What it doesما الذي يفعله
Three things, and deliberately not a fourth. It terminates TLS, it inspects every request for known attacks, and it forwards what passes to your application.ثلاثة أمور، ورابعٌ متروك عن عمد. ينهي TLS، ويفحص كل طلب بحثاً عن الهجمات المعروفة، ويمرّر ما يجتاز الفحص إلى تطبيقك.
Nothing about your application changes. It does not need a library, an agent, a code change or a redeploy — the firewall stands in front of what you already run.لا يتغيّر شيء في تطبيقك. لا يحتاج إلى مكتبة ولا وكيل ولا تعديل في الشيفرة ولا إعادة نشر — فالجدار يقف أمام ما تشغّله أصلاً.
In front of your applicationأمام تطبيقك
A visitor reaches nginx, nginx asks wāfi, and only then does the request reach your application. You do not write that configuration by hand — the firewall prints it, so it cannot drift from the version you are running.يصل الزائر إلى nginx، ويسأل nginx وافي، وعندها فقط يصل الطلب إلى تطبيقك. ولستَ من يكتب هذه الإعدادات يدوياً — بل يطبعها الجدار نفسه، فلا يمكن أن تتباعد عن النسخة التي تشغّلها.
- visitor → nginxالزائر ← nginx
TLS ends here. The connection is accepted and the request is matched to one of your applications.ينتهي TLS هنا. يُقبل الاتصال ويُطابَق الطلب بأحد تطبيقاتك. - nginx → wāfinginx ← وافي
The request is assessed — its path, its headers and its body — and the answer is allow or refuse.يُقيَّم الطلب — مساره وترويساته وجسمه — ويكون الجواب سماحاً أو رفضاً. - wāfi → your applicationوافي ← تطبيقك
What passes is forwarded, unchanged. A refusal never reaches you at all, so nothing in your application has to handle it.ما يجتاز يُمرَّر كما هو. أمّا المرفوض فلا يصل إليك أصلاً، فلا شيء في تطبيقك مضطرٌّ للتعامل معه.
A refused request gets a plain page that names no rule and carries a reference number. Telling an attacker which pattern stopped them turns a block into a tuning aid; the reference is what your support desk searches for when the person who was refused is a customer.يتلقّى الطلب المرفوض صفحة بسيطة لا تذكر أي قاعدة وتحمل رقم إشارة. فإخبار المهاجم بالنمط الذي أوقفه يحوّل الحجب إلى أداة ضبط له؛ أمّا رقم الإشارة فهو ما يبحث عنه مكتب الدعم لديك حين يكون المرفوض عميلاً.
Patterns, and named vulnerabilitiesأنماط وثغرات مسمّاة
Two kinds of rule, doing two different jobs. The first describes the shape of an attack — an injection, a traversal, a script in a form field — and does not care what software you run. The second addresses one named vulnerability in one product, so that an application you have not yet patched stops being reachable.نوعان من القواعد، لكلٍّ منهما عمل مختلف. الأول يصف شكل الهجوم — حقنٌ أو اجتياز مسار أو سكربت في حقل نموذج — ولا يعنيه ما البرمجيات التي تشغّلها. والثاني يعالج ثغرة مسمّاة بعينها في منتج بعينه، حتى يتوقّف تطبيق لم تُرقّعه بعدُ عن كونه قابلاً للاستغلال.
No single pattern blocks on its own. Matches add up, and one threshold at the end decides — so a request that looks slightly unusual in three ways is treated differently from one that is unmistakable in one.لا يحجب أي نمط منفرداً بذاته. بل تتراكم المطابقات ويقرّر حدٌّ واحد في النهاية — فالطلب الذي يبدو غريباً قليلاً من ثلاث جهات يُعامَل معاملة مختلفة عن طلب لا لبس فيه من جهة واحدة.
