Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A web application firewall (WAF) can sit in front of a publicly reachable Node.js API and filter incoming requests against rules before they reach your application code. For a hosted API, the practical route is a WAF run by your hosting or edge provider, placed on the path that client traffic takes to the API. You do not install it as an npm package or application middleware.

The “five minutes” in the title is editorial framing. The provider documentation covers prerequisites and configuration steps, but none of it measures how long setup takes. Plan for the account, DNS or routing, and testing work described below, which will usually take longer than a single pass through the console.

What a WAF filters, and what it leaves to you

A WAF checks each request against a set of rules and takes an action when one matches. Cloudflare says its rules can inspect properties such as IP address, URL path, headers, and body content (Cloudflare WAF concepts). AWS documents four actions for matched requests: allow, block, count, and challenge (AWS WAF documentation).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A WAF does not authenticate callers, decide what an authenticated user may do, or validate the data your endpoints accept. It also does not replace secure coding, monitoring, or rate controls suited to your API. Managed rules are a starting point, and how much of each request they inspect depends on your plan or service. Treat the WAF as one layer in front of your API, with the controls in your Node.js code still in place.

#1 Best Overall
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Choose a route before you start

The two routes covered here differ in where the filtering happens and who runs it. Compare them on the factors that matter for your deployment:

Factor Cloudflare WAF AWS WAF on API Gateway REST APIs
Where it sits In front of a domain added to Cloudflare, so client requests pass through Cloudflare first Associated with a REST API stage in Amazon API Gateway
Prerequisites A Cloudflare account and the domain added to Cloudflare (Cloudflare getting-started guide) An AWS account, an API Gateway REST API, and a Regional web ACL. The AWS guide names the AWS WAFv2 web ACL for this case (AWS API Gateway guide)
Managed rules The Free plan has the Free Managed Ruleset deployed by default. The broader Cloudflare Managed Ruleset and the Cloudflare OWASP Core Ruleset depend on plan (Cloudflare managed rules) You add managed and custom rules to the web ACL. Managed rule group availability and cost are not stated on the cited AWS page
Request-body inspection Limit varies by plan; see the limits section below The first 64 KB of the body is matched (AWS API Gateway guide)
Logging and tuning Security Events and Security Analytics, with availability varying by plan (Cloudflare WAF overview) The count action lets you observe matches before blocking. Log destinations are not described on the cited page
Operational ownership Cloudflare runs the proxy; you manage DNS and rules in the Cloudflare dashboard You own the web ACL, its rules, and the stage association in your AWS account

Choose Cloudflare if your domain already uses it or you want filtering that does not depend on your hosting platform. Choose AWS if your API already runs on API Gateway REST APIs. The AWS route is an API Gateway integration path. It does not apply to a Node.js server hosted elsewhere unless that deployment supports the same integration.

Route 1: Cloudflare in front of your API

  1. Create a Cloudflare account and add the domain your API uses. The getting-started guide assumes both steps are complete (Cloudflare WAF getting-started guide).

    Free tools Windows power users keep installed

    One-click scans. No signup required.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  2. Make sure the hostname clients call resolves through Cloudflare. A WAF that clients can bypass filters nothing. Follow the DNS instructions in the getting-started guide for this step, since the exact settings depend on how your domain is configured.

  3. Deploy a managed ruleset. On the Free plan, the Free Managed Ruleset is deployed by default, and you may skip the managed-ruleset deployment portion of the guide.

  4. Review Security Events after real traffic has passed through the proxy. Look for matches against your own endpoints, not only the ones you expected.

  5. Add custom rules or rate limits for controls specific to your API, such as limiting login attempts or restricting paths to particular methods.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Route 2: AWS WAF on an API Gateway REST API

  1. Confirm your API is a REST API in Amazon API Gateway. The cited AWS guide covers REST APIs, not other API Gateway API types.

  2. In AWS WAF, create a Regional web ACL. Add the managed rule groups and custom rules you need, and set the rules you are less sure about to count rather than block.

    Rank #2
    WatchGuard Firebox T45-PoE Network Security/Firewall Appliance (WGT47000-US+WGT470063)
    • WatchGuard Firebox T45 tabletop appliances bring enterprise-level network security to small office/branch office and retail environments. These appliances are small-footprint, cost-effective security powerhouses that deliver all the features present in WatchGuard’s higher-end UTM appliances, including all security capabilities, such as AI-powered anti-malware, threat correlation, and DNS-filtering.
    • 5G and Wi-Fi 6 enabled models available. Up to 3.94 Gbps firewall throughput, 5 x 1Gb ports, 30 Branch Office VPNs
    • Zero-touch deployment makes it possible to eliminate much of the labor involved in setting up a Firebox to connect to your network - all without having to leave your office. A robust, Cloud-based deployment and configuration tool comes standard with WatchGuard Firebox appliances. Local staff connects the device to power and the Internet, and the appliance connects to the Cloud for all its configuration settings.
    • Firebox T45 models make network optimization easy. With integrated SD-WAN and optional 5G technology, you can ensure failover to the cellular network, minimize disruptive connectivity, and establish secure and reliable connections for small offices.
    • Standard Support includes 24x7 access to technical support, with an unlimited number of incidents with a targeted response time of 24 hours for low priority, 8 hours for medium priority, 4 hours for high priority, and live calls for critical priority. Support is Web-Based and Phone-Based.
  3. Associate the web ACL with the REST API stage, following the association method in the AWS API Gateway guide (AWS API Gateway guide).

  4. Send normal API requests through the stage and check the matches recorded for the web ACL. Move rules from count to block only after legitimate traffic passes cleanly.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What changes in your Node.js code

Because the WAF is a proxy in front of your application, a few details in the app itself are worth checking:

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Tuning without blocking real clients

Cloudflare warns that managed rules can produce false positives, meaning legitimate requests can be mitigated. Some rules are disabled by default to balance protection against false positives, and Cloudflare advises against enabling every available rule outside a proof of concept (Cloudflare managed ruleset reference). Use the same caution on either route.

Limits to plan around

Request-body inspection is the limit that most often surprises API teams. Cloudflare documents a maximum inspected body size that varies by plan: 1 MB on Free, a lower default on other paid plans, and 128 KB for Enterprise in the documented context (Cloudflare managed rules). AWS matches only the first 64 KB of the body. For an API that accepts large JSON bodies or uploads, the portion beyond the inspected limit is not covered by WAF body rules, so your application must validate it.

Plan details, limits, and console labels can change. Confirm current figures in the linked provider documentation before you rely on them.

Verify the setup

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.