servers are not completely defenseless even without a dedicated WAF. NGINX and the Apache HTTP Server come with their own filtering mechanisms, are capable of blocking IP addresses, and can be combined with tools such as Fail2ban. ModSecurity has also been available for many years as a protection module for Apache, NGINX, and Internet Information Services (IIS). That said, a standalone WAF consistently separates the protection function from the web application and is deployed as a separate instance upstream of the application.
The WAF will
...
Buy this article as PDF
(incl. VAT)
Buy ADMIN Magazine
Subscribe to our ADMIN Newsletters
Subscribe to our Linux Newsletters
Find Linux and Open Source Jobs
Most Popular
Focus On Self-Hosting
• Reliable Network Storage with TrueNAS Community Edition
• Self-Hosted File Syncing with Seafile
• Wiring the Modern Stack with Node-RED
• Self-Hosted Collaboration with Forgejo
• Self-Hosted PaaS with Coolify
• Build and Host Docker Images
• Self-Hosted Pritunl VPN Server with MFA
Support Our Work
ADMIN content is made possible with support from readers like you. Please consider contributing when you've found an article to be beneficial.
