What is WAF Free?
WAF Free from VNETWORK is a free web application firewall solution within the Web/App/API Protection (WAAP) platform - VNIS. Built on AI, WAF Free was created to help businesses, especially small and medium enterprises (SMEs), easily reach international security standards against a growing wave of cyberattacks, without incurring hidden costs.
At its core, WAF (Web Application Firewall) is a defense layer at the application level that detects and blocks malicious requests exploiting common vulnerabilities such as SQL Injection, XSS, and automated scanning, before they reach the origin server.
WAF Free’s key advantage is that it runs directly on VNETWORK’s Edge Network, letting businesses deploy it instantly without investing in hardware, leasing dedicated services, or switching DNS providers. As a result, a website with no existing protection layer can activate a standard security shield within just a few minutes of setup.
![]()
How does WAF Free help businesses?
WAF Free helps businesses reduce the risk of cyberattacks, meet legal compliance requirements, and access enterprise-grade security capabilities at no cost.
Small businesses are easy targets due to limited staff and security budgets. According to a 2025 cybersecurity survey by the National Cyber Security Association, 52.3% of agencies and businesses have suffered damage from cyberattacks; according to the Ministry of Public Security, losses reached nearly VND 40 trillion between 2020 and 2025.
Beyond the risk of attack, pressure on SMEs is also rising as deploying a security solution has become a legal obligation. Decree 85/2016/NĐ-CP and Circular 12/2022/TT-BTTTT require information systems at level 2 or higher to deploy a web application firewall (WAF), while the Law on Personal Data Protection No. 91/2025/QH15 requires every organization that processes user data to apply technical measures against unauthorized leaks. Yet 56% of organizations lack dedicated information security staff, and only 11% have the capacity to defend themselves, leaving most SMEs facing both the risk of penalties and business disruption.
WAF Free was created to fill exactly this gap, delivering key benefits to businesses:
- Reduce risk, protect revenue and reputation: block common attacks early, before they disrupt service or leak customer data.
- Meet compliance requirements: help businesses fulfill the legal obligations mentioned above.
- Enterprise-grade security, free of charge: benefit from the same protection layer VNETWORK uses to safeguard more than 400,000 websites, apps, and APIs worldwide.
- Save on cost and headcount: no need to hire a dedicated IT team or invest in separate hardware.
Core features of WAF Free
WAF Free helps protect your digital business channels with the following features:
- Protection against OWASP Top 10 vulnerabilities such as SQL Injection, XSS, and RFI
- Blocking basic DDoS attacks targeting your website
- Rate Limiting to restrict abnormal access frequency
- Faster Web/App content delivery through CDN infrastructure
- Real-time traffic monitoring dashboard
The table below quickly compares WAF Free with the Custom plan, so businesses can choose what fits their needs:
| Criteria | WAF Free Plan | Custom Plan (WAAP) |
|---|---|---|
| Cost | Free | Contact us, based on needs |
| OWASP Top 10 Protection | Yes | Yes |
| DDoS Blocking | Basic | Multi-layer (Layer 3/4/7), continuous |
| Rate Limiting | Yes | Yes |
| CDN Acceleration | Yes | Multi-CDN and AI Load Balancing |
| Real-time AI-WAF Analysis | No | Yes |
| Bot Management | No | Yes |
| API Protection | No | Yes |
| 24/7 SOC and SLA | No | Yes |
| Domain, Traffic, RPS | Limited by plan | Customized to needs |
For basic needs, WAF Free is enough to give a website a standard protection layer from day one, at no extra cost.
Activate WAF Free in 3 steps
Activating WAF Free takes just three simple steps and less than 2 minutes, with no need to change your current system architecture.
Before starting, go to VNETWORK’s Partner Portal and create an account (choose Business Account if registering for a company, or Individual Account if registering as an individual). Clicking the link directly takes you straight to the onboarding page to activate WAF Free right away.
If logging in normally with an existing VNETWORK-ID account, take these additional steps: go to Services → Security → Web Application & API Protection → Activate. The system provisions WAAP for the current project, and the service card opens the WAAP console so you can bring your first website under protection through the three steps below.
Step 1. Add Your Website and Declare the Origin
- Open Onboarding or select Add Website from the Websites page to start the wizard.
- At the Domain & Origin step, enter the Website Domain: the public hostname users visit, e.g. example.com, without http or https.
- Enter the Origin Server: the https scheme along with the IP or origin domain where WAAP forwards clean traffic (IPv6 is not yet supported).

Step 2. Configure SSL
- At the SSL step, choose how to issue a TLS certificate for the website (you can change or add a certificate later in the website’s SSL tab).
- Free managed SSL (recommended): VNETWORK issues and automatically renews the certificate, usable across multiple services. Click Issue free certificate, add a DNS record to verify ownership, and the certificate then renews automatically.
- Auto-generated vendor certificate: the edge automatically issues a Let’s Encrypt certificate once you point a CNAME record.
- Click Continue to move to the next step, or Skip & verify later to configure SSL afterward.

