What is a Web Application Firewall (WAF), and how it differs from a network firewall
Quick answer
A network firewall filters traffic by port, IP address and protocol. It has no idea what's actually inside an HTTP request. A Web Application Firewall (WAF) sits a layer higher and inspects the content of web requests, looking for patterns that match known attack types, then blocks requests that look malicious even if they arrive over an allowed port. The two are complementary layers, not alternatives to each other.
What a network firewall checks
A network firewall makes its decisions from the outside of a request, not the inside. It looks at things like the source and destination IP address, the port being used, and the protocol in play, then decides whether that combination is allowed through. This is often called layer 3 or layer 4 filtering, referring to the network and transport layers of the networking stack. It's a coarse but essential filter: block port 3389 from the public internet, allow port 443, only permit certain source ranges to reach an admin interface, and so on.
What a network firewall does not do is open up the request and read what's inside it. If a connection is permitted on port 443, the firewall lets the traffic through and moves on. It doesn't parse the HTTP headers, the URL parameters, or the body of the request to judge whether the content itself is dangerous. That's by design: a network firewall operates at a level below where "HTTP request" or "web application" even exist as concepts.
What a WAF checks instead
A WAF operates at layer 7, the application layer, meaning it actually inspects the content of a web request rather than just the envelope it arrives in. It looks at the URL, query string, headers, cookies and request body, and compares what it finds against patterns associated with known attack types, things like SQL injection attempts, cross-site scripting (XSS) payloads, and malicious file upload attempts. If a request matches one of those patterns, the WAF can block it, log it, or challenge it, even though the underlying connection is using a completely legitimate port and protocol.
This is the core difference in one sentence: a network firewall asks "should this connection be allowed at all", a WAF asks "given that this connection is allowed, does the actual content of this request look like an attack".
| Network firewall | WAF | |
|---|---|---|
| Layer | Network / transport (layer 3-4) | Application (layer 7) |
| Decides based on | IP address, port, protocol | Request content: URL, headers, body |
| Sees inside an HTTP request | No | Yes |
| Typical attacks it catches | Port scans, unauthorised protocol access, disallowed source IPs | SQL injection, cross-site scripting, malicious file uploads |
| Blind spot | Malicious content sent over an allowed port | Attacks that don't rely on request content, such as raw connection floods |
Why one doesn't replace the other
These sit at different layers on purpose, and neither one covers the other's blind spot. A network firewall alone will not catch a malicious SQL injection payload sent over an allowed port 443 connection, because the payload arrives inside content the firewall was never designed to read. It sees a normal, permitted HTTPS connection and passes it through. Equally, a WAF alone doesn't replace the coarse filtering a network firewall provides: blocking unwanted ports and source ranges before traffic even reaches the application is still useful groundwork.
Treat them as two layers of the same defence rather than a choice between them. A network firewall narrows down what's allowed to reach a service at all. A WAF then looks at what actually shows up in the requests that do reach it.