For setting up your WAF, it is necessary that your website is connected to the internet. Naturally, we will use the https protocol instead of HTTP. Https is a secured version of HTTP: Communication between the end-user and the website is encrypted. It helps prevent intruders from tampering with the communication between the end-users browsers and the website. Every site that is not protected with https can reveal information about the identity and behavior of end-users.
We configure a website preferably with a Domain Validated SSL-certificate. We also need support from your DNS administrator to CNAME your website to the Akamai platform. Let us prepare the basic configuration in the Akamai platform with the certified professionals at our hosting team. Once this is done, we are ready to go.
It is at the edges of the Akamai platform where the logic takes place: when we have configured the firewall, traffic is re-routed via the DNS change and we will let the web application firewall learn for the first weeks to come. We call this alert-mode: The firewall is not active, but it will report on what it sees.
On a daily basis we will check configurations, and only if we are sure that we can enable the firewall without impacting the customers’ business, we will activate the firewall: we call this deny-mode. Once activated we have good reporting available on our dashboard, with a possibility to send out logs and reports.