Dev.to Security ๐Ÿ” Cybersecurity ๐Ÿ‘ 0 ๐Ÿ“– 1 min read

How to set up a self-hosted WAF for Webapps in 2 minutes ?

Securing a web application usually means either routing private traffic through a third-party cloud CDN or wrestling with complex Nginx configurations. Here is how to set up Aegisโ€”an open-source, self-hosted Web Applica

Securing a web application usually means either routing private traffic through a third-party cloud CDN or wrestling with complex Nginx configurations.

Here is how to set up Aegisโ€”an open-source, self-hosted Web Application Firewall (WAF) and reverse proxyโ€”in under two minutes.

1. Install & Deploy Aegis

Choose either the quick installation script or Docker:

Option A: Install via Script (Linux)

Clone the repository and run the automated installer:

git clone https://github.com/divinelabio/aegis.git
cd aegis
sudo bash install.sh

Verify the systemd service is active:

sudo systemctl status aegis

Option B: Deploy via Docker

Run the self-contained container with persistent data storage:

docker run -d --name aegis_server \
  --restart unless-stopped \
  -p 8080:8080 -p 8081:8081 \
  -v aegis_data:/var/lib/aegis/data \
  -e AEGIS_ADMIN_PASSWORD="ChooseStrongAdminPassword123!" \
  ghcr.io/divinelabio/aegis:latest
  • Port 8080: Public Ingress Proxy (sits in front of your applications).
  • Port 8081: Web Dashboard for traffic monitoring and policy tuning.

2. Test WAF Attack Blocking

Aegis inspects incoming requests and blocks common web exploits (SQL Injection, XSS, Remote Code Execution) out of the box.

Test it by sending a simulated SQL Injection payload to the proxy:

curl -i "http://localhost:8080/?id=1%27%20OR%201=1--"

Aegis intercepts the attack and returns HTTP 403 Forbidden:

HTTP/1.1 403 Forbidden
X-WAF-Rule-ID: 942100

Access denied: This request was rejected by the application security layer.

The attack is dropped at the edge and never reaches your backend servers.

3. Manage Routes in the Web Dashboard

Open http://localhost:8081 in your browser.

From the dashboard, you can:

  • Route incoming traffic to your backend origin servers.
  • View blocked attacks and threat telemetry in real time.
  • Adjust Layer 7 rate limits, toggle Geo-IP blocking, and manage SSL certificates.

All policy updates reload dynamically in memory with zero downtimeโ€”no proxy restarts required.

Resources

The Community Edition is free to self-host on your own servers and homelabs:

๐Ÿ“ฐ Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes โ€” full credit and traffic to the original publisher.