A firewall will only protect against attacks aimed towards the web server it self, and not the actual web application on it. Some firewalls have basic protection agains the most common attacks towards applications like SQL injection and XSS ... but if you want protection for attacks like the once im referring to, you need a full Web Application Firewall, .. and normal one just wount cut it....