Getting started with the Edge WAF

If your web application uses a Fastly CDN or Compute service, you can integrate the Next-Gen WAF into your request flow by enabling an Edge WAF deployment. Like your CDN or Compute service, Fastly delivers the Edge WAF through our global network of POPs. This means that you don’t have to make any changes to your hosting environment (e.g., installing clients or applications locally). The Edge WAF is able to process a request within a few milliseconds.

Prerequisites

Before enabling the Edge WAF, be sure you have the following prerequisites in place:

Quick start

Once all prerequisites have been met, you can enable the Edge WAF for your web application. If you're able to access the WAF using the Fastly control panel, follow the Fastly control panel instructions. Otherwise, use the Next-Gen WAF control panel instructions.

HINT: Have a Compute service? Check out our tutorial.

  1. Fastly control panel
  2. Next-Gen WAF control panel
  1. Log in to the Fastly control panel.
  2. From the Home page, select the appropriate service. You can use the search box to search by ID, name, or domain.
  3. Click Edit configuration and then select the option to clone the active version.
  4. Click Security.

  5. In the Next-Gen WAF card, click the pencil Pencil icon to edit the following deployment settings and then click Submit:

    Edit Next-Gen WAF deployment settings

    • From the Workspace menu, select the workspace that you want to link to the service. If your account only has one workspace, this field is read-only.
    • In the % of traffic field, enter the percentage of traffic that you want the Next-Gen WAF to inspect. When set to 100, all traffic to your service is inspected. When the value is less than 100, a random sample of the specified percentage is inspected.
  6. Click the switch to the On position.

  7. (Optional) Use attack tooling to verify that the Next-Gen WAF is monitoring your web application and identifying malicious and anomalous requests.

What’s next

Learn more about how the Edge WAF works and adjust the protection of your web application as needed.