Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. What is a Web Application Firewall (WAF), and how it differs from a network firewall

What is a Web Application Firewall (WAF), and how it differs from a network firewall

Applies to Web applications, APIs, any HTTP/HTTPS serviceAudience Technical evaluator, developerLast reviewed September 2026

Quick answer

A network firewall filters traffic by port, IP address and protocol. It has no idea what's actually inside an HTTP request. A Web Application Firewall (WAF) sits a layer higher and inspects the content of web requests, looking for patterns that match known attack types, then blocks requests that look malicious even if they arrive over an allowed port. The two are complementary layers, not alternatives to each other.

What a network firewall checks

A network firewall makes its decisions from the outside of a request, not the inside. It looks at things like the source and destination IP address, the port being used, and the protocol in play, then decides whether that combination is allowed through. This is often called layer 3 or layer 4 filtering, referring to the network and transport layers of the networking stack. It's a coarse but essential filter: block port 3389 from the public internet, allow port 443, only permit certain source ranges to reach an admin interface, and so on.

What a network firewall does not do is open up the request and read what's inside it. If a connection is permitted on port 443, the firewall lets the traffic through and moves on. It doesn't parse the HTTP headers, the URL parameters, or the body of the request to judge whether the content itself is dangerous. That's by design: a network firewall operates at a level below where "HTTP request" or "web application" even exist as concepts.

What a WAF checks instead

A WAF operates at layer 7, the application layer, meaning it actually inspects the content of a web request rather than just the envelope it arrives in. It looks at the URL, query string, headers, cookies and request body, and compares what it finds against patterns associated with known attack types, things like SQL injection attempts, cross-site scripting (XSS) payloads, and malicious file upload attempts. If a request matches one of those patterns, the WAF can block it, log it, or challenge it, even though the underlying connection is using a completely legitimate port and protocol.

This is the core difference in one sentence: a network firewall asks "should this connection be allowed at all", a WAF asks "given that this connection is allowed, does the actual content of this request look like an attack".

Network firewallWAF
LayerNetwork / transport (layer 3-4)Application (layer 7)
Decides based onIP address, port, protocolRequest content: URL, headers, body
Sees inside an HTTP requestNoYes
Typical attacks it catchesPort scans, unauthorised protocol access, disallowed source IPsSQL injection, cross-site scripting, malicious file uploads
Blind spotMalicious content sent over an allowed portAttacks that don't rely on request content, such as raw connection floods

Why one doesn't replace the other

These sit at different layers on purpose, and neither one covers the other's blind spot. A network firewall alone will not catch a malicious SQL injection payload sent over an allowed port 443 connection, because the payload arrives inside content the firewall was never designed to read. It sees a normal, permitted HTTPS connection and passes it through. Equally, a WAF alone doesn't replace the coarse filtering a network firewall provides: blocking unwanted ports and source ranges before traffic even reaches the application is still useful groundwork.

Treat them as two layers of the same defence rather than a choice between them. A network firewall narrows down what's allowed to reach a service at all. A WAF then looks at what actually shows up in the requests that do reach it.

Related articles

  • Firewall basics in Portal
  • Understanding DDoS protection: what it actually does
  • What is SQL injection, and how to protect against it
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure