Just don’t run broken software. The attackers will not be able to exploit you then. If they have zero day exploits, the WAF will most of the time not save you since they are often pretty easy to circumvent. WAFs are only effective against old and shitty exploits that should be patched anyways since ages.
Wafs don’t make you safer but create unnecessary attack surface. Just keep your machine and services up to date.
Debian.