Using wāfiاستخدام وافي

A firewall for your web application, running on your own infrastructure. Requests reach it before they reach you; the ones carrying a known attack never arrive.جدار ناري لتطبيق الويب لديك، يعمل على بنيتك التحتية أنت. تصل إليه الطلبات قبل أن تصل إليك، وما يحمل منها هجوماً معروفاً لا يصل أبداً.

It replaces the part of a large appliance that almost everybody actually uses: terminating TLS, refusing attacks, and sending what is left to the right place. The rest of the appliance is not here, on purpose.يحلّ محلّ الجزء الذي يستخدمه الجميع تقريباً من جهاز ضخم: إنهاء TLS، ورفض الهجمات، وتمرير ما تبقّى إلى وجهته. أمّا بقية الجهاز فليست هنا، عن قصد.

In development — not open for sign-up yet. This page describes how it behaves.قيد التطوير — لم يُفتح للتسجيل بعد. تصف هذه الصفحة كيف يتصرّف.

Overviewنظرة عامة

What it doesما الذي يفعله

Three things, and deliberately not a fourth. It terminates TLS, it inspects every request for known attacks, and it forwards what passes to your application.ثلاثة أمور، ورابعٌ متروك عن عمد. ينهي TLS، ويفحص كل طلب بحثاً عن الهجمات المعروفة، ويمرّر ما يجتاز الفحص إلى تطبيقك.

Nothing about your application changes. It does not need a library, an agent, a code change or a redeploy — the firewall stands in front of what you already run.لا يتغيّر شيء في تطبيقك. لا يحتاج إلى مكتبة ولا وكيل ولا تعديل في الشيفرة ولا إعادة نشر — فالجدار يقف أمام ما تشغّله أصلاً.

It runs where you run. Requests, their bodies, and everything the firewall records about them stay on your infrastructure — see Where it runs.يعمل حيث تعمل أنت. فالطلبات وأجسامها وكل ما يسجّله الجدار عنها تبقى على بنيتك التحتية — انظر أين يعمل.
How it runsطريقة التشغيل

In front of your applicationأمام تطبيقك

A visitor reaches nginx, nginx asks wāfi, and only then does the request reach your application. You do not write that configuration by hand — the firewall prints it, so it cannot drift from the version you are running.يصل الزائر إلى nginx، ويسأل nginx وافي، وعندها فقط يصل الطلب إلى تطبيقك. ولستَ من يكتب هذه الإعدادات يدوياً — بل يطبعها الجدار نفسه، فلا يمكن أن تتباعد عن النسخة التي تشغّلها.

  1. visitor → nginxالزائر ← nginx
    TLS ends here. The connection is accepted and the request is matched to one of your applications.ينتهي TLS هنا. يُقبل الاتصال ويُطابَق الطلب بأحد تطبيقاتك.
  2. nginx → wāfinginx ← وافي
    The request is assessed — its path, its headers and its body — and the answer is allow or refuse.يُقيَّم الطلب — مساره وترويساته وجسمه — ويكون الجواب سماحاً أو رفضاً.
  3. wāfi → your applicationوافي ← تطبيقك
    What passes is forwarded, unchanged. A refusal never reaches you at all, so nothing in your application has to handle it.ما يجتاز يُمرَّر كما هو. أمّا المرفوض فلا يصل إليك أصلاً، فلا شيء في تطبيقك مضطرٌّ للتعامل معه.
It fails closed. If the firewall cannot decide, the request does not pass. That is the honest behaviour for a firewall and it is a real trade: a firewall that routes around itself when it stops is not protecting anything, so the thing you install to prevent an outage can cause one.يفشل مغلقاً. إن تعذّر على الجدار أن يقرّر، فلا يمرّ الطلب. هذا هو السلوك الصادق لجدار ناري، وهو مقايضة حقيقية: فالجدار الذي يُلتفّ حوله عند توقّفه لا يحمي شيئاً، ومن ثمّ فإن ما تثبّته لمنع انقطاع قد يتسبّب في انقطاع.

