> For the complete documentation index, see [llms.txt](https://karansingh.gitbook.io/aws-saa-c02/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://karansingh.gitbook.io/aws-saa-c02/security-and-encryption/web-application-firewall-waf-overview.md).

# Web Application Firewall (WAF) Overview

* WAF is a **web application firewall** that helps **protect your web applications or APIs against common web exploits** that may affect availability, compromise security, or consume excessive resources.<br>

* WAF gives you control over how traffic reaches your applications by enabling you to create security rules that block common attack patterns, such as **SQL injection or cross-site scripting**, and rules that filter out specific traffic patterns you define.<br>

* You can get started quickly using **Managed Rules for WAF, a pre-configured set of rules managed by AWS or AWS Marketplace Sellers**.
  * The Managed Rules for WAF address issues like the OWASP Top 10 security risks.

* You can **deploy WAF on CloudFront as part of your CDN solution, an Application Load Balancer or an API Gateway**.

## Firewall Manager <a href="#fms-chapter" id="fms-chapter"></a>

* Firewall Manager **simplifies your administration and maintenance tasks across multiple accounts and resources** for **WAF, Shield Advanced, VPC security groups, and Network Firewall**.<br>
* With Firewall Manager, you **set up your AWS WAF firewall rules, Shield Advanced protections, Amazon VPC security groups, and Network Firewall firewalls just once**.
