> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/zero-touch-waf/introduction.md).

# Introduction

Link11’s Zero Touch WAF (Web Application Firewall) is an extension of the Web DDoS Protection solution. It protects customers against a wide variety of common application attacks (e.g. SQL injection, XSS, and CSRF).

Highlights include:

* The WAF can be [activated](/product-guides/web-ddos/interface/instances/zero-touch-waf.md#zero-touch-waf-blocking) for individual Web DDoS instances in WebGUI.&#x20;
* It enforces [the Link11 WAF Ruleset](/reference/zero-touch-waf-rules.md).&#x20;
* [Custom rules](/product-guides/web-ddos/interface/instances/zero-touch-waf.md#customized-waf-rulesets) can also be created and enforced.
* Individual Rules can be [enabled or disabled in WebGUI](/product-guides/web-ddos/interface/instances/zero-touch-waf.md#zero-touch-waf-rule-set).
* Within instances, Rules can be configured for [enforcement on specific paths](/product-guides/web-ddos/interface/waf-rules.md#id-webddos-wafrules-pathspecificrules).
