> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/web-ddos/interface/instances/zero-touch-waf.md).

# Zero Touch WAF

To use the Link11 Zero Touch WAF (Web Application Firewall), the service has to be bought, and then the Link11 team must activate it.&#x20;

If this is not the case, the following window will appear:

<figure><img src="/files/b1ueBA4OqqSmVdVMm2Hr" alt=""><figcaption></figcaption></figure>

Once the team has activated the service, the WAF settings will appear in WebGUI.

{% hint style="danger" %}
The Zero Touch WAF does not work with [TLS Passthrough](/product-guides/web-ddos/interface/instances/tls-settings.md#tls-passthrough) enabled.
{% endhint %}

## **Zero Touch WAF**

Enabling this option will activate the WAF observation mode. The WAF should stay in this mode for at least 24 hours. Review the [WAF logs](/product-guides/web-ddos/interface/waf-logs.md) to see if any legitimate clients would have been filtered (i.e., if any False Positives would have occurred).

<figure><img src="/files/KgId2qgCzkDIqugjYTfu" alt=""><figcaption><p>WAF is disabled</p></figcaption></figure>

***

## **Zero Touch WAF blocking**

Selecting this will enable the WAF to begin normal operation. Be sure that any False Positives were corrected before activating; otherwise there might be connectivity issues for some users.

<figure><img src="/files/NxxAkeCuNFLJO8XqjsSn" alt=""><figcaption><p>WAF is enabled</p></figcaption></figure>

***

## **Zero Touch WAF Rule Set**

Here the Rules that will be applied to the Firewall are displayed. These Rules are implementations of the [Mod Security Core Rule Set](https://owasp.org/www-project-modsecurity-core-rule-set/).

Here, admins can enable or disable categories of Rules. To enable/disable individual Rules, go to the [WAF Rules](/product-guides/web-ddos/interface/waf-rules.md) page.

{% hint style="info" %}
Because the Rules are implementations of standard Mod Security rules, they are not intended to be editable by admins. If you need custom rules for the WAF, contact Support.
{% endhint %}

<figure><img src="/files/m1R25SQb9yBPiElgjBbN" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/MLKKcnCLz5uvaiUbMdQP" alt=""><figcaption><p>Header with version selection</p></figcaption></figure>

We recommend using the newest version of the rule set.

## **Rules**

The WAF rules are described in detail here: [Zero Touch WAF Rules](/reference/zero-touch-waf-rules.md).

***

## **Customized WAF Rulesets**

Customers that have requested and been approved to use tailored WAF rules that are unique to their instances will see the “Customized WAF Rulesets” option enabled. Customer WAF Rules are built and maintained by our team on your behalf to facilitate a blocking or whitelisting action that is not possible with the default rulesets offered by Link11.

To request Custom WAF Rules for an instance please contact your Sales Representative to start the process.

<figure><img src="/files/L7EZaD8pQLUSYBs1bWkb" alt=""><figcaption></figcaption></figure>

## **Save Settings**

<figure><img src="/files/sWGmQn64qvG354GyDIXX" alt=""><figcaption></figcaption></figure>

After applying all needed Rules clicking on the Button will save the changes