You tell it which platforms you actually run, and the rules that cannot apply to you are not loaded. A rule about a Windows system file is noise on a Linux fleet, and noise is what makes people switch a firewall off.تخبره بالمنصّات التي تشغّلها فعلاً، فلا تُحمَّل القواعد التي لا تنطبق عليك. فالقاعدة المتعلّقة بملف نظام في ويندوز ضجيجٌ على أسطول لينكس، والضجيج هو ما يدفع الناس إلى إيقاف الجدار.
Nobody approves a rule by handلا أحد يعتمد قاعدةً يدوياً
New vulnerabilities are published constantly, and a firewall whose rules wait on somebody's review is a firewall that is out of date exactly when it matters. So rules arrive on their own. Three things stand in for the person who is not there.تُنشر الثغرات الجديدة بلا انقطاع، والجدار الذي تنتظر قواعده مراجعة أحدهم هو جدار متقادم في اللحظة التي يهمّ فيها. لذا تصل القواعد من تلقاء نفسها. وثلاثة أمور تنوب عن الشخص غير الموجود.
- Watch before you block. A deployment can run in a mode where the firewall assesses every request and refuses none, and the console reports what it would have done. That is how you find out what a rule does to your traffic without finding out from your users.راقب قبل أن تحجب. يمكن تشغيل النشر في وضع يقيّم فيه الجدار كل طلب ولا يرفض شيئاً، وتذكر لوحة التحكم ما كان سيفعله. وهكذا تعرف أثر القاعدة على حركتك دون أن تعرفه من مستخدميك.
- A rule that gets it wrong switches itself off. The firewall watches what a newly arrived rule does to real traffic and disables that one rule — not the whole set — when it starts refusing ordinary requests.القاعدة المخطئة توقف نفسها. يراقب الجدار أثر القاعدة الواصلة حديثاً على الحركة الحقيقية، فيعطّل تلك القاعدة وحدها — لا المجموعة كلّها — متى بدأت ترفض طلبات عادية.
- You can put a whole set back. One action in the console returns the rules to the version that was running before. It is the escape hatch, and it exists so that automatic updates are a decision you can undo rather than one you have to trust.ويمكنك إرجاع مجموعة كاملة. إجراء واحد في لوحة التحكم يعيد القواعد إلى النسخة التي كانت تعمل قبلها. إنه مخرج الطوارئ، ووجوده يجعل التحديث التلقائي قراراً يمكنك التراجع عنه لا قراراً عليك أن تثق به.
A false positive is two clicksالإنذار الكاذب نقرتان
Every web application firewall refuses something it should not. What decides whether one is bearable is not how rarely that happens — it is how long it takes to fix when it does, and at three in the morning nobody is editing a rule file.كل جدار ناري لتطبيقات الويب يرفض ما لا ينبغي أن يرفضه. وما يقرّر احتمال الجدار من عدمه ليس نُدرة وقوع ذلك — بل المدة التي يستغرقها إصلاحه حين يقع، ولا أحد في الثالثة فجراً يحرّر ملف قواعد.
The console lists what fired, grouped by rule, with the request that tripped it. Beside each one is a button that allows it — narrowed to that one path, and where possible to the single field that matched, rather than switching the rule off everywhere.تعرض لوحة التحكم ما انطلق من القواعد، مجموعاً بحسب القاعدة، ومعه الطلب الذي أطلقها. وإلى جانب كل واحدة زرٌّ يسمح بها — محصوراً بذلك المسار وحده، وبالحقل المطابِق وحده متى أمكن، بدل إيقاف القاعدة في كل مكان.
Every narrowing records who made it and why. Turning a rule off everywhere is offered too, and the console says plainly what that trades away.يسجَّل مع كل حصرٍ مَن أجراه ولماذا. وإيقاف القاعدة في كل مكان متاح أيضاً، وتذكر لوحة التحكم بوضوح ما الذي تفرّط فيه بذلك.
