Managed WAF setup: DNS cutover to count mode
Campus and agency web teams ask what managed WAF setup looks like on the calendar. How long to install a WAF? What does one DNS change mean for CNAME vs apex? When does traffic hit the edge, and when do you promote? This is the straight WAF DNS cutover path for higher-ed web/IT, public-sector teams, and agencies that want to go live with a managed firewall without rewriting the site. Hosting and CMS stay put. Rules start in count. You click promote when evidence says junk.
What "one DNS change" means
Managed WAF setup is not a plugin install and not a hosting migration. It is pointing the public hostname at the ProtectMyWebsite edge so HTTP(S) flows through the shield first.
In practice: (1) You (or we) change DNS so the site’s public name resolves to the edge — typically a CNAME for www, or an apex/root alias when your DNS provider supports it. (2) SSL is issued or terminated at the edge. Visitors keep the same URL; no CMS certificate work. (3) Origin stays where it is. WordPress, Drupal, static hosts, and agency stacks keep running; the edge proxies to them. (4) Rules start in count. Matches log; they do not deny yet. Editors, monitors, IdP/LMS callbacks, and peak form hours show up first.
That is the whole “install” for a single property. See DIY WAF vs managed if you are still deciding who owns the edge.
CNAME vs apex: what operators change
Most campus and agency estates already live on www plus an apex (example.edu, agency.gov). You do not move content or editors — only where the public name points. Keep origin IPs off the open internet after cutover.
If DNS sits with a central NOC or registrar — common on higher education and government estates — use concierge DNS. ProtectMyWebsite coordinates with whoever holds the zone; typically about one business day once access and hostname list are clear.
| Hostname | Typical DNS cutover | Operator note |
|---|---|---|
| www and other subdomains | CNAME to the ProtectMyWebsite edge | Cleanest path; one record per hostname |
| Apex / root (@) | Provider alias / ANAME-style record to the edge | Same outcome — traffic hits the edge |
| Multi-hostname sites | Repeat for each public name that must be shielded | Same count → promote story per property |
How long to install a WAF? (day 0–24)
Separate traffic on the edge from rules in block. Rules start in count. After 24 hours, your dashboard shows what's safe to block — one click.
Go live managed firewall website can mean “DNS flipped and SSL green” in hours (or ~one business day with concierge DNS). Hardened means you reviewed the first count window and promoted junk — usually after ~24 hours.
Promote Copilot reads your count window and explains what's safe to promote — you still click once. It does not auto-block.
| Window | What happens | What “done” means |
|---|---|---|
| Day 0 — signup / DNS | Create the site, point DNS (self-serve or concierge), SSL live at the edge | Visitors already pass through the managed firewall |
| Day 0–~24 hours — count | Managed rules for injection, XSS-class noise, known exploit patterns, bad bots, malicious IPs, plus useful rate limits — all start in count | Observing real traffic; no day-one deny theater |
| After ~24 hours — promote | Dashboard shows what’s safe to block. Promote Copilot recommends Promote, Hold, or Needs allowlist with evidence | You click. Copilot explains; it does not auto-block |
| Ongoing | New noise lands in count until you promote | Same loop — observe → explain → human promote |
SSL, forms, and what does not change
Operators worry cutover will break SSO, admissions POSTs, or citizen uploads. On a count-first path:
Same URLs — bookmarks and users do not change. Forms and callbacks keep working while rules are in count — nested admissions bodies, Webforms, FOIA uploads, LMS/IdP redirects. CMS editors keep saving HTML and uploading PDFs; count mode surfaces that evidence before anyone promotes a risky rule. No in-app plugin/module required as the edge — DNS + proxy, not another WordPress or Drupal security module.
Campus and agency teams prefer count-first go-live over “flip DNS and hope deny packs are quiet.”
Self-serve vs concierge DNS vs Talk to sales
Self-serve is $150/site/month with a 14-day trial — card at Stripe at checkout. Larger Campus Estate footprints: Talk to sales (no Estate dollar amounts on this page). Copilot is included on self-serve and estate paths.
Start with a free passive scan before DNS. Create the trial at signup when ready to cut over.
| Path | Best when | What you do |
|---|---|---|
| Self-serve | One (or a few) well-owned sites; you control DNS | Sign up, add site, change DNS, start count. Card at Stripe for the 14-day trial; then $150/site/month |
| Concierge DNS | Zone owned by central IT / registrar / agency NOC | We coordinate cutover; typically ~one business day once hostname list and access are clear |
| Talk to sales (Campus Estate) | Many departmental properties, uneven ownership | Multi-site story. Talk to sales; no Estate dollar amounts here. Copilot included on self-serve and estate paths |
Go-live checklist (campus / agency)
1. Inventory public hostnames (www, apex, microsites that must share the shield). 2. Confirm origin reachability and lock down public origin exposure after cutover. 3. Choose self-serve or concierge DNS based on who edits the zone. 4. Flip DNS → SSL green at the edge. Site is live in count. 5. Let ~24 hours of real traffic accumulate — peak forms, editors, SSO if you have them. 6. Open the dashboard. Promote Copilot surfaces Promote / Hold / Needs allowlist. Human clicks. 7. Repeat for the next property — or Talk to sales for a multi-site estate.
One operator story across main and departmental properties. See multi-site solutions, higher education, and government.
FAQ
How long does managed WAF setup take? DNS cutover is usually hours on self-serve when you control the zone, or about one business day with concierge DNS. Rules start in count when traffic hits the edge. After ~24 hours the dashboard shows what’s safe; you promote — Copilot explains, it does not auto-block. See WAF count mode.
What does “one DNS change” mean for CNAME vs apex? Subdomains typically use a CNAME to the ProtectMyWebsite edge. Apex/root uses your provider’s alias-style record. Hosting and CMS stay put; SSL is at the edge. Same count → promote story either way.
Can we go live without blocking real forms on day one? Yes. Managed rules start in count — matches log, they do not deny yet. That protects admissions, citizen uploads, CMS editors, and IdP/LMS callbacks while you gather evidence. Promote is a human click after Copilot recommends Promote / Hold / Needs allowlist. Details: What's safe to block?
Is there a trial, and what does self-serve cost? Self-serve is $150/site/month with a 14-day trial — card at Stripe at checkout. See pricing and signup. Larger Campus Estate footprints: Talk to sales (no Estate dollar amounts on this page).
When should we Talk to sales instead of self-serve DNS? When you have many properties, mixed DNS ownership, or need a campus/agency estate roll-out. Start with multi-site solutions; use DIY vs managed if you are still choosing operator vs console. Copilot is included on self-serve and estate paths.
Start here
ProtectMyWebsite managed WAF setup is DNS cutover → count → promote — one change to go live, ~24 hours to see what’s safe, human clicks, no auto-block theater.
Related
- All guides
- What is WAF count mode? (and why you start there)
- What's safe to block on a WAF?
- DIY WAF vs managed: console burden or operator?
- Managed WAF pricing: is $150/site worth it?
- Free Website Security Scan: What the Grade Means
- Managed WAF for multi-site campus and agency estates
- Pricing
- Managed WAF for multi-site teams
- WAF for higher education
- WAF for government
- Free security scan
- Start a 14-day trial