OWASP CRS block rules in production
Web Application Firewalls (WAF) are a neat strategy to protect your webservers from malicious connections. All of the WAFs in the market work similarly. You define rules of what you think is good or bad traffic and the WAF tries to detect attacks based on that. But your WAF will always just be as good as your rules. The OWASP CRS Instead of having to write all your own rules, the OWASP Project has a Core Rule Set (CRS) which you can download for free from their website.