How it differs from a network firewall
A network firewall decides which connections are allowed based on addresses and ports. A WAF inspects the content of web requests and understands how web applications are attacked. Both are needed: one does not replace the other.
What it protects against
WAFs are designed around common web attacks, many of them listed in the OWASP Top 10: injection, cross site scripting, access to forbidden paths, credential stuffing and malicious bots. Many WAF services also absorb application layer DDoS attacks.
Virtual patching
When a vulnerability is found in an application and the fix will take time, a WAF rule can block attempts to exploit it in the meantime. This buys time, but it does not replace fixing the code.
Limits
A WAF needs tuning: too strict and it blocks real customers, too permissive and it lets attacks through. It does not fix insecure code or logic flaws, which is why it works best alongside secure development, SAST and DAST testing and regular pentesting.




