<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CG WAF - Multiple Nano  Agents HAProxy in HA – SSL  Termination with Wordpress as  Next-Hop vCenter8 in WAF</title>
    <link>https://community.checkpoint.com/t5/WAF/CG-WAF-Multiple-Nano-Agents-HAProxy-in-HA-SSL-Termination-with/m-p/232030#M270</link>
    <description>&lt;P&gt;&lt;STRONG&gt;Main Objective:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The main objective of this document is provide a brief summary of Check Point CG WAF integration with HAProxy in high availability (HA) mode and why this is needed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why:&lt;/STRONG&gt;&lt;BR /&gt;To prevent a single point of failure, most products incorporate some kind of built-in feature for high availability between a primary/active device and the secondary/standby device in the event that if the primary device were to go down, the secondary/active would assume the role of the primary/active device and therefore the traffic is uninterrupted.&lt;BR /&gt;With respect to CG WAF, a native HA feature is not available. This might change in the future. However, depending on how you deploy CG WAF, we can achieve HA and load sharing by using virtual machine scale set (VMSS) in Azure and AWS or by using a load balancer such as HAProxy or Netscalar or any other load balancers.&lt;/P&gt;
&lt;P&gt;In our use case that follows with HAProxy, we have demonstrated how we can achieve HA and load sharing with CG WAF.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Use Case 1 – CG WAF in HA using HAProxy as Frontend Load Balancer&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Flow&lt;/STRONG&gt;&lt;BR /&gt;Inbound/Ingress traffic is intercepted by CG WAF (multiple agents) in HA where the next hop is &lt;BR /&gt;a web application.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Use Case 2 - CG WAF in HA using HAProxy as Frontend Load balancer and a Backend load &lt;BR /&gt;balancer as the next hop.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Flow&lt;/STRONG&gt;&lt;BR /&gt;Inbound/Ingress traffic is intercepted by CG WAF (multiple agents) in HA where the next hop is &lt;BR /&gt;a backend load balancer in HA and the web application.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Nov 2024 17:36:16 GMT</pubDate>
    <dc:creator>para92</dc:creator>
    <dc:date>2024-11-07T17:36:16Z</dc:date>
    <item>
      <title>CG WAF - Multiple Nano  Agents HAProxy in HA – SSL  Termination with Wordpress as  Next-Hop vCenter8</title>
      <link>https://community.checkpoint.com/t5/WAF/CG-WAF-Multiple-Nano-Agents-HAProxy-in-HA-SSL-Termination-with/m-p/232030#M270</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Main Objective:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;The main objective of this document is provide a brief summary of Check Point CG WAF integration with HAProxy in high availability (HA) mode and why this is needed.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Why:&lt;/STRONG&gt;&lt;BR /&gt;To prevent a single point of failure, most products incorporate some kind of built-in feature for high availability between a primary/active device and the secondary/standby device in the event that if the primary device were to go down, the secondary/active would assume the role of the primary/active device and therefore the traffic is uninterrupted.&lt;BR /&gt;With respect to CG WAF, a native HA feature is not available. This might change in the future. However, depending on how you deploy CG WAF, we can achieve HA and load sharing by using virtual machine scale set (VMSS) in Azure and AWS or by using a load balancer such as HAProxy or Netscalar or any other load balancers.&lt;/P&gt;
&lt;P&gt;In our use case that follows with HAProxy, we have demonstrated how we can achieve HA and load sharing with CG WAF.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Use Case 1 – CG WAF in HA using HAProxy as Frontend Load Balancer&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;Flow&lt;/STRONG&gt;&lt;BR /&gt;Inbound/Ingress traffic is intercepted by CG WAF (multiple agents) in HA where the next hop is &lt;BR /&gt;a web application.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Use Case 2 - CG WAF in HA using HAProxy as Frontend Load balancer and a Backend load &lt;BR /&gt;balancer as the next hop.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Flow&lt;/STRONG&gt;&lt;BR /&gt;Inbound/Ingress traffic is intercepted by CG WAF (multiple agents) in HA where the next hop is &lt;BR /&gt;a backend load balancer in HA and the web application.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2024 17:36:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/WAF/CG-WAF-Multiple-Nano-Agents-HAProxy-in-HA-SSL-Termination-with/m-p/232030#M270</guid>
      <dc:creator>para92</dc:creator>
      <dc:date>2024-11-07T17:36:16Z</dc:date>
    </item>
  </channel>
</rss>

