Zum Hauptinhalt springen
Support
0
Kontaktieren Sie uns
English
Nederlands
Español
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareers
Cloud Compute

Mit Cloud Compute haben Sie jederzeit und überall Zugriff auf ein Portal, über das Sie Ihre gesamte IT-Umgebung konfigurieren können – egal wo auf der Welt Sie sich befinden.

Cloud-Speicher

Zuverlässiger Zugriff auf Ihre Dateien, Infrastruktur und Anwendungen zu jeder Zeit – ganz ohne Unterbrechungen oder Verzögerungen. Bei Worldstream bieten wir eine Vielzahl von Speicherlösungen an.

Flexible cloud icon
Flexible Cloud
Private cloud icon
Private Cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Objektspeicher
Hollow cube icon
Dateiablage
Block storage icon
Blockspeicher
Backup storage icon
Sicherungsspeicher
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Dedicated Server

Wählen Sie jetzt Ihren Dedicated Server. Individuelle oder Instant Delivery. Leistungsstarke Server, die perfekt zu Ihrem Anwendungsfall passen.

Use Cases

Ganz gleich, welcher Use Case – wir helfen Ihnen, die ideale Lösung zu finden.

Deal servers icon
Deals
AMD servers icon
AMD-Prozessoren
AI servers icon
Intel-Prozessoren
Hollow cube icon
Virtualisierung, Containerisierung & Orchestrierung
Hollow cube icon
Websites & Applications
Hollow cube icon
Gaming & Streaming Infrastruktur
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Smartes Outsourcing

Bestimmte IT-Lösungen generieren Mehrwert, andere erfüllen eher eine unterstützende Funktion. Denken Sie beim Outsourcing daran.

Kosteneffizienz

IT-Komplettpakete mögen erstmal wie eine sichere Option erscheinen, doch wenn man sich die Kosten genau anschaut, sind andere Lösungen oft sinnvoller.

IT-Flexibilität und Kontrolle

Outsourcing heißt nicht, dass man die Kontrolle verliert; man bekommt sogar mehr Flexibilität und Kontrolle.

Cloud-Repatriierung

Die Cloud ist kein Endziel: Sie sollten Ihre Cloud-Umgebung kontinuierlich prüfen und an die sich ändernden Anforderungen anpassen.

Finanzdienstleistungen
Logistik und Transport
Einzelhandel und E-commerce
Medien und Unterhaltung
Technik und Softwareentwicklung
Sicherheit
Managed Service Provider
Brauchen Sie Unterstützung?

Mit erfahrenen Technikern und einer durchschnittlichen Reaktionszeit von 7 Minuten erhalten Sie innerhalb kürzester Zeit eine solide technische Supportlösung.

Chatten Sie mit unsKontaktieren Sie uns
Über WorldstreamÜber die TechnologieKundenfälleWissensdatenbank
Über unsLernen Sie unser Team kennenJobsWerden Sie WiederverkäuferZertifizierungenUnsere RechenzentrenUnser NetzwerkDDoS-SchutzAMD EPYC-ServerTechnologiepartnerBetriebssystemeAlle KundenfälleEasyTerraDutch Drone CompanyPerfGridArtikelFAQNachrichten und BlogbeiträgeProdukte und Services
Kontaktieren Sie uns

Rufen Sie an unter +31 (0) 174 – 712 117 Industriestraat 53, Naaldwijk

English
Nederlands
Español
0
Dedicated ServersFlexible VPSCloud-TechnologieColocationHerausforderungen in der ITSektorenCareersÜber WorldstreamÜber die TechnologieKundenfälleWissensdatenbankMy Worldstream
Contact
Support
EnglishNederlandsEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. What is a Web Application Firewall (WAF), and how it differs from a network firewall

What is a Web Application Firewall (WAF), and how it differs from a network firewall

Gilt für Web applications, APIs, any HTTP/HTTPS serviceZielgruppe Technical evaluator, developerZuletzt geprüft September 2026

Kort antwoord

A network firewall filters traffic by port, IP address and protocol. It has no idea what's actually inside an HTTP request. A Web Application Firewall (WAF) sits a layer higher and inspects the content of web requests, looking for patterns that match known attack types, then blocks requests that look malicious even if they arrive over an allowed port. The two are complementary layers, not alternatives to each other.