A refused request gets a plain page that names no rule and carries a reference number. Telling an attacker which pattern stopped them turns a block into a tuning aid; the reference is what your support desk searches for when the person who was refused is a customer.يتلقّى الطلب المرفوض صفحة بسيطة لا تذكر أي قاعدة وتحمل رقم إشارة. فإخبار المهاجم بالنمط الذي أوقفه يحوّل الحجب إلى أداة ضبط له؛ أمّا رقم الإشارة فهو ما يبحث عنه مكتب الدعم لديك حين يكون المرفوض عميلاً.

The rulesالقواعد

Patterns, and named vulnerabilitiesأنماط وثغرات مسمّاة

Two kinds of rule, doing two different jobs. The first describes the shape of an attack — an injection, a traversal, a script in a form field — and does not care what software you run. The second addresses one named vulnerability in one product, so that an application you have not yet patched stops being reachable.نوعان من القواعد، لكلٍّ منهما عمل مختلف. الأول يصف شكل الهجوم — حقنٌ أو اجتياز مسار أو سكربت في حقل نموذج — ولا يعنيه ما البرمجيات التي تشغّلها. والثاني يعالج ثغرة مسمّاة بعينها في منتج بعينه، حتى يتوقّف تطبيق لم تُرقّعه بعدُ عن كونه قابلاً للاستغلال.

No single pattern blocks on its own. Matches add up, and one threshold at the end decides — so a request that looks slightly unusual in three ways is treated differently from one that is unmistakable in one.لا يحجب أي نمط منفرداً بذاته. بل تتراكم المطابقات ويقرّر حدٌّ واحد في النهاية — فالطلب الذي يبدو غريباً قليلاً من ثلاث جهات يُعامَل معاملة مختلفة عن طلب لا لبس فيه من جهة واحدة.

You tell it which platforms you actually run, and the rules that cannot apply to you are not loaded. A rule about a Windows system file is noise on a Linux fleet, and noise is what makes people switch a firewall off.تخبره بالمنصّات التي تشغّلها فعلاً، فلا تُحمَّل القواعد التي لا تنطبق عليك. فالقاعدة المتعلّقة بملف نظام في ويندوز ضجيجٌ على أسطول لينكس، والضجيج هو ما يدفع الناس إلى إيقاف الجدار.

By default a request body is inspected up to 128 KB, and anything larger is forwarded to your application without being inspected. It is stated here rather than left to be discovered: it is the boundary of what the firewall has looked at. The limit is yours to raise, at a cost in memory and in the time each large request takes.افتراضياً يُفحص جسم الطلب حتى ١٢٨ كيلوبايت، وما زاد عن ذلك يُمرَّر إلى تطبيقك دون فحص. وقد ذُكر هذا هنا بدل أن يُترك ليُكتشف: فهو حدّ ما نظر إليه الجدار. والحدّ لك أن ترفعه، بكلفة في الذاكرة وفي الزمن الذي يستغرقه كل طلب كبير.
Updatesالتحديثات

Nobody approves a rule by handلا أحد يعتمد قاعدةً يدوياً

New vulnerabilities are published constantly, and a firewall whose rules wait on somebody's review is a firewall that is out of date exactly when it matters. So rules arrive on their own. Three things stand in for the person who is not there.تُنشر الثغرات الجديدة بلا انقطاع، والجدار الذي تنتظر قواعده مراجعة أحدهم هو جدار متقادم في اللحظة التي يهمّ فيها. لذا تصل القواعد من تلقاء نفسها. وثلاثة أمور تنوب عن الشخص غير الموجود.

