Multiple WAF uses

Wanting to setup a WAF, and have this in front of a production website and a QA website (2 servers).

  1. Can this be done?
  2. If I make change to the WAF (for testing against QA site) will this effect the Prod ?
  3. If it does effect it, any ways we could look to segregate the two? eg Ability to test changes against the QA and not effect the prod access/rules etc.

Thanks

Is the testing site on a different hostname / sub-domain like test.domain.com? :thinking:
If yes, then make sure to include (http.host contains "test.domain.com") with an “AND” operator within your rule expression so the rule would have effect only on test domain, or rather only on the production - depending if you’re using it in a negative way or not with your desired action for.

2 Likes

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.