The three terms are often used interchangeably, but they sit in different places and look at different things.
Think of your IT system as an office building. The gate guard controls who can enter the building. The website is the one office inside the building that's open to outside visitors, and it has its own front-desk security who only watches people entering that office and checks whether the forms they fill in carry anything harmful. Regional reception outposts let visitors check in closer to home, and fake visitors get absorbed there. These three roles are the firewall, the WAF, and the CDN.
Each one sits in a different position, and none can substitute for the others.
Looks at the source address and port of a connection and decides whether to allow or block the whole thing. It doesn't look at content.
Understands the content of a web request: URL parameters, form fields, cookies, and API data, checking whether it carries attack payloads.
Puts website content on the node closest to the user, so visitors check in nearby; fake traffic gets absorbed here.
The firewall handles connections, the WAF handles content, and the CDN handles traffic volume. Most businesses already have a firewall; what they're missing is the layer that understands web page content.
For a website to operate, its public web port has to stay open to the whole world. An attacker doesn't need to force a door. They walk straight through the front entrance, using a web request that looks identical to any regular visitor's. To the firewall, that's just normal web traffic, so it lets it through.
The difference is hidden in the form fields. A firewall doesn't parse web page content and doesn't know which field feeds into a database; it can't tell whether the "product name" box contains "ballpoint pen" or a database command. The gate guard doesn't flip through the papers a visitor is carrying.
"I have an SSL certificate, so I'm safe": a certificate encrypts the transmission, protecting it from being intercepted along the way, but it doesn't check whether the content is good or bad. An attack payload can just as easily arrive encrypted.
"My site is too small for anyone to attack": most attacks aren't targeted at you specifically. Scanners knock on doors across the internet, checking which ones are unlocked.
"We already have a firewall": the two operate at different layers. The generic web rules bundled with a next-generation firewall aren't tuned to your website's specific fields.
How to fit the three layers of protection into your existing architecture depends on where your traffic comes from and the state of your data center.
View Web & API Protection (WAF) How to choose among the three protection layers Ask about protection planning