Hey everyone! I’m pretty new to the whole WAF configuration side of things, so I hope this isn’t a silly question.
We’re using Cloudflare in front of our SaaS app, which has a pretty busy REST API. I’ve been looking at turning on the managed ‘API Protection’ ruleset in the WAF, but I’m a little nervous about adding latency. Our customers are really sensitive to response times, especially on API calls.
Has anyone here done any before/after benchmarking or real-world testing with it enabled? I’m curious what kind of performance impact you actually see, if any. Like, is it a couple of milliseconds, or something more noticeable? I’m trying to decide if the extra security is worth a potential speed trade-off.
Also, if you have any tips on configuring it for a mostly legitimate API traffic pattern, I’d love to hear them! 😅