On your own infrastructureعلى بنيتك التحتية أنت
The firewall and its console are software you run. Nothing of ours sits between your visitors and your application, and there is no service of ours that has to be reachable for your site to serve a request.الجدار ولوحة تحكّمه برمجيات تشغّلها أنت. فلا شيء من عندنا يقع بين زوّارك وتطبيقك، ولا توجد خدمة لنا يلزم أن تكون متاحة كي يخدم موقعك طلباً.
That is what makes it safe for the console to show you the request that tripped a rule, body and all. Tuning a false positive is impossible without seeing what was refused, and the reason you can see it is that it never went anywhere.وهذا ما يجعل من الآمن أن تعرض لك لوحة التحكم الطلب الذي أطلق القاعدة، بجسمه وكل ما فيه. فضبط الإنذار الكاذب مستحيل دون رؤية ما رُفض، وسبب تمكّنك من رؤيته أنه لم يذهب إلى أي مكان.
The console is rendered on the server and works with no JavaScript, in English and Arabic. Somebody running a firewall on their own hardware should not need a build toolchain to find out why their site is refusing requests, and a machine with no route to the internet should not be a special case.تُبنى لوحة التحكم على الخادم وتعمل بلا جافاسكربت، بالعربية والإنجليزية. فمن يشغّل جداراً نارياً على عتاده لا ينبغي أن يحتاج إلى سلسلة أدوات بناء ليعرف لماذا يرفض موقعه الطلبات، ولا ينبغي أن يكون الجهاز المعزول عن الإنترنت حالة خاصة.
What it is notما ليس هو
A large appliance does many things. This does three, and the list below is not a roadmap — it is what has been left out so that the three are good.الجهاز الضخم يفعل أشياء كثيرة. وهذا يفعل ثلاثة، وما يلي ليس خارطة طريق — بل هو ما تُرك جانباً كي تكون الثلاثة جيّدة.
- Not a gateway for your staff. No access policies, no single sign-on, no VPN. That is a different product with a different job.ليس بوّابة لموظفيك. لا سياسات وصول ولا دخول موحّد ولا شبكة خاصة افتراضية. ذاك منتج آخر بعمل آخر.
- Not a network firewall. It reads requests, not packets. Refusing traffic below the level of an HTTP request is a separate thing, and it is not here yet.ليس جدار شبكة. يقرأ الطلبات لا الحِزَم. ورفض الحركة دون مستوى طلب HTTP أمر منفصل، وليس هنا بعد.
- No health checks and no sticky sessions. Deliberately: those are the features that make a load balancer something you have to operate, and an application that needs them is telling you something.لا فحوص صحّة ولا جلسات لاصقة. عن قصد: فتلك هي الميزات التي تجعل موازن الحمل شيئاً يلزم تشغيله وإدارته، والتطبيق الذي يحتاجها يقول لك شيئاً.
- Not a guarantee. It blocks attacks that are known and described. A firewall is one layer, and it is not a reason to leave your application unpatched.ليس ضماناً. يحجب الهجمات المعروفة الموصوفة. والجدار طبقة واحدة، وليس سبباً لترك تطبيقك بلا ترقيع.
Built in Saudi Arabiaصُنع في السعودية
The appliances this replaces are licensed by throughput, renewed yearly, and sold with a great deal you will never switch on. We build in Riyadh, in Arabic and English from the first line, and the console reads the same either way — a firewall's screens are read under pressure, and a language nobody chose is a bad place to be at three in the morning.الأجهزة التي يحلّ محلّها تُرخَّص بحسب سعة المرور، وتُجدَّد سنوياً، وتُباع ومعها الكثير ممّا لن تشغّله أبداً. أمّا نحن فنبني في الرياض، بالعربية والإنجليزية من السطر الأول، وتُقرأ لوحة التحكم بأيّهما سواء — فشاشات الجدار الناري تُقرأ تحت الضغط، ولغةٌ لم يخترها أحد مكانٌ سيّئ للوقوف فيه في الثالثة فجراً.