Protects websites from attacks with a high-performance and complete Web Application Firewall (WAF) module.

Prevent security breaches

Provide robust protection against application threats, including OWASP3’s Top Ten, which allows companies to prevent data theft and degradation. By integrating whitelist and blacklist security and automated application learning, WAF can accurately locate attacks. Thanks to the ability to disinfect entries, the WAF can make attacks harmless without disrupting users’ access to applications.

Protect their data and brand by avoiding data leaks

The WAF can inspect outgoing traffic for sensitive data such as credit card and social security numbers. With easy-to-define PCRE (Perl Compatible Regular Expressions) masks, companies can hide custom strings, such as obscene words, that appear in website forums.

Reduce application vulnerabilitie

With ready-to-use protection against web attacks such as SQL injection and cross-site scripts, WAF can prevent hackers from exploiting web site vulnerabilities. Customized aFleX scripting rules can be defined by customers to patch remaining vulnerabilities, ensuring that applications are protected from abuse.

Protect sessions and cookies

By optionally encrypting cookies, WAF can protect applications against threats such as cookie poisoning, cookie injection and session replay. Administrators can set cookies to be encrypted, which allows them to limit protection to sensitive read-only cookies, such as session cookies.

Stop automatic attacks

The WAF protects against application DDoS attacks, SQL injections, XSS vulnerabilities, prevents buffer overflow attacks by setting maximum thresholds accepted for certain aspects of HTTP requests and blocking requests that exceed configured limits. Block automated attacks from a specific region using IP geolocation.

Ensure that attackers cannot escape web defenses

The solution standardizes each web request before inspecting it, ensuring that attackers cannot bypass the web application firewall by obscuring it.

Prevent search engines from indexing sensitive data

Block requests for password-protected or private sections of a protected website from search engine or user agent IP addresses. Administrators can set policies to block access to specific web pages or to block specific user agents from the Appliance’s web user interface.


Data security & global compliance : EU (HDS & ISO 27001), US (HIPAA), China (CSL & PHIMM).


