Comparison diagram showing self-hosted WAF near the origin and managed edge WAF in a global edge network before cloud services.
两种模式的核心差异在于谁控制路由、策略、升级、日志和紧急回滚。
  • 自托管 WAF
  • 源站侧控制
  • 托管边缘 WAF
  • 全球边缘网络
  • 决策标准
  • 成本、日志、延迟、回滚

实验状态

对象
Self-hosted WAF and managed edge WAF operating models
状态
方法论
更新
2026-07-09

证据原则

WAFWiki 会区分已验证的动手实测、冒烟实测、架构图和方法论说明。任何本地实验都只证明记录环境中的有限路径,不代表完整生产就绪。

环境

可复现信息

自托管模式

Team owns deployment, upgrades, logs, tuning, and bypass path

托管模式

Provider operates the edge platform while the team owns policy and routing choices

对比方法

Use the same workload, observation window, and false-positive checklist

命令

如何复现实验

对比同一请求路径

Replay identical clean workflows through both candidate WAF paths when architecture allows it.

对比状态码、延迟、规则事件、请求字段和回滚步骤。

记录责任归属

For each candidate, list who owns DNS, TLS, policy changes, upgrades, support escalation, logs, and bypass.

风险更低的方案通常是团队能稳定运营并有信心回滚的方案。

观察结果

该模型帮助验证什么

自托管优势

本地控制

Good when origin-side control and data locality matter.

托管优势

托管运营能力

Good when global edge, DDoS, CDN, bot controls, and support matter together.

优先用流量路径和运营责任作为一阶判断标准。
没有请求量、规则范围、日志和支持需求时,不要直接比较价格。
公平对比应使用同一组代表性业务流程。

证据上下文

证据来自已记录的本地实验摘要。

公开页面展示可安全公开的环境与结果摘要;原始本地日志保留在项目文档中,便于后续复核。

限制

这个结果不能证明什么

相关研究

继续研究 Self-hosted WAF and managed edge WAF operating models