> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/zero-touch-waf/setup.md).

# Setup

## Prerequisites

1. Zero Touch WAF is an extension of Link11’s Web DDoS Protection service; thus, this service is required in order to use the WAF.
2. Web DDoS cannot be in [TLS Passthrough mode](/product-guides/web-ddos/interface/instances/tls-settings.md#tls-passthrough).

Once Zero Touch WAF has been purchased, it will be available for activation in WebGUI.

<figure><img src="/files/m9Rw744pLBLayKSkADXi" alt=""><figcaption></figcaption></figure>

To set it up, please follow [these instructions](/product-guides/web-ddos/interface/instances/zero-touch-waf.md).&#x20;

## After initial setup is completed

Initially, Zero Touch WAF uses a learning mode where rules get triggered, but no direct blocking of requests will occur. Admins can then review the WAF rulesets via the [WAF Logs](/product-guides/web-ddos/interface/waf-logs.md) function in the WebGUI, see where False Positive alarms are occurring, and can disable the responsible rules per Web DDoS instance.

This evaluation phase should last at least 24 hours. (If there is a low volume of typical traffic during this time, a longer time period should be considered.)&#x20;

At the end of the phase, customers can [enable the WAF blocking mode](/product-guides/web-ddos/interface/instances/zero-touch-waf.md#zero-touch-waf-blocking).
