1
Bought a "developer friendly" WAF and my team spent 3 days fixing false positives
Last month we rolled out a new WAF from a vendor called ShieldWall (they had a flashy demo at a conference). Within 2 hours our login endpoint was blocked because it flagged a legit POST request as an SQLi attempt. My team spent 3 days whitelisting rules and tuning thresholds before it worked right. Has anyone else had a WAF that was way too aggressive out of the box?
2 comments
Log in to join the discussion
Log In2 Comments
john_cooper1mo ago
Did you try turning on the "learning mode" first before going full blocking? We had the same headache with ours and it saved us a ton of time just letting it watch traffic for a week before it started actually stopping anything.
5
willow1141mo ago
Learning mode saved my sanity when my firewall kept blocking my own streaming services. @john_cooper that's solid advice.
2