DEV Community

Divinelab.io
Divinelab.io

Posted on

How to set up a self-hosted WAF for Webapps in 2 minutes ?

Securing a web application usually means either routing private traffic through a third-party cloud CDN or wrestling with complex Nginx configurations.

Here is how to set up Aegis—an open-source, self-hosted Web Application Firewall (WAF) and reverse proxy—in under two minutes.


1. Install & Deploy Aegis

Choose either the quick installation script or Docker:

Option A: Install via Script (Linux)

Clone the repository and run the automated installer:

git clone https://github.com/divinelabio/aegis.git
cd aegis
sudo bash install.sh
Enter fullscreen mode Exit fullscreen mode

Verify the systemd service is active:

sudo systemctl status aegis
Enter fullscreen mode Exit fullscreen mode

Option B: Deploy via Docker

Run the self-contained container with persistent data storage:

docker run -d --name aegis_server \
  --restart unless-stopped \
  -p 8080:8080 -p 8081:8081 \
  -v aegis_data:/var/lib/aegis/data \
  -e AEGIS_ADMIN_PASSWORD="ChooseStrongAdminPassword123!" \
  ghcr.io/divinelabio/aegis:latest
Enter fullscreen mode Exit fullscreen mode
  • Port 8080: Public Ingress Proxy (sits in front of your applications).
  • Port 8081: Web Dashboard for traffic monitoring and policy tuning.

2. Test WAF Attack Blocking

Aegis inspects incoming requests and blocks common web exploits (SQL Injection, XSS, Remote Code Execution) out of the box.

Test it by sending a simulated SQL Injection payload to the proxy:

curl -i "http://localhost:8080/?id=1%27%20OR%201=1--"
Enter fullscreen mode Exit fullscreen mode

Aegis intercepts the attack and returns HTTP 403 Forbidden:

HTTP/1.1 403 Forbidden
X-WAF-Rule-ID: 942100

Access denied: This request was rejected by the application security layer.
Enter fullscreen mode Exit fullscreen mode

The attack is dropped at the edge and never reaches your backend servers.


3. Manage Routes in the Web Dashboard

Open http://localhost:8081 in your browser.

From the dashboard, you can:

  • Route incoming traffic to your backend origin servers.
  • View blocked attacks and threat telemetry in real time.
  • Adjust Layer 7 rate limits, toggle Geo-IP blocking, and manage SSL certificates.

All policy updates reload dynamically in memory with zero downtime—no proxy restarts required.


Resources

The Community Edition is free to self-host on your own servers and homelabs:

Top comments (0)