When you enable the WAF test cookie functionality the first request which a client makes to your site will have a cookie inserted and a redirect which will send them to load the page again.

When the client returns after the reload and they have the cookie they will then be allowed to pass through without any interruptions, if the client returns without the cookie then they will be blocked.

For your typical user, they will not even notice the reload and check happen.

The benefits to this are that many spam bots and DoS attack tools will not accept and then return a cookie thus it can cause an immediate 100% block of an attack.

Updated on December 12, 2018

