Comparison diagram showing self-hosted WAF near the origin and managed edge WAF in a global edge network before cloud services.
The two models differ less by the word WAF and more by who controls routing, policy, upgrades, logging, and emergency rollback.
  • Self-hosted WAF
  • Origin-side control
  • Managed edge WAF
  • Global edge network
  • Decision criteria
  • Cost, logs, latency, rollback

Lab status

Product
Self-hosted WAF and managed edge WAF operating models
Status
Methodology
Updated
2026-07-09

Evidence policy

WAFWiki separates verified smoke-test results from architecture diagrams and methodology notes. A smoke test proves one narrow local path; it does not claim full production readiness.

Environment

Reproducibility notes

Self-hosted model

Team owns deployment, upgrades, logs, tuning, and bypass path

Managed model

Provider operates the edge platform while the team owns policy and routing choices

Comparison method

Use the same workload, observation window, and false-positive checklist

Commands

How this lab can be reproduced

Compare the same request path

Replay identical clean workflows through both candidate WAF paths when architecture allows it.

Compare status code, latency, rule event, request field, and rollback steps.

Document ownership

For each candidate, list who owns DNS, TLS, policy changes, upgrades, support escalation, logs, and bypass.

The lower-risk option is often the one the team can operate and roll back confidently.

Observed result

What this model helps validate

Self-hosted strength

Local control

Good when origin-side control and data locality matter.

Managed strength

Operational leverage

Good when global edge, DDoS, CDN, bot controls, and support matter together.

Use traffic path and operations ownership as first-order criteria.
Do not compare pricing without request volume, rule scope, logs, and support needs.
A fair comparison uses the same representative business workflows.

Evidence context

Evidence is summarized from the recorded local run.

The public page shows safe excerpts from the recorded environment and results. Raw local logs remain in the project documentation for auditability.

Limitations

What this result does not prove

Related research

Continue researching Self-hosted WAF and managed edge WAF operating models