Step 3. Choose Security Features
- At the Security Features step, turn on AI-WAF Protection to activate the AI-WAF protection layer for your website.
- Choose a protection level from the list: Basic (recommended), Standard, Strict, Basic Plus, Standard Plus, Monitoring, or Balanced.
- Click Complete Setup to finish the onboarding wizard.

After completing the wizard, point your domain’s DNS record to the CNAME (the target shown in the console) so that all traffic passes through WAAP. As soon as the DNS change takes effect, the website begins to be automatically filtered and protected.
7 standout features of VNIS
Beyond the baseline protection in WAF Free, VNIS offers many advanced features ready for any attack scenario. Here are the standout features:
1. AI-WAF
AI-WAF detects and blocks Web/App threats in real time right at the CDN edge node, analyzing the context and behavior of every request against more than 2,400 rules. AI-WAF defends against vulnerability exploitation, brute force attacks, and Layer 7 attacks, while minimizing false positives so real users are not affected.
2. Bot Management
Bot Management identifies real users and blocks malicious bots in real time, preventing data scraping and automated abuse. Bot Management helps eliminate traffic from botnets before they overload or steal content from your website.
3. DDoS Protection
DDoS Protection absorbs and mitigates multi-layer denial-of-service attacks (Layer 3/4/7), keeping your website running continuously even under large-scale attacks. DDoS Protection combines global network capacity to disperse and remove abnormal traffic.
4. Emergency Mitigation
Emergency Mitigation allows instant activation of an emergency blocking mode when an attack is detected. With Emergency Mitigation, operations teams can rate-limit access or block traffic by country, IP range, or network provider in just a few actions.
5. TLS and HTTP/3
TLS and HTTP/3 encrypt connections and speed up transmission, reducing latency for end users. Support for the modern HTTP/3 protocol helps websites load faster and more reliably, while keeping data safe in transit.
6. Rate Limiting
Rate Limiting caps the number of requests from a single source within a given time window, preventing abuse and automated scanning attempts. Rate Limiting is an effective defense against brute force and abnormal access behavior, while preserving a smooth experience for legitimate users.
7. API Protection
API Protection detects and protects every API endpoint from unauthorized access. API Protection monitors API traffic, detects hidden endpoints, and prevents exploitation, helping ensure API security for modern applications. It also helps prevent data loss (Data Loss Prevention – DLP) by inspecting the content exchanged through each endpoint, detecting sensitive data fields such as personally identifiable information or payment card numbers exposed in responses. This capability reduces the risk of customer data leaks through APIs and makes it easier for businesses to meet current data protection compliance requirements.
Start protecting your website for free now!
WAF Free delivers a simple, convenient experience: just 3 steps, set up in 2 minutes, no IT team required, no extra cost, no change to your IT architecture. Businesses can also easily customize it through feature requests, with access to a ticket support system, detailed documentation, and in-depth reporting. Experience WAF Free on the same platform trusted by many large enterprises, and upgrade to the Custom plan anytime your system needs a deeper layer of protection.
FAQ – Frequently asked questions about WAF Free
1. What is WAF Free?
WAF Free is VNETWORK’s free web application firewall solution, part of the VNIS Web/App/API security ecosystem. Built on AI, WAF Free helps businesses, especially small and medium ones, easily reach international security standards to protect their websites and applications without incurring hidden costs.
2. How does WAF Free help my website?
WAF Free defends against OWASP Top 10 attacks such as SQL Injection, XSS, and RFI, blocks basic DDoS attacks, provides Rate Limiting, accelerates delivery through CDN, and offers a real-time monitoring dashboard. WAF Free also helps businesses meet information security compliance requirements.
3. How long does it take to activate WAF Free, and does it require infrastructure changes?
Three steps: add your website and declare the Origin, configure SSL, and enable Security Features; then point DNS to the edge so the website goes live. The whole process takes less than 2 minutes, requires no change to your IT architecture, and does not require switching DNS providers.
4. What’s the difference between WAF Free and the Custom plan?
WAF Free is free and provides OWASP Top 10 protection, basic DDoS blocking, Rate Limiting, CDN acceleration, and a real-time dashboard. The Custom plan adds real-time AI-WAF analysis, Bot Management, API Protection, Multi-CDN, 24/7 SOC, and an SLA commitment for more advanced protection needs.
5. Do I need a highly skilled IT team to run WAF Free?
No. WAF Free is a self-serve service: businesses register and activate it themselves through an intuitive wizard interface. This means even teams without dedicated information security staff can operate it on their own.
6. If I run into an issue while using it, where can I get support?
Businesses can submit a support request through VNETWORK’s ticket support system directly on the platform, along with detailed documentation for self-service lookup before technical support intervention is needed. For urgent issues, the VNETWORK team receives and responds directly through the ticket system to ensure the website’s protection is not interrupted.