S
1

Bought a "developer friendly" WAF and my team spent 3 days fixing false positives

Last month we rolled out a new WAF from a vendor called ShieldWall (they had a flashy demo at a conference). Within 2 hours our login endpoint was blocked because it flagged a legit POST request as an SQLi attempt. My team spent 3 days whitelisting rules and tuning thresholds before it worked right. Has anyone else had a WAF that was way too aggressive out of the box?
2 comments

Log in to join the discussion

Log In
2 Comments
john_cooper
Did you try turning on the "learning mode" first before going full blocking? We had the same headache with ours and it saved us a ton of time just letting it watch traffic for a week before it started actually stopping anything.
5
willow114
willow1141mo ago
Learning mode saved my sanity when my firewall kept blocking my own streaming services. @john_cooper that's solid advice.
2