Cloud Defender or a traditional WAF

A Web Application Firewall (WAF) can be installed in house, as an appliance or software, or used as a managed service. What changes for your sites and APIs.

In short

There is no right choice for everyone: it depends on where the applications are and who can look after them every day.

Cloud Defender

Makes sense when:

  • You protect sites and APIs exposed to the internet and nobody in the company has time to run a WAF.
  • You want DDoS protection and malicious IP blocking without installing hardware.
  • You want to see blocked attacks in Cyber Console, next to the other services.

In-house WAF

Makes sense when:

  • You need to protect internal applications that are not reachable from the internet.
  • Contractual or regulatory constraints prevent traffic from passing through an external service.
  • You need very specific rules and have a team that writes and maintains them.

Point by point

Comparison checked on 1 October 2026.
Activation Cloud DefenderA DNS record pointing to secure.aegister.com, with no code changes In-house WAFInstallation, configuration and placement in the network
Maintenance Cloud DefenderUpdates and rules are on us In-house WAFUpdates, patches and capacity are on you
Rules against SQL injection and XSS Cloud DefenderTuned by us to your traffic In-house WAFConfigured and maintained in house
Malicious IP addresses Cloud DefenderBlocked with our threat intelligence, list updated automatically In-house WAFIf the product has a feed and the licence includes it
Volumetric DDoS attacks Cloud DefenderHandled at the edge, before your line In-house WAFA device in house cannot stop an attack that saturates the connection
Direct access to the server Cloud DefenderThe server accepts only traffic that comes through Cloud Defender In-house WAFDepends on how the network is configured
TLS certificates Cloud DefenderHandled at the edge In-house WAFHandled by you
Internal applications Cloud DefenderNot covered: Cloud Defender protects what is exposed to the internet In-house WAFCovered, if the WAF sits in the internal network
Visibility Cloud DefenderIn Cyber Console: threats blocked, attacking IPs, origins and the layer that blocked In-house WAFIn the WAF's console

Getting started with Cloud Defender

  1. 1

    Domains

    Tell us which sites and APIs to protect.

  2. 2

    DNS

    The DNS record points to secure.aegister.com: requests pass through our edge.

  3. 3

    Server

    Your server accepts only traffic that comes from Cloud Defender.

  4. 4

    Tuning

    In the first weeks we tune the rules to your real traffic.

Frequently asked questions

No. A DNS record is enough: the applications stay as they are.

A few minutes for the DNS record. In the first weeks we tune the rules to your traffic.

Yes: to inspect HTTPS requests, Cloud Defender handles TLS at the edge and forwards only allowed traffic to your server.

No: it protects sites and APIs reachable from the internet. Internal applications need protection inside your network.

Not sure yet which fits you?

The Cyber Check-up returns your company's cyber profile and the priorities to start from.