What a network firewall checks

A network firewall makes its decisions from the outside of a request, not the inside. It looks at things like the source and destination IP address, the port being used, and the protocol in play, then decides whether that combination is allowed through. This is often called layer 3 or layer 4 filtering, referring to the network and transport layers of the networking stack. It's a coarse but essential filter: block port 3389 from the public internet, allow port 443, only permit certain source ranges to reach an admin interface, and so on.

What a network firewall does not do is open up the request and read what's inside it. If a connection is permitted on port 443, the firewall lets the traffic through and moves on. It doesn't parse the HTTP headers, the URL parameters, or the body of the request to judge whether the content itself is dangerous. That's by design: a network firewall operates at a level below where "HTTP request" or "web application" even exist as concepts.

What a WAF checks instead

A WAF operates at layer 7, the application layer, meaning it actually inspects the content of a web request rather than just the envelope it arrives in. It looks at the URL, query string, headers, cookies and request body, and compares what it finds against patterns associated with known attack types, things like SQL injection attempts, cross-site scripting (XSS) payloads, and malicious file upload attempts. If a request matches one of those patterns, the WAF can block it, log it, or challenge it, even though the underlying connection is using a completely legitimate port and protocol.

This is the core difference in one sentence: a network firewall asks "should this connection be allowed at all", a WAF asks "given that this connection is allowed, does the actual content of this request look like an attack".

Network firewallWAF
LayerNetwork / transport (layer 3-4)Application (layer 7)
Decides based onIP address, port, protocolRequest content: URL, headers, body
Sees inside an HTTP requestNoYes
Typical attacks it catchesPort scans, unauthorised protocol access, disallowed source IPsSQL injection, cross-site scripting, malicious file uploads
Blind spotMalicious content sent over an allowed portAttacks that don't rely on request content, such as raw connection floods

Why one doesn't replace the other

These sit at different layers on purpose, and neither one covers the other's blind spot. A network firewall alone will not catch a malicious SQL injection payload sent over an allowed port 443 connection, because the payload arrives inside content the firewall was never designed to read. It sees a normal, permitted HTTPS connection and passes it through. Equally, a WAF alone doesn't replace the coarse filtering a network firewall provides: blocking unwanted ports and source ranges before traffic even reaches the application is still useful groundwork.

Treat them as two layers of the same defence rather than a choice between them. A network firewall narrows down what's allowed to reach a service at all. A WAF then looks at what actually shows up in the requests that do reach it.

Related articles

  • Firewall basics in Portal
  • Understanding DDoS protection: what it actually does
  • What is SQL injection, and how to protect against it
War dieser Artikel hilfreich?

Solide IT. Keine Überraschungen

Sparringspartner für IT-Reife
Wir räumen die Hindernisse aus dem Weg, damit Sie freie Bahn haben
Vorhersehbare und transparente Kosten

Kontakt

  • Industriestraat 53, Naaldwijk
  • Zahlungsmöglichkeiten
  • Missbrauch
  • Ressourcen für Entwickler
  • Network Operations Center
  • Über uns
  • Lernen Sie unser Team kennen
  • Jobs
  • Werden Sie Wiederverkäufer
  • Zertifizierungen
  • Unsere Rechenzentren
  • Unser Netzwerk
  • DDoS-Schutz
  • AMD EPYC-Server
  • Technologiepartner
  • Betriebssysteme
  • Übersicht
  • FAQ
  • Kundenfälle
  • Nachrichten und Blogbeiträge
  • Use Cases
English
Nederlands
Español
English
Nederlands
Español
  • Rechtliches
  • Transparenzhinweis