Knowledge Hub · Security

Will turning on Cloudflare's WAF through FirstNet break our applications?

Web Application & DDoS Protection · Answered by FirstNet Technology Services

Short answer

Not if it is staged properly. FirstNet stages the Cloudflare WAF in detection mode first and tunes it against your real traffic before enforcement. It documents a rollback path with your application team, and cutover stays reversible until enforcement.

In detail

How FirstNet onboards the WAF:

  • Discovery and a phased design aligned with Cloudflare's technical account team
  • Domains onboarded and DNS applied, with baseline managed rulesets in detection mode
  • False positives reviewed against real traffic and rules tuned
  • Rules tightened and enforcement switched on once the baseline is clean
  • Ongoing false-positive triage and attack-event reviews after go-live

Change windows and acceptance criteria are agreed with you before cutover, and the result is validated against them with your technical contact.

The WAF covers managed rulesets, custom rules, OWASP Top 10 coverage, virtual patching and exposed-credential checks. Because Cloudflare depends on DNS or BGP pointing at its edge, FirstNet also documents fallback procedures aligned with your existing DNS playbook.

Tell FirstNet about fragile or legacy applications during discovery so they get extra testing before enforcement.

Source: FirstNet Web Application & DDoS Protection service page →

Didn’t answer your question?

Call