  1. Watch before you block. A deployment can run in a mode where the firewall assesses every request and refuses none, and the console reports what it would have done. That is how you find out what a rule does to your traffic without finding out from your users.راقب قبل أن تحجب. يمكن تشغيل النشر في وضع يقيّم فيه الجدار كل طلب ولا يرفض شيئاً، وتذكر لوحة التحكم ما كان سيفعله. وهكذا تعرف أثر القاعدة على حركتك دون أن تعرفه من مستخدميك.
  2. A rule that gets it wrong switches itself off. The firewall watches what a newly arrived rule does to real traffic and disables that one rule — not the whole set — when it starts refusing ordinary requests.القاعدة المخطئة توقف نفسها. يراقب الجدار أثر القاعدة الواصلة حديثاً على الحركة الحقيقية، فيعطّل تلك القاعدة وحدها — لا المجموعة كلّها — متى بدأت ترفض طلبات عادية.
  3. You can put a whole set back. One action in the console returns the rules to the version that was running before. It is the escape hatch, and it exists so that automatic updates are a decision you can undo rather than one you have to trust.ويمكنك إرجاع مجموعة كاملة. إجراء واحد في لوحة التحكم يعيد القواعد إلى النسخة التي كانت تعمل قبلها. إنه مخرج الطوارئ، ووجوده يجعل التحديث التلقائي قراراً يمكنك التراجع عنه لا قراراً عليك أن تثق به.
The second one is harder than it looks, and getting it wrong is worse than not having it. A rule that suddenly refuses a great many requests may be a rule that is wrong about your traffic — or a rule that has just caught an attack. The two are told apart by how many different places the requests come from: refusals spread across many sources are a rule misreading ordinary visitors, while refusals concentrated in a few are the rule doing its job. Reacting to the rate alone would switch off the rule at the moment it started earning its place.الأمر الثاني أصعب ممّا يبدو، والخطأ فيه أسوأ من غيابه. فالقاعدة التي ترفض فجأة عدداً كبيراً من الطلبات قد تكون قاعدة مخطئة بشأن حركتك — أو قاعدة التقطت للتوّ هجوماً. ويُفرَّق بينهما بـعدد المصادر المختلفة التي تأتي منها الطلبات: فالرفض المنتشر عبر مصادر كثيرة قاعدةٌ تسيء قراءة زوّار عاديين، أمّا الرفض المتركّز في مصادر قليلة فهو القاعدة تؤدي عملها. والتفاعل مع المعدّل وحده يوقف القاعدة في اللحظة التي بدأت فيها تستحقّ مكانها.
False positivesالإنذارات الكاذبة

A false positive is two clicksالإنذار الكاذب نقرتان

Every web application firewall refuses something it should not. What decides whether one is bearable is not how rarely that happens — it is how long it takes to fix when it does, and at three in the morning nobody is editing a rule file.كل جدار ناري لتطبيقات الويب يرفض ما لا ينبغي أن يرفضه. وما يقرّر احتمال الجدار من عدمه ليس نُدرة وقوع ذلك — بل المدة التي يستغرقها إصلاحه حين يقع، ولا أحد في الثالثة فجراً يحرّر ملف قواعد.

The console lists what fired, grouped by rule, with the request that tripped it. Beside each one is a button that allows it — narrowed to that one path, and where possible to the single field that matched, rather than switching the rule off everywhere.تعرض لوحة التحكم ما انطلق من القواعد، مجموعاً بحسب القاعدة، ومعه الطلب الذي أطلقها. وإلى جانب كل واحدة زرٌّ يسمح بها — محصوراً بذلك المسار وحده، وبالحقل المطابِق وحده متى أمكن، بدل إيقاف القاعدة في كل مكان.

The console names every rule it is about to narrow before you press the button. Because matches accumulate, letting one request through often means narrowing more than one rule — and allowing a protection is not something you should agree to without being told what it was.تذكر لوحة التحكم كل قاعدة توشك أن تحصرها قبل أن تضغط الزر. فلأن المطابقات تتراكم، فإن السماح بطلب واحد كثيراً ما يعني حصر أكثر من قاعدة — والتنازل عن حماية ليس ممّا ينبغي أن توافق عليه دون أن يُقال لك ما هو.

Every narrowing records who made it and why. Turning a rule off everywhere is offered too, and the console says plainly what that trades away.يسجَّل مع كل حصرٍ مَن أجراه ولماذا. وإيقاف القاعدة في كل مكان متاح أيضاً، وتذكر لوحة التحكم بوضوح ما الذي تفرّط فيه بذلك.

Where it runsأين يعمل

On your own infrastructureعلى بنيتك التحتية أنت

The firewall and its console are software you run. Nothing of ours sits between your visitors and your application, and there is no service of ours that has to be reachable for your site to serve a request.الجدار ولوحة تحكّمه برمجيات تشغّلها أنت. فلا شيء من عندنا يقع بين زوّارك وتطبيقك، ولا توجد خدمة لنا يلزم أن تكون متاحة كي يخدم موقعك طلباً.

