This doesn't seem like a very plausible scenario, as the SSL certificate and key needed to decrypt the information that the WAF needs in order to make its policy decision is on a different device. It would only work if you had the traffic decrypted on that server, then sent to the WAF for policy decision, then sent on to wherever it needed to go in the network.