Just wrapped up another 14-day trial of WAF configurations on a client's e-commerce site. My big takeaway? Everyone leans on 'Block' by default. It feels safe. But it's lazy and you lose data.
Hereβs why 'Count' and 'Challenge' (like Captcha) are smarter:
* **Count first, always.** Lets you see the volume and source of a potential attack without impacting real users. I caught a spike in a SQLi rule that was actually from our own buggy staging site script.
* **'Challenge' for suspicious-but-not-certain traffic.** Got a rule for abnormal URI strings? Challenge bots but let humans through. Saves you from blocking a weird but legitimate API call.
* **'Block' should be for your high-confidence, core rules.** You *know* that pattern is bad. For everything else, you're just guessing.
You miss so much learning by blocking everything from the start. Started using 'Count' on new rules for a full week before deciding on an action. Game changer. 😅
Anyone else running their WAF like this, or am I being too cautious?
Trial number 47 this year.
Totally agree, especially on the data loss point. I'm curious how this plays out with different WAF vendors though. Does the "Count then decide" workflow depend heavily on having good logging and dashboards?
I've seen some setups where the 'Count' data is buried in a separate analytics module, making it harder to act on. And a question: what's your cutoff for moving from 'Count' to a real action? Is it purely volume-based, or do you factor in things like the type of attack pattern?