That is what makes it safe for the console to show you the request that tripped a rule, body and all. Tuning a false positive is impossible without seeing what was refused, and the reason you can see it is that it never went anywhere.وهذا ما يجعل من الآمن أن تعرض لك لوحة التحكم الطلب الذي أطلق القاعدة، بجسمه وكل ما فيه. فضبط الإنذار الكاذب مستحيل دون رؤية ما رُفض، وسبب تمكّنك من رؤيته أنه لم يذهب إلى أي مكان.

Alerts are webhooks to an address you choose, and an alert carries no request data at all — no body, no header, no payload. There is no field in one that could hold it.التنبيهات خطّافات ويب إلى عنوان تختاره أنت، ولا يحمل التنبيه أي بيانات من الطلب البتّة — لا جسماً ولا ترويسة ولا حمولة. فليس فيه حقلٌ يمكن أن يحملها.

The console is rendered on the server and works with no JavaScript, in English and Arabic. Somebody running a firewall on their own hardware should not need a build toolchain to find out why their site is refusing requests, and a machine with no route to the internet should not be a special case.تُبنى لوحة التحكم على الخادم وتعمل بلا جافاسكربت، بالعربية والإنجليزية. فمن يشغّل جداراً نارياً على عتاده لا ينبغي أن يحتاج إلى سلسلة أدوات بناء ليعرف لماذا يرفض موقعه الطلبات، ولا ينبغي أن يكون الجهاز المعزول عن الإنترنت حالة خاصة.

Limitsالحدود

What it is notما ليس هو

A large appliance does many things. This does three, and the list below is not a roadmap — it is what has been left out so that the three are good.الجهاز الضخم يفعل أشياء كثيرة. وهذا يفعل ثلاثة، وما يلي ليس خارطة طريق — بل هو ما تُرك جانباً كي تكون الثلاثة جيّدة.

  • Not a gateway for your staff. No access policies, no single sign-on, no VPN. That is a different product with a different job.ليس بوّابة لموظفيك. لا سياسات وصول ولا دخول موحّد ولا شبكة خاصة افتراضية. ذاك منتج آخر بعمل آخر.
  • Not a network firewall. It reads requests, not packets. Refusing traffic below the level of an HTTP request is a separate thing, and it is not here yet.ليس جدار شبكة. يقرأ الطلبات لا الحِزَم. ورفض الحركة دون مستوى طلب HTTP أمر منفصل، وليس هنا بعد.
  • No health checks and no sticky sessions. Deliberately: those are the features that make a load balancer something you have to operate, and an application that needs them is telling you something.لا فحوص صحّة ولا جلسات لاصقة. عن قصد: فتلك هي الميزات التي تجعل موازن الحمل شيئاً يلزم تشغيله وإدارته، والتطبيق الذي يحتاجها يقول لك شيئاً.
  • Not a guarantee. It blocks attacks that are known and described. A firewall is one layer, and it is not a reason to leave your application unpatched.ليس ضماناً. يحجب الهجمات المعروفة الموصوفة. والجدار طبقة واحدة، وليس سبباً لترك تطبيقك بلا ترقيع.
Why hereلماذا هنا

Built in Saudi Arabiaصُنع في السعودية

The appliances this replaces are licensed by throughput, renewed yearly, and sold with a great deal you will never switch on. We build in Riyadh, in Arabic and English from the first line, and the console reads the same either way — a firewall's screens are read under pressure, and a language nobody chose is a bad place to be at three in the morning.الأجهزة التي يحلّ محلّها تُرخَّص بحسب سعة المرور، وتُجدَّد سنوياً، وتُباع ومعها الكثير ممّا لن تشغّله أبداً. أمّا نحن فنبني في الرياض، بالعربية والإنجليزية من السطر الأول، وتُقرأ لوحة التحكم بأيّهما سواء — فشاشات الجدار الناري تُقرأ تحت الضغط، ولغةٌ لم يخترها أحد مكانٌ سيّئ للوقوف فيه في الثالثة فجراً.