Managed WAF for multi-site campus and agency estates
Thin IT teams do not lose sleep over one polished homepage. They lose sleep over dozens of departmental, college, and agency properties — mixed CMS, mixed hosts, incomplete inventory — and one operator who owns the edge. ProtectMyWebsite is a managed WAF for multiple websites: one DNS change per property (or we handle DNS), rules at the edge, hosting and content unchanged. Short product page: /solutions/multi-site-managed-waf. This guide covers why a campus website estate firewall must be count-first, how a multi-site WAF one team fails with a different deny pack per domain, when self-serve $150/site/month is enough, and when Campus Estate WAF means Talk to sales team.
Why multi-site estates need one managed edge story
Campus and agency estates are operator-hard for the same reasons:
Inventory is never finished. Central IT’s list and the school or agency list diverge. Forgotten department, program, event, and vendor portals still accept POSTs.
One thin team, many owners. A web or security pair covers the main .edu or .gov, colleges, athletics, regional offices, and microsites. Nobody has bandwidth for a DIY rule console per domain.
Forms define the brand. Admissions, registration, permit, benefits, and contact POSTs must stay up. A blocked form on a forgotten subdomain is still a closed counter.
Drupal and WordPress dominate. Mixed hosts, uneven patch windows, freeze calendars. Edge coverage without a module or plugin on every property matters.
That is why /waf-for/higher-education and /waf-for/government share one operator problem: many sites, one thin team, zero appetite for false positives. Sister deep dives: /guides/higher-education-managed-waf and /guides/government-managed-waf.
The inventory problem — and why deny-per-site fails
An agency multi-domain WAF (or campus estate) fails first as a spreadsheet problem. Operators discover hostnames after an incident: staging still public, an alumni portal on the same VIP, a college microsite never moved behind the edge. Deny-on-day-one packs make that worse — each property gets a different rule story; the thin team spends cycles on allowlists instead of inventory. A multi-site WAF one team needs one operator story:
1. Rules start in count. Matches log; they do not deny yet.
2. Real traffic runs ~24 hours. Editors, monitors, IdP callbacks, and peak form hours show up — per property, same promote language.
3. The dashboard shows what’s safe to block — one click.
4. Promote Copilot recommends Promote, Hold, or Needs allowlist — evidence plus a short why. It does not auto-block. You still click.
Shared count → promote is how one operator scales a campus website estate firewall without a different deny pack per college or bureau. Context: /guides/diy-vs-managed-waf.
Campus Estate WAF — what “managed” actually means
A Campus Estate WAF is not another appliance console for the network team. It is an edge-managed WAF in front of each public hostname — a managed WAF for multiple websites operators can actually run:
1. Exploit probes, login floods, bad bots, and injection/XSS-class noise hit the shield first.
2. Origin sees less junk CPU and fewer mysterious form outages across the estate.
3. No CMS module or plugin required on every microsite — hosting and content stay put.
4. Operators promote from evidence, with the same promote language on every property.
The pitch is not a vendor war. It is: stop treating in-app hardening or a DIY rule console as your public edge for dozens of domains. Managed path: DNS → observe → promote.
Pricing (self-serve): $150/site/month, 14-day trial at checkout. See /pricing. For larger campus or agency estates (main property + many departmental or multi-domain properties), Talk to sales team — no Campus Estate dollar amounts here.
| Step | What happens |
|---|---|
| Onboard | One DNS change per property, or concierge DNS (~one business day). Hosting and content stay put. |
| Observe | Managed rules for injection, XSS-class noise, known exploit patterns, bad bots, malicious IPs, plus rate limits on login and form endpoints — all start in count. |
| Promote | After ~24 hours, the dashboard surfaces candidates. Copilot explains Promote / Hold / Needs allowlist; the human promotes. |
| Operate | No in-CMS security pack to keep updated on every microsite. Edge shield stays on while owners catch up on patching. |
Self-serve vs Campus Estate — when to Talk to sales
Use self-serve when one operator can onboard property by property at $150/site/month and a 14-day trial proves count → promote. Signup: /signup.
Use Campus Estate when inventory is large, onboarding needs concierge volume, or purchasing wants one conversation for the whole estate. The CTA is always Talk to sales team. Copilot and count → promote are the same on both paths; only the commercial path changes. Operator hub: /solutions.
Origin IP still matters across the estate
A quiet edge on the main .edu or .gov means nothing if attackers still punch a departmental load balancer. Estates leak origin IPs when inventory is incomplete: historical DNS, staging on the same VIP, vendor portals, forgotten college or regional subdomains never moved behind the edge. Hide the origin IP behind the WAF and allowlist edge IPs only on origin listeners for every property you claim to protect — or a flood walks around the shield while the dashboard stays calm on the properties you remembered.
One operator story for campuses and agencies
Most multi-site estates are Drupal Multisite fragments, departmental WordPress, agency portals with shared IdP paths, and vendor-hosted forms. Edge-managed WAF fits that reality: share one count → promote story across main site and microsites; keep admissions, registration, permit, benefits, and upload endpoints in count until evidence says promote; virtual-patch known exploit patterns at the edge while owners schedule Composer or plugin updates under freeze windows.
Verticals: /waf-for/higher-education, /waf-for/government. Multi-site page: /solutions/multi-site-managed-waf.
FAQ
What is a managed WAF for multiple websites? An edge web application firewall in front of each public hostname that you do not install as a CMS module or plugin on every property. ProtectMyWebsite sits on DNS; hosting and content stay as they are. Rules start in count; you promote what’s safe to block. Short page: /solutions/multi-site-managed-waf.
What is a campus website estate firewall or Campus Estate WAF? A campus website estate firewall (or Campus Estate WAF) means edge-managed WAF coverage across the main campus property plus departmental and college microsites — same count → promote language, not a DIY console per domain. For larger estates, Talk to sales team.
How does a multi-site WAF one team avoid false positives? Start rules in count on each property, let real traffic run ~24 hours, then promote only what the dashboard shows is safe. Promote Copilot can flag Hold or Needs allowlist when hits look like legitimate POSTs — you still click.
When is self-serve $150/site enough vs Talk to sales for Campus Estate? Self-serve $150/site/month with a 14-day trial fits smaller estates you onboard property by property. Campus Estate is for larger inventory or one purchasing conversation — Talk to sales team. No Estate dollar amounts here; see /pricing for self-serve.
Does Promote Copilot auto-block estate traffic? No. Copilot explains Promote / Hold / Needs allowlist from count-window evidence. The human still clicks. If AI is unavailable, the non-AI suggest UI remains. Count → promote is the same on self-serve and Campus Estate paths.
Start here
ProtectMyWebsite is the managed WAF for multi-site campus and agency operators who need a campus website estate firewall and agency multi-domain WAF that watches first — one team, shared count → promote.
Pricing (self-serve): $150/site/month, 14-day trial. Campus estate (many properties): Talk to sales team — no Campus Estate dollar amounts here. Copilot included on self-serve and estate paths.
Related
- All guides
- Managed WAF for multi-site teams
- Managed WAF for higher education websites
- Managed WAF for government websites
- DIY WAF vs managed: console burden or operator?
- Managed WAF pricing: is $150/site worth it?
- Managed WAF setup: DNS cutover to count mode
- WAF for FOIA and public records portals
- WAF for athletics, news, and campus microsites
- Managed WAF for university and college websites
- Managed WAF for government and public-sector websites
- What is WAF count mode? (and why you start there)
- What's safe to block on a WAF?
- Hide your origin IP behind a WAF (and allowlist edge IPs only)
- Solutions & guides
- Pricing
- Free security scan
- Start a 